While other IT providers react after an attack, our Security Operations Centre is watching your environment right now - detecting threats before they become breaches, from right here in Manitoba.
SOC Status
Operational - 24/7
Threat Response
Under 15 min
Active Monitoring
All client environments
Data Residency
Manitoba, Canada
●
24/7 Threat Monitoring
●
SIEM Correlation
●
Managed Detection & Response
●
Threat Intelligence
●
Incident Response
●
Ransomware Containment
●
Vulnerability Management
●
Zero-Day Defence
●
PIPEDA Compliance
●
Log Analysis
●
Forensic Investigation
●
Endpoint Detection
What Is a SOC?
A Security Operations Centre is a dedicated facility staffed by analysts who monitor, detect, and respond to cyber threats around the clock. Most businesses rely on reactive IT support - they find out about an attack after it's already happened. A SOC changes that entirely.
.avif)
No other IT provider in Manitoba operates a genuine, on-premises Security Operations Centre. ETS built Winnipeg's first and only SOC so local businesses can access the same enterprise-grade protection that was previously available only to large corporations in major cities. Your data stays in Manitoba. Your analysts are minutes away.
24/7
Active Monitoring
<15min
Threat Response
Our analysts and automated tooling watch every endpoint, server, network device, and cloud workload - correlating millions of events per day to identify anomalies that signify real attacks, not just noise.
When a real threat is confirmed, we don't send you an email. We act - isolating affected systems, containing the threat, and neutralizing it before it spreads. Your business keeps running.
Beyond alerting on known threats, our analysts proactively hunt for indicators of compromise that automated tools miss - searching for attackers who may already be inside your environment.
Every incident is documented with full forensic detail. We provide the audit trails, breach reports, and regulatory notifications required by PIPEDA, PHIA, and your cyber insurance policy.
24/7
SOC Uptime
<15m
Threat Response
100%
Local Team
#1
Only SOC in Winnipeg
0
Offshore Data Routing
SOC Capabilities
Our SOC isn't a single tool - it's a stack of integrated capabilities operated by certified analysts who understand your environment and know what normal looks like.
01
SIEM - Security Information & Event Management
Real-time log collection and correlation across every device, system, and application in your environment. Our SIEM identifies attack patterns that no single tool can see in isolation.
02
MDR - Managed Detection & Response
Human-led triage and response layered on top of automated detection. When an alert fires, an analyst reviews it, confirms it's real, and acts - not just escalates.
03
EDR - Endpoint Detection & Response
Deep visibility into every laptop, server, and workstation. Our EDR agents detect malicious behaviour at the process level - catching fileless attacks, lateral movement, and ransomware before encryption begins.
04
Threat Intelligence
Our SOC is connected to global threat intelligence feeds and Canadian cyber threat sharing networks. We receive early warnings about attack campaigns targeting Manitoba businesses before they arrive.
05
Vulnerability Management
Continuous scanning identifies weaknesses before attackers exploit them. We prioritize by real-world exploitability - not just CVSS scores - so your team patches what actually matters first.
06
Incident Response & Forensics
When an incident occurs, our certified IR team responds on-site in Winnipeg. Full forensic analysis, breach containment, evidence preservation, and regulatory reporting - all handled locally.
How It Works
Every threat follows a defined response process. Here's what happens from the moment our systems detect an anomaly to full resolution - all while your team stays focused on work.
01
SIEM and EDR tools flag an anomaly. Automated scoring filters noise from real threats 24/7.
Continuous
02
A SOC analyst reviews the alert, correlates it with threat intel, and confirms whether it's a real incident.
< 5 minutes
03
Affected systems are isolated immediately. Lateral movement is blocked before attackers can spread.
< 10 minutes
04
The threat is removed, malicious code is cleaned, and the attack vector is closed permanently.
< 15 minutes
05
Systems are restored from clean backups if needed. Operations resume with zero data loss.
As needed
06
A full incident report is delivered - root cause, timeline, remediation steps, and regulatory notices
Within 24 hrs
SOC vs. No SOC
Most Winnipeg businesses have standard antivirus and a firewall and call it "protected." Here's what's actually different when you have a real SOC behind you.
Scenario
Without a SOC
With ETS SOC
Ransomware begins encrypting files
✗ Discovered hours later, often too late
✓ Detected & contained within minutes
Attacker gains initial access
✗ Sits undetected for avg. 197 days
✓ Behavioural anomaly flagged immediately
Phishing credential stolen
✗ No visibility into account misuse
✓ Impossible Travel & login anomaly alerts
Zero-day vulnerability published
✗ Patched weeks later, if at all
✓ Threat intel triggers emergency patching
Insider threat or data exfiltration
✗ Invisible without user behaviour analytics
✓ Flagged by UBA and DLP monitoring
PIPEDA breach notification required
✗ Scramble to determine scope & timeline
✓ Forensic timeline ready, report drafted
Cyber insurance claim
✗ No logs, no evidence, claim denied
✓ Complete audit trail supports claim
SOC vs. No SOC
Antivirus and firewalls are table stakes - they block known threats at the perimeter. A SOC goes far beyond that: it monitors behaviour inside your network, correlates events across your entire environment, and responds to the sophisticated attacks that perimeter tools miss entirely. Modern attackers bypass antivirus routinely. A SOC catches what they leave behind.
Yes - 100%. All log data, security telemetry, and incident records are stored in Canadian data centres. Our SOC analysts are Manitoba residents. Your data never crosses the border, which is critical for PIPEDA compliance and cyber insurance policies that require Canadian data residency.
Our SIEM ingests logs from virtually any source - Microsoft 365, Azure, firewalls, switches, servers, cloud platforms, and business applications. We deploy lightweight agents where needed and connect existing tools via API. Most environments are fully onboarded within two weeks with zero downtime.
Our SOC operates 24 hours a day, 365 days a year - including weekends and holidays. When a real threat is confirmed, our on-call analyst takes action immediately without waiting for business hours. For critical incidents, your designated point of contact is notified right away, and on-site response is available across Winnipeg.
Most MSSPs route your alerts to offshore Level 1 analysts who follow scripts and escalate everything. Our SOC analysts are senior, local, and know your environment - because we also manage your IT. That context is what separates a real response from a ticket. We also own your incident response end to end, including on-site forensics in Winnipeg, which no remote MSSP can offer.
Our SOC is built to serve Winnipeg small and mid-sized businesses - typically 10 to 500 employees - that need enterprise-grade security without an enterprise-sized budget. We've designed our service tiers to be accessible to healthcare clinics, law firms, manufacturers, and municipal organizations across Manitoba.