Protectione Network Security

Five systems, one dashboard, one database.

Flow monitoring, data retention, threat intelligence, vulnerability scanning and NIS2 reporting run on a single platform. Stop an attack at your upstream with RTBH, and have the regulator's report pre-filled before you start writing it.

45 minutes, onlineTailored to your networkDeployed in 48 hoursSupport in English and Czech
The Protectione Network Security overview dashboard
protectione.net · recorded from a live system
The problem

How many systems are you running today?

A typical ISP runs five separate tools, five licences and five places to look for context. Every additional system adds complexity, integration cost and the risk that something falls between them.

Flow monitoring

Its own collector, its own database, its own licence.

Data retention

A legal obligation handled by yet another system and yet another storage tier.

Threat intelligence

Feeds downloaded somewhere and evaluated somewhere else — not where the flows are.

Vulnerability scanner

Another tool, another console, another report nobody connects to network operations.

NIS2 records

Spreadsheets, shared documents and deadlines tracked by hand.

The answer

One platform. One database. One dashboard.

All five areas run on the same data. When a flow record shows a suspicious address, its reputation, ASN, attack history and any link to an open incident are on the same screen.

Demo

Watch it, then run it on your own data

The recording from a live system follows the path from a flow record to a blocked address and a pre-filled report. A video is fine, but deciding on someone else's data is not — which is why we offer a demo on your own traffic.

A demo on your data

We deploy the system into your network and let it run on real traffic. You see your own flows, your own attacks and your own vulnerabilities — not a prepared showcase.

  • 30 days on the full Complete edition, no feature limits
  • Deployed in 48 hours for the cloud and virtual options
  • No commitment — if it does not fit, we simply switch it off
  • At the end you get a summary of what the system found in your network

The video is in Czech with Czech subtitles. An English walkthrough is available live.

Request a demo on my data
Who it is for

Designed for network operators

For internet service providers and network infrastructure operators — not a general security tool that discovered ISPs later.

Regional ISPs

Providers running their own network infrastructure across a region.

Municipal operators

Operators of municipal networks and metropolitan fibre infrastructure.

Telcos

Telecommunications operators with complex backbone infrastructure.

Data centres

Colocation and cloud infrastructure operators.

Critical infrastructure

Connectivity providers for critical government and industrial networks.

Why

The four reasons we hear most often

Lower cost

Fewer licences, fewer servers, fewer integrations. One platform instead of five tools with separate licence fees.

Less administration

One system instead of several disconnected ones. The team focuses on security, not on maintaining tools.

Faster response

Investigate an incident in minutes. The context — flows, threats, vulnerabilities — is in one place.

NIS2 readiness

Records and reporting in one place, with all five reporting stages and the time remaining on each.

Core capabilities

From a flow record to a blocked IP address

Deep traffic analysis, threat detection, mitigation and regulatory support over a single data set.

Deep flow inspection

Every IP flow analysed in real time. IPFIX, NetFlow v9 and native interface mirroring.

Automated threat detection

22 predefined rules in three families: floods against your addresses, floods from one of your hosts, and scans and sweeps. UDP and TCP SYN floods, reflection attacks over DNS, NTP, LDAP, SSDP, memcached and chargen, port scans and address sweeps. From a mirrored interface the system names an attack within seconds.

Context from global threat sources

Every flow is enriched with source reputation from eight feeds — FireHOL, abuse.ch Feodo and ThreatFox, AlienVault OTX, Emerging Threats Open and MISP. You recognise traffic to infrastructure known from botnets and malware campaigns without reading the payload.

NIS2 compliance

The module covers NIS2 obligations and implements the Czech transposition in detail (Act 264/2025 Coll. and decrees 409/2025 and 410/2025 Coll.). It determines your regime, decides what counts as a reportable incident and tracks all five reporting stages including time remaining. We adapt the module to other national transpositions.

RPKI and prefix hijack detection

Continuous comparison of what is actually announced in global routing against what prefix holders authorised by signing a ROA. A divergence is a strong signal of a prefix hijack, a route leak or a misconfiguration.

Vulnerability analysis

Active and passive scanning, CVE and CVSS enriched with EPSS and KEV — prioritised by what is actually being exploited.

What sets it apart

What you will not get elsewhere in one package

01

Detection and mitigation in one

You do not just see the attack — the system cuts it off at the upstream peer via RTBH or FlowSpec.

02

Attack aggregation

Hundreds of thousands of scan records become one aggregated entry. Smaller database, faster investigation.

