ConsultancyNOC-as-a-Service

A NOC without building one.

Monitoring, alerting, incident handling and changes on your network, by the engineers who run AS211588 every day. We see it before your customers do; you remain the owner of equipment, design and access.

24/7We detect, we callOwn monitoring stackYou remain the owner
Who it is for

Sound familiar?

One network engineer, no cover

You have one person who knows the network. When they sleep, are on holiday or leave, there is nobody.

The team wants to sleep

You have engineers, but no rota for the night. Alerts go to a group mailbox that is read in the morning.

Outgrown watching dashboards

Monitoring exists, but someone only looks when a customer calls. You want it the other way round.

What we do
24/7 monitoring and alerting
Availability, performance, flow and logs of your equipment in our monitoring stack: Grafana, Prometheus, SNMP, sFlow and NetFlow, syslog. Thresholds are tuned to your network during onboarding.
Detection and first response
On an alarm we open the ticket, we call you and an engineer gets to work. The clock starts at the alarm, not at your report.
Changes and configuration management
Standard changes are agreed in advance and go fast. Larger changes are planned in your maintenance window. Every configuration is backed up with change detection.
Vendors and escalation
On the Managed level we open tickets with your vendors, carriers and exchanges in your name, and stay on them until it is resolved.
Where is the line?

Yourself, Monitor & Notify or Managed.

Two levels, two places where responsibility crosses over. On both levels equipment, design and vendor contracts remain yours.

YourselfMonitor & NotifyManaged
Monitoring and alertingyouusus
Who sees it firstyou, or a customerus, and we call youus, and we call you
Diagnosis and first responseyouus, remotelyus, remotely
Remediation on the devicesyouyou, or us hourlyus, within the agreed bundle
Standard changesyouyouus, from a pre-agreed list
Emergency changesyouyouus, following agreed playbooks
Configuration backup with change detectionyourecommendedrequired, set up by us
Tickets with vendor, carrier, exchangeyouon requestus, in your name
Hardware, spares, support contractsyouyouyou
Design and architectureyouyou, or us as an engagementyou, or us as an engagement
How it works

From onboarding to handover.

  1. Intake
    Which devices, which level of monitoring, which maintenance window, whom we call and in what order.
  2. Onboarding
    Access through a WireGuard peer to your out-of-band router or through what you already have. Monitoring baseline, standard changes and playbooks recorded in the service register.
  3. Live
    From the day we confirm everything is in monitoring, the SLA commitments apply.
  4. Handover
    If you stop, you get everything back within thirty days: register, repository, monitoring configuration and runbooks. We remove our accounts and tell you which they were.

Everything we keep for you lives in a service register you can consult yourself.

Practical

What to expect.

Coverage
24/7, all year. There is no cheaper office-hours level; a network outage does not wait.
Who is watching
The same engineers who manage AS211588. No separate first line that only forwards.
Access
A personal account per engineer on your equipment, never shared. Preferably through a WireGuard peer to a local out-of-band router, otherwise through your existing access. Access is revoked within one working day when an engineer leaves.
Monitoring stack
Grafana, Prometheus with our own NETCONF and SNMP poller, SNMPv3, sFlow and NetFlow, syslog. We only keep flow data if you want us to; otherwise we set up recording on your own equipment.
Reporting
No periodic reports unless agreed. Every incident and change sits under a ticket in the dashboard. Security incidents are always reported.
Commitments
Response times, change lead times and the credit scheme are in the SLA addendum for managed network, which comes with every proposal.
Price
A monthly fee per device or per environment, after the intake. What is included and what is not is on the quote.
Why Xyphen IT

Engineering that earns trust.

  • Own NOC that runs AS211588 24/7
  • Monitoring we build ourselves and use every day
  • You keep ownership, design and root
  • Written SLA with response times and credits

NOC-as-a-Service at Xyphen IT is not a call centre with a script. The engineer who calls you at night can also fix it.

FAQ

Frequently asked questions about NOC-as-a-Service

Do you need access to our routers?

For Monitor & Notify only read access for monitoring. For Managed also a personal account per engineer to make changes. Everything is traceable through the logging on your own equipment, and the service register shows which accounts we hold.

Can we keep our own monitoring?

Yes. We monitor with our own stack, because we must be able to trust it at night, but we can forward alerts to your systems and your dashboards remain yours.

What if we already have a NOC contract?

Then we look at the overlap during the intake. Often we take the network and the rest stays where it is; the line is recorded in the service register.

What may you do without calling?

Only the playbook actions we recorded together during onboarding, such as a failover or a DDoS filter. Everything else happens after your go-ahead, and we keep calling until we reach someone.

How do we get it back if we stop?

Within thirty days: service register, repository with configurations, monitoring configuration and runbooks. Our accounts go, and monitoring data is deleted unless you want an export first.

How does this relate to managed colocation?

Managed colocation is about your hardware in our data centre, up to and including firmware. NOC-as-a-Service is about your network, wherever it is. They can go together, and we record the boundary.

Want us to see it first?

Tell us about your network. After a 30-minute intake you get a proposal with the split that fits you.