SECaaS.IT

PRISM EagleEye · Security Operations

What is actually happening right now — not what was logged last week.

EagleEye combines security events from your SIEM/XDR, operational and capacity data from monitoring, asset dependencies on the OBASHI model, and threat intelligence (CISA-KEV/EPSS) into one situational picture — showing role-by-role which business processes are currently exposed to which risk.

The Problem

Security and compliance are separate worlds. For now.

SIEM without context

Your SIEM shows thousands of events — but not which business process is currently affected. Prioritisation by gut feeling.

Compliance without live data

Your ISMS shows where you stood at the last audit — not what is happening in your infrastructure today.

CMDB without connection

Assets are inventoried. But which asset supports which process, which requirement is affected? That link is missing.

How EagleEye works

What EagleEye does differently.

Three layers that have existed side by side — connected into one actionable situational picture.

One picture instead of five tools
Which process is at risk right now?
Action when the event happens — not after

One picture instead of five tools

  • Evidence from Wazuh/XDR, Zabbix monitoring, Docker version state and threat intelligence — continuously on a 5-minute cycle
  • Asset dependencies on the OBASHI model (6 layers: Ownership, Business, Application, System, Hardware, Infrastructure)
  • NIST CSF 2.0 radar, compliance score, exposed hosts and business risk — filtered by role for CISO, IT operations, ISB and management

Which process is at risk right now?

  • OBASHI links assets to business processes; technical findings are propagated up to the business and owner level
  • Deterministic risk engine prioritises by severity, reachability, exploit context and business criticality — traceable, no blackbox score
  • Risk score per process and role; NIST CSF 2.0 lens and CIS/SCA hardening evidence per host

Action when the event happens — not after

  • Derive a ticket directly from an action item (idempotent, deduplicated) — including a prioritised what-first list per role
  • Effectiveness loop: done only counts once the finding disappears from the evidence — not just when the ticket is closed
  • PRISM ISO feedback: CIS/evidence proofs flow automatically as control evidence into PRISM ISO — audit proof created at the point of response, not right before the audit

Capabilities

More than a dashboard — an operational system.

ISO 27001 control mapping

Every SIEM event and every monitoring finding is automatically mapped to the relevant ISO 27001 control — audit evidence created by operations.

Regulatory crosswalk NIS-2 / DORA / KRITIS

Evidence and findings are also evaluated against NIS-2, DORA and KRITIS requirements — one event, multiple frameworks simultaneously.

CMDB reconciliation & asset drift

EagleEye detects when the actual infrastructure diverges from your CMDB — new assets, disappeared hosts, changed relationships.

Evidence-based copilot

AI-assisted analysis of findings with verifiable evidence links — no blackbox, every suggestion is traceable to source data.

Architecture, Operations & Maturity

Self-hosted, Made in Germany

Docker Compose deployment, non-root containers, TLS, VPN-only gate; data stored in Germany.

Lean, auditable core

Logic in a unit-tested stdlib core (render-only UI); SQLite today, PostgreSQL as target architecture.

Data sources

Wazuh/XDR, Zabbix, Docker versions, CISA-KEV/EPSS, CIS/SCA — extensible via a connector model.

Maturity

EagleEye Core v1.0 is production-ready and runs as our own operations and security centre — available for customer environments now.

One system for Security Operations and Compliance.

PRISM ISO shows where your organisation should be. PRISM Audit checks whether it is there. EagleEye shows what is happening right now.

PRISM ISO PRISM Audit EagleEye
Shows Where you should be Whether you comply What is happening now
Time perspective Certification cycle Audit year Continuously (5-min cycle)
Audience ISMS team / management Auditors / revision CISO / IT ops / ISB
Key question Do we have all controls? Do we maintain them? Are we secure right now?

See EagleEye on a real situational picture.

In the initial consultation we show how SIEM/XDR events, asset dependencies and compliance evidence come together in an actionable situational picture. No pitch — we clarify whether EagleEye fits your security infrastructure.