MDR partner · Sumo Logic Cloud SIEM

Managed SOC on Sumo Logic Cloud SIEM, with the detections run by us.

For teams that chose a cloud SIEM to avoid running infrastructure but end up with insights nobody works at night. The Fortgale MDR service runs rules and playbooks in your Sumo Logic tenant and contains through the connected tools, at a median TTC of <30 minutes.

<15 minMedian TTD
<30 minMedian TTC
24·7·365SOC in Milan since 2017
Fortgale × Sumo Logic
MDR · live
Sumo Logic sensor activeEndpoint · cloud · identity telemetry
Sumo Logic
European SOC 24·7·365L2/L3 analysts · direct interaction
Fortgale
Multi-domain AI tier-zeroNoise reduced >90% by day 30
Fortgale
Native Sumo Logic responseHost isolation in seconds
Live
Proprietary intelligence287 tracked adversary groups and attack tools
Fortgale
MDR live, Sumo Logic + Fortgale SOC active
Compliance
ISO/IEC 27001
NIS2 ready
DORA aligned
GDPR · ENISA
Technology partnership
Sumo Logic Cloud SIEM
MITRE ATT&CK aligned
OpenCTI
Coverage

What we cover on Sumo Logic.

The Sumo Logic components the SOC operates. Sumo Logic is SaaS only: if it is not in place yet, licensing and tenant setup are part of the service.

01

Cloud SIEM

The Sumo Logic chain from records to signals to insights, tied to entities: analysts work insights, not individual logs.

02

Fortgale rules

Match, threshold, chain, aggregation, first seen and outlier rules written by Fortgale, with tuning expressions and match lists built on your environment.

03

Threat intelligence

Fortgale indicators loaded as a threat intelligence source next to the feeds already included in the tenant, used by rules through threat matching.

04

Automation Service and Cloud SOAR

Enrichment, notification and containment playbooks in the Automation Service included with Cloud SIEM; with Cloud SOAR, incident management and War Room as well.

05

Cloud and SaaS sources

AWS CloudTrail, Azure, Google Cloud, Kubernetes, Microsoft 365 and third-party EDR in the same tenant.

06

Cloud hunting

Hunting led by Fortgale analysts on AWS IAM abuse, Entra ID compromise and exposed Kubernetes clusters.

What we add

What Fortgale adds on top of Sumo Logic.

A SIEM collects and correlates; it does not decide. Fortgale brings the detection engineering that turns it into a defence: rules built on 287 tracked adversary groups and attack tools, mapped to MITRE ATT&CK and maintained by the Milan SOC, with every alert enriched by proprietary CTI before it reaches the analyst. The data stays in your environment, under your retention. Noise drops by more than 90% by day 30, and once an alert is confirmed the analyst acts through the tools connected to the platform: median TTD <15 minutes, median TTC <30 minutes.

Sumo Logic does not contain on its own: a confirmed insight becomes action through Automation Service or Cloud SOAR playbooks, with integrations to the EDR for isolation, to Active Directory and Entra ID for account blocking and to AWS or Azure for session revocation.

The Automation Service included with Cloud SIEM runs playbooks but does not manage cases: incident management needs Cloud SOAR. At onboarding we agree with you where the analyst approves an action and where the playbook proceeds on its own.

Fortgale rules live in your tenant next to Sumo Logic content, and the 34,000 IOCs a week of Fortgale CTI enter as a threat intelligence source: a connection to attributed infrastructure raises a signal that weighs on the entity involved.

Takeover

How we take over your Sumo Logic environment.

Takeover happens on your Sumo Logic tenant, in the region where you opened it: sources, collectors and retention stay as they are.

Monitoring starts as soon as access is live, and technical onboarding closes in one week: roles, Fortgale rules, match lists, playbooks and response authorisations.

That week also covers cloud and SaaS sources, because without Entra ID sign-in logs or CloudTrail some detections stay blind. On your side: a tenant administrator, permissions on the response integrations and the escalation list.

From the field

Phishing around funding rounds: the target was the leadership.

In April 2026 Fortgale published a case of phishing aimed at investment rounds: around ten key people, executives and finance staff, at a company in the middle of a funding round, approached with emails built on public news about the round. The kit was Rockstar 2FA, a phishing as a service that sits between the victim and Microsoft 365 to capture credentials and MFA tokens. The Fortgale anti-AiTM system flagged the page before compromise: one user had clicked, no unauthorised access happened. The campaign was linked to PhishSurf Nebula.

The article is not about Sumo Logic, but it shows where the game is played: in Microsoft 365 sign-in logs, on the most exposed identities. In Cloud SIEM that is the job of a first seen rule on a sign-in from never-seen infrastructure for an executive, a chain rule linking the link click to the following sign-in and a match list of the accounts to protect first; a playbook can then revoke sessions before the stolen token is used.

FAQ

What buyers running Sumo Logic actually ask.

Does the data stay in our Sumo Logic tenant?

Yes. Logs stay in your tenant and in the region chosen when it was opened: in Europe Sumo Logic runs deployments in Frankfurt, Ireland and Zurich, and since June 2026 also on the AWS European Sovereign Cloud. Our analysts work inside your tenant with the agreed roles.

Do we need Cloud SOAR, or is the Automation Service enough?

To run containment playbooks the Automation Service included with Cloud SIEM is enough. Cloud SOAR adds incident management, War Room and reporting: you need it if you want the whole case lifecycle to stay in Sumo Logic.

Do we need an EDR to contain?

You need a tool that carries out the action. Sumo Logic correlates logs and signals, but host isolation is done by the EDR and session revocation by the identity or cloud provider: playbooks connect them, and where an integration is missing the analyst acts on the tool's console with the agreed permissions.

How do we move from another provider without a gap in coverage?

Sources and history stay in the tenant: only roles, active rules and playbooks change. Fortgale monitoring starts as soon as access is live, and the previous contract can end once technical onboarding is complete, after one week.

Do we buy the Sumo Logic licences, or do you?

Either way: Fortgale operates the Sumo Logic tenant you already have, or provides licensing and setup as part of the service.

See a real runbook

A real runbook on your Cloud SIEM.

We walk through a Sumo Logic insight step by step: the signals that built it, the Fortgale rule that weighed most, the containment playbook and the evidence left in the tenant. Alongside it, the Report on the actors most likely to target your sector.

Response time: < 1 business day.