Winnipeg's Only Security Operations Centre

Threats Hunted.
24 Hours.
365 Days.

While other IT providers react after an attack, our Security Operations Centre is watching your environment right now - detecting threats before they become breaches, from right here in Manitoba.

SOC Status

Operational - 24/7

Threat Response

Under 15 min

Active Monitoring

All client environments

Data Residency

Manitoba, Canada

24/7 Threat Monitoring

SIEM Correlation

Managed Detection & Response

Threat Intelligence

Incident Response

Ransomware Containment

Vulnerability Management

Zero-Day Defence

PIPEDA Compliance

Log Analysis

Forensic Investigation

Endpoint Detection

What Is a SOC?

Your Always-On
Cybersecurity Command Centre.

A Security Operations Centre is a dedicated facility staffed by analysts who monitor, detect, and respond to cyber threats around the clock. Most businesses rely on reactive IT support - they find out about an attack after it's already happened. A SOC changes that entirely.

The Only. SOC in Winnipeg.

No other IT provider in Manitoba operates a genuine, on-premises Security Operations Centre. ETS built Winnipeg's first and only SOC so local businesses can access the same enterprise-grade protection that was previously available only to large corporations in major cities. Your data stays in Manitoba. Your analysts are minutes away.

24/7

Active Monitoring

<15min

Threat Response

DETECT

Continuous Threat Detection

Our analysts and automated tooling watch every endpoint, server, network device, and cloud workload - correlating millions of events per day to identify anomalies that signify real attacks, not just noise.

RESPOND

Active Incident Response

When a real threat is confirmed, we don't send you an email. We act - isolating affected systems, containing the threat, and neutralizing it before it spreads. Your business keeps running.

HUNT

Proactive Threat Hunting

Beyond alerting on known threats, our analysts proactively hunt for indicators of compromise that automated tools miss - searching for attackers who may already be inside your environment.

REPORT

Compliance & Reporting

Every incident is documented with full forensic detail. We provide the audit trails, breach reports, and regulatory notifications required by PIPEDA, PHIA, and your cyber insurance policy.

24/7

SOC Uptime

<15m

Threat Response

100%

Local Team

#1

Only SOC in Winnipeg

0

Offshore Data Routing

SOC Capabilities

Six Layers of
Active Defence.

Our SOC isn't a single tool - it's a stack of integrated capabilities operated by certified analysts who understand your environment and know what normal looks like.

01

SIEM - Security Information & Event Management

Real-time log collection and correlation across every device, system, and application in your environment. Our SIEM identifies attack patterns that no single tool can see in isolation.

Log Correlation

Real-Time Alerts

Anomaly Detection

02

MDR - Managed Detection & Response

Human-led triage and response layered on top of automated detection. When an alert fires, an analyst reviews it, confirms it's real, and acts - not just escalates.

Analyst-Led

Containment

Remediation

03

EDR - Endpoint Detection & Response

Deep visibility into every laptop, server, and workstation. Our EDR agents detect malicious behaviour at the process level - catching fileless attacks, lateral movement, and ransomware before encryption begins.

CrowdStrike

SentinelOne

Behavioural AI

04

Threat Intelligence

Our SOC is connected to global threat intelligence feeds and Canadian cyber threat sharing networks. We receive early warnings about attack campaigns targeting Manitoba businesses before they arrive.

Global Feeds

Canadian ISAC

IOC Blocking

05

Vulnerability Management

Continuous scanning identifies weaknesses before attackers exploit them. We prioritize by real-world exploitability - not just CVSS scores - so your team patches what actually matters first.

Continuous Scanning

Risk Prioritization

Patch Guidance

06

Incident Response & Forensics

When an incident occurs, our certified IR team responds on-site in Winnipeg. Full forensic analysis, breach containment, evidence preservation, and regulatory reporting - all handled locally.

On-Site IR

Forensics

PIPEDA Reporting

How It Works

From Alert to All-Clear.
In Under 15 Minutes.

Every threat follows a defined response process. Here's what happens from the moment our systems detect an anomaly to full resolution - all while your team stays focused on work.

01

Detect

SIEM and EDR tools flag an anomaly. Automated scoring filters noise from real threats 24/7.

Continuous

02

Triage

A SOC analyst reviews the alert, correlates it with threat intel, and confirms whether it's a real incident.

< 5 minutes

03

Contain

Affected systems are isolated immediately. Lateral movement is blocked before attackers can spread.

< 10 minutes

04

Eradicate

The threat is removed, malicious code is cleaned, and the attack vector is closed permanently.

< 15 minutes

05

Recover

Systems are restored from clean backups if needed. Operations resume with zero data loss.

As needed

06

Report

A full incident report is delivered - root cause, timeline, remediation steps, and regulatory notices

Within 24 hrs

What You Get With
ETS vs. Everyone Else.

Most Winnipeg businesses have standard antivirus and a firewall and call it "protected." Here's what's actually different when you have a real SOC behind you.

Scenario

Without a SOC

With ETS SOC

Ransomware begins encrypting files

✗ Discovered hours later, often too late

✓ Detected & contained within minutes

Attacker gains initial access

✗ Sits undetected for avg. 197 days

✓ Behavioural anomaly flagged immediately

Phishing credential stolen

✗ No visibility into account misuse

✓ Impossible Travel & login anomaly alerts

Zero-day vulnerability published

✗ Patched weeks later, if at all

✓ Threat intel triggers emergency patching

Insider threat or data exfiltration

✗ Invisible without user behaviour analytics

✓ Flagged by UBA and DLP monitoring

PIPEDA breach notification required

✗ Scramble to determine scope & timeline

✓ Forensic timeline ready, report drafted

Cyber insurance claim

✗ No logs, no evidence, claim denied

✓ Complete audit trail supports claim

SOC Questions,
Straight Answers.

Do I need a SOC if I already have antivirus and a firewall? +

Antivirus and firewalls are table stakes - they block known threats at the perimeter. A SOC goes far beyond that: it monitors behaviour inside your network, correlates events across your entire environment, and responds to the sophisticated attacks that perimeter tools miss entirely. Modern attackers bypass antivirus routinely. A SOC catches what they leave behind.

Is our data stored in Canada? +

Yes - 100%. All log data, security telemetry, and incident records are stored in Canadian data centres. Our SOC analysts are Manitoba residents. Your data never crosses the border, which is critical for PIPEDA compliance and cyber insurance policies that require Canadian data residency.

How does the SOC integrate with our existing tools?+

Our SIEM ingests logs from virtually any source - Microsoft 365, Azure, firewalls, switches, servers, cloud platforms, and business applications. We deploy lightweight agents where needed and connect existing tools via API. Most environments are fully onboarded within two weeks with zero downtime.

What happens when a threat is detected at 2am? +

Our SOC operates 24 hours a day, 365 days a year - including weekends and holidays. When a real threat is confirmed, our on-call analyst takes action immediately without waiting for business hours. For critical incidents, your designated point of contact is notified right away, and on-site response is available across Winnipeg.

How is ETS's SOC different from a generic MSSP?+

Most MSSPs route your alerts to offshore Level 1 analysts who follow scripts and escalate everything. Our SOC analysts are senior, local, and know your environment - because we also manage your IT. That context is what separates a real response from a ticket. We also own your incident response end to end, including on-site forensics in Winnipeg, which no remote MSSP can offer.

What size businesses does the SOC serve?+

Our SOC is built to serve Winnipeg small and mid-sized businesses - typically 10 to 500 employees - that need enterprise-grade security without an enterprise-sized budget. We've designed our service tiers to be accessible to healthcare clinics, law firms, manufacturers, and municipal organizations across Manitoba.