// about

About

ITgalya provides SOC, Incident Response and risk assessment services to organisations that want a professional information security layer alongside their existing IT function.

We focus on detecting, investigating and responding to cyber threats, combining technology, human analysis and an evidence-based working methodology.

Our clients typically already have a working IT function but no mature security operations centre. We work alongside that team rather than in place of it: they own the infrastructure and the day-to-day operation, and we add the detection, investigation and response layer.

Our goal is a simple one: to give an organisation a clear picture of where it stands, a fast response, and the confidence that someone is genuinely watching what happens in its environment.

Technical Depth

Hands-on monitoring, investigation and response work — across endpoints, identities, Microsoft 365 and cloud environments.

Availability Agreed Up Front

How much availability there is, and how to reach us during an incident, are agreed with each client in advance — so it is clear who to call and when, rather than something to work out mid-incident.

Speed, From Our Own Tooling

We build our own internal tooling, combining automation and AI, to cut the manual work out of collection and analysis — so professional time goes into decisions rather than into gathering data.

Complete Discretion

Absolute confidentiality and discretion in every engagement.

// r&d

Research and development

ITgalya's commercial work today is security operations: monitoring, alert investigation, incident response and risk assessments. Alongside that work — not in place of it — we build internal capability and automation intended to improve the quality of an investigation, shorten response times and give an event wider context.

The research direction is about connecting events, behaviour and context. The premise is that a single alert is only part of the picture, and that the value lies in assembling it into a sequence someone can understand and act on.

What we equally do not do: sell a solution that has not proved itself, or present an internal working tool as though it were a product.

This work is ongoing. It is not offered as a standalone commercial product, and it is not part of what a client buys today.

Frequently asked questions

What is ITgalya?

ITgalya is an Israeli information security provider offering Managed SOC, Incident Response, cyber risk assessments and security training to organisations. ITgalya is a commercial brand operated in Israel.

What services does ITgalya provide?

Four service lines: Managed SOC monitoring and operation; incident response, from containing the incident through to restoring operations; cyber risk assessments that find and prioritise security gaps; and security training tailored to the organisation. Forensic analysis and evidence collection are part of incident response, not a separate service.

Who are ITgalya's services for?

Primarily organisations that already have a working IT function — in house or outsourced — but no mature security operations centre. ITgalya works alongside that IT team rather than in place of it, adding the monitoring, alert investigation and incident response capability they do not have internally. ITgalya is not an IT provider and does not replace an organisation's support or infrastructure function.

What makes ITgalya different?

Hands-on security operations alongside internal development: we do not only operate other vendors' security products, we also build tooling and automation in house intended to improve the quality of an investigation and the time it takes to respond. That research and development work is ongoing and is not sold as a standalone product.

Where does ITgalya operate?

ITgalya operates in Israel and provides service in Hebrew and English.

How do I contact ITgalya?

By email at support@itgalya.com, or through the form on the site — on the contact page and at the end of the self-assessment. Either way the enquiry reaches the company mailbox. Please do not send passwords, credentials or sensitive material through the form; we will agree a secure channel for anything that needs one.

// next step

Not sure what the right next step is?

Use the short assessment to identify the areas worth reviewing, or tell us what changed and we will start from there.

Do not send passwords, credentials, API keys, logs or sensitive incident material through the web form.