03

Eight threat sources built in

FireHOL, abuse.ch Feodo and ThreatFox, OTX, ET Open and MISP — including a link to your own MISP server.

04

140,315 ASNs and a million routes

Data straight from the RIR registries, with RPKI validation, BCP-38, MANRS and CAIDA rank.

05

RPKI and prefix hijack detection

10,542 tracked divergences between what is announced and what is authorised.

06

Exports everywhere

CSV, JSON and PDF in every section — flows, attacks, ASNs, incidents and forensic analyses.

Traffic analysis

Full visibility into network traffic

The system collects data over NetFlow v9, IPFIX, packet mirroring and TCPdump — from multiple collectors, sites and data centres at the same time. Collection methods can be combined and the distributed architecture extended without limits as the network grows.

  • Historical traffic analysis
  • Real-time analysis
  • Detailed flow search with advanced filtering
  • Export to PDF, CSV and JSON
  • Multiple collectors and probes across sites
System screen
Flow analysis — traffic charts and the busiest addresses for the selected period
Attack aggregation

Hundreds of thousands of records, stored as one

Conventional systems store every connection attempt separately. During a scan or a DDoS that produces hundreds of thousands to millions of records, loading the database and driving up storage cost. The system recognises port scanning, brute force, DDoS traffic and one-way connection attempts and converts them into aggregated records.

  • Substantially lower storage demand
  • Better system performance
  • Faster analysis
  • Easier incident investigation
System screen
Aggregated flows — hundreds of thousands of connection attempts in one readable view
Investigation

From an alert to an answer you can evidence

Every detected attack can be taken apart in depth — by its identifier, or by examining a specific IP address in a given time window. Analyses are stored, so you can come back to them a month later when writing the final report.

  • Traffic Patterns — patterns that recur in your traffic
  • Incident Simulation — rehearse how a response plays out before a real one arrives
  • Stored forensic analyses with export
  • Testing your response is part of mandatory NIS2 measures
System screen
IP profile — geolocation, WHOIS, ASN and history in a single view
ASN intelligence

140,315 ASNs, a million routes, refreshed straight from the RIR registries

For any IP address you immediately know who owns it, what its ASN reputation is, how traffic reaches it and what relationships that network has. Data is populated from RIPE NCC (5.0 m records), APNIC (1.2 m), LACNIC, AFRINIC and ARIN over RDAP.

System screen
ASN database — an address lookup returns the route, RIR record, organisation and reputation
Distinctive capability

RPKI and prefix hijack detection

The system continuously compares what is actually announced in global routing against what prefix holders authorised by signing a ROA. A route covered by a ROA that does not authorise the announcing AS is a strong signal of a prefix hijack, a route leak or a configuration error.

There are currently 10,542 such divergences in the database — each showing the announcing AS, the authorised AS and the affected prefix, with export to PDF and JSON.

  • BCP-38 — which networks let spoofed source addresses through
  • MANRS — who commits to routing security norms
  • Attack Map — interactive map of attack flows with geolocation
  • Live Feed — a stream of detected events filtered by severity
System screen
Peering map — 5,270 interconnection facilities and the relationships between networks
Vulnerability management

Patch by what is actually being exploited

The built-in scanner checks devices on the network in two modes: a quick scan at most once an hour per subnet and a full scan once a day, both in parallel blocks, so a large network does not extend scan time linearly.

System screen
Vulnerability analysis — severity distribution and the most frequent CVEs over 30 days
Automated protection

From detection to response within seconds

The system does not only detect. It can stop an attack at your upstream peer — before it saturates your uplink.

System screen
Response history — what the system triggered, when, and against which address

For every action you set the severity at which it triggers and how it should treat late detections from exporters. A blackhole can also be announced manually for a specific prefix, with an expiry or until revoked — and any active announcement withdrawn with one click.

Integration

Fits into an ISP environment

The platform is designed to slot into an operator's existing infrastructure. Integration runs over a REST API and webhooks — into practically any CRM, billing or operations system an ISP uses.

  • ISP CRM systems and customer portals
  • Billing and ticketing systems
  • Monitoring platforms and SIEM solutions
  • Internal applications over the REST API
System screen
Notifications — where each alert goes: email, syslog, SNMP trap, webhook
Operations tools

Traceroute where you see the flows

When you are handling an incident at three in the morning, you are not jumping between three windows and two SSH sessions. The context you need is on the same screen as the flow record that brought you there.

System screen
Health Monitor — service availability and an outage record
Deployment

Live in 48 hours. Three options, whichever suits you.

The system handles traffic up to 100 Gbps. Collection can be split across multiple collectors and probes, so the architecture grows with your network — across sites and data centres.

Cloud edition — within 48 hours

We run the platform, you connect to it. The fastest route to first data, with no hardware to buy and no changes to your infrastructure.

Virtual appliance — within 48 hours

You deploy the software into your own virtualisation. Data never leaves your network — for data retention, and for operators with their own policy on traffic data, usually the only acceptable option.

Hardware appliance — within a week

A certified device on lease, including replacement on failure, firmware, monitoring, remote management and SLA. Timing depends on hardware availability.

NIS2

Not a calendar of deadlines. A guide to what the law asks of an ISP.

The module goes beyond the general wording of the directive. It implements the Czech transposition — Act 264/2025 Coll. and decrees 409/2025 and 410/2025 Coll. — in detail. The framework of obligations is the same across the EU; we adapt the module to other national transpositions.

It determines your regime

A provider of a public communications network or service is regulated regardless of size — the small-enterprise exemption does not apply to you. The regime is decided by company size or reach: higher obligations from 350,000 active SIMs or 100,000 fixed connections, otherwise lower obligations. One organisation means one regime.

It decides what even counts as an incident

A reportable incident has three characteristics at once: it occurred within the scope of security management you defined, it originates in cyberspace, and a deliberate cause cannot be ruled out within 24 hours. The system knows these tests and shows you why one outage must be reported and another must not.

It tracks all five stages

Initial report ≤ 24 h · Notification ≤ 72 h (trust services 24 h) · Interim report on the regulator's request · Status report after 30 days if the incident is still open · Final report ≤ 30 days after resolution. For each stage you see how much time is left — or by how much it is overdue.

It knows the rest of the obligations too

Notifying the authority, contact details, security measures within the statutory period, and responding to warnings and reactive countermeasures without delay. Authority contacts, including emergency numbers, sit inside the system, split by your regime.

SituationOutcome
A user clicked a phishing link and entered credentialsIncident — reportable
Phishing arrived but nobody clickedEvent — not reportable
Outage during planned maintenanceNot an incident — intent ruled out
System screen
NIS2 guide — the reporting stages and the time remaining on each

Failing to report — late, not at all, or omitting follow-up reports — is an offence. Reporting an incident does not itself trigger an inspection; incidents happen to well-secured organisations too.

Incident management

You do not have to guess what is reportable

Health Monitor watches service availability and groups outages into candidate NIS2 incidents on its own — with calculated impact and an assessment of whether the cause looks like a cyber attack.

You then simply decide. Dismiss an operational outage. Promote a real incident into a report that is already pre-filled and carries the evidence: which attacks, from which addresses, at what severity.

Where the system's role ends

The statutory clock starts with your decision — until then the system only flags that there is something to assess. We keep that boundary deliberately: what counts as an incident is decided by your responsible officer, not by software.

System screen
Incident register — reporting candidates and closed cases
Comparison

Protectione vs. conventional NetFlow vs. SIEM

CapabilityProtectioneConventional NetFlowSIEM
Flow monitoring~
Data retention~
Threat intelligence
Vulnerability management~
Mitigation via RTBH / FlowSpec
NIS2 to national law~
RPKI and ASN intelligence
ISP specialisation~
Single platform
Transparent pricing

A subscription scaled to the size of your network

Price follows the number of ISP subscribers. No hidden fees. Prices exclude VAT and apply to the 500–1,000 subscriber band; larger networks are priced by band.

For smaller ISPs

Start

CZK 5,000
/ month, excl. VAT
  • Flow monitoring
  • Data retention (statutory minimum)
  • NetFlow / IPFIX collection
  • Basic reports
Book a walkthrough
Most popular

Advanced

CZK 7,000
/ month, excl. VAT
  • Everything in Start
  • Threat intelligence
  • Attack Map and Live Feed
  • NIS2 core support
  • Vulnerability scan
Book a walkthrough
Full network protection

Complete

CZK 10,000
/ month, excl. VAT
  • Everything in Advanced
  • Vulnerability management
  • Automated response (RTBH, FlowSpec)
  • Full NIS2 reporting
  • RPKI, BGP and ASN analysis
  • Priority place in the support queue
Book a walkthrough

No lock-in

Cancel at any time.

7% for 24 months

Discount on the total price for a two-year term.

10% for 36 months

Discount on the total price for a three-year term.

5% paid annually

Discount when paying a year in advance.

Hardware appliance — CZK 2,500 / month over 36 months

A certified device on lease: hardware, replacement on failure, firmware, monitoring, remote management and an SLA guarantee. After the term, a service fee of CZK 1,000 per month or purchase for a nominal sum.

Pricing by network size

ISP subscribersStartAdvancedComplete
500–1 0005 0007 00010 000
1 001–2 0007 0009 00013 000
2 001–5 0009 00012 00016 000
5 001–10 00012 00016 00020 000
10 001–20 00015 00020 00025 000
20 001+on requeston requeston request

Per month in CZK, excl. VAT.

Prices are shown in CZK; a euro quotation is available on request. For more than 20,000 subscribers we prepare an individual offer. A guaranteed response time (SLA) is a separate service on top of the plan.

FAQ

What people ask most

How long does deployment take?

The cloud and virtual editions are deployed within 48 hours. The hardware appliance within a week, depending on device availability. For the virtual edition we need resources in your virtualisation and access to a mirrored interface, or NetFlow / IPFIX export configured on your routers.

What load does the system handle?

Up to 100 Gbps. Collection can be split across multiple probes and collectors, across sites and data centres — the architecture grows with the network, so you do not have to size it up front.

How quickly does it recognise an attack?

From a mirrored interface, within seconds. Records from IPFIX and NetFlow v9 exporters arrive 15 to 60 seconds after a connection ends, depending on your router configuration — the system evaluates those too and marks them as late, so you can tell what is happening now from what happened a moment ago.

Will it report attacks that are not really attacks?

Sensitivity is set with a single control across four levels — from high for quiet networks to very low for backbone and transit, where only a genuinely large attack should raise an alert. Each individual threshold can be tuned separately, and addresses that must never trigger a response go on a whitelist.

What if a detection is wrong and the system starts blocking?

For every response you set the severity at which it triggers. The whitelist also works granularly — per IP, port or protocol, and separately for the LAN and WAN side. Active blackholes sit in one table and any of them can be withdrawn with a single click.

Does the data stay with us?

With the virtual and hardware appliance, yes — the system runs inside your network and the data does not leave it. The cloud edition is for operators who want a fast start without their own hardware; you can move between the options.

Can we connect it to our SIEM and monitoring?

Yes — SNMP trap, syslog and URL callback are among the detector's responses. There is also a REST API for CRM, billing, customer portal or ticketing integration.

How are vulnerabilities prioritised?

Beyond CVSS, the system pulls EPSS (probability of exploitation) and CISA's KEV catalogue of vulnerabilities known to be exploited. You patch by what actually threatens you.

We have older CPE that does not cope well with scanning.

The system has a stability test mode that identifies exactly those devices, and subnets or individual addresses can be excluded from scanning.

What happens to our data if we end the contract?

The data is yours and export is always available. It is charged by data volume according to the current price list — for large historical archives the transfer and processing are not trivial. We calculate the figure for you in advance, not on your way out.

What support and SLA do you offer?

Standard support in English and Czech is included. A guaranteed response time (SLA) is a separate monthly subscription on top of the plan.

Online walkthrough

We show you the system on your network, not on a generic demo

Forty-five minutes, online, no commitment. We go through what the platform would look like at your organisation — how many systems it would replace, how NIS2 reporting would work for you, and what it would mean for your team. Walkthroughs are one-to-one, so the answers are specific rather than generic.

The form could not be sent. Please email josef@protectione.net or call +420 602 422 430.
Thank you. We will get back to you within one business day. If it is urgent, call +420 602 422 430.

Protectione Network Security walkthrough

Length45 minutes
FormatOnline video call
AttendeesYour team, as many as you need
ForISP owners, CTOs, network and security teams
PriceFree, no commitment

After you send the form we get back to you within one business day to agree a time that suits you.

Contact

Let's talk about your network security

Interested in a demo, a pilot, or simply want to know more? Get in touch directly. We usually reply within 24 hours on business days.

Email

Josef Macháček

josef@protectione.net

Phone

Call directly

+420 602 422 430

Getting started

Stop maintaining five systems. Start running the network from one platform.

One platform. One database. One dashboard.

Book a walkthrough
NIS2 readyOn-premise or cloud — your choiceDeployed in 48 hoursSupport in English and Czech