
Co-founder and COO

COMPANY: Soteria
HEADQUARTERS: Charleston, South Carolina
CYBERSECURITY SERVICES: Managed detection and response, cyber security advisory, offensive security and red teaming, incident response, virtual CISO and high-level advisory, architecture and security configuration assessments, governance
CHALLENGES:
Find an EDR foundation that fit a small, self-funded consultancy without a large capital outlay
Scale onboarding and rule management across a growing customer base without growing headcount at the same rate
SOLUTION: LimaCharlie SecOps Cloud Platform (SCP)
BENEFITS:
API-first architecture cut new customer onboarding from a six-page manual process to a few minutes
GitHub-based detection as code keeps rules consistent across every tenant as the client base grows
New platform capabilities, like vulnerability reporting, turn into new service offerings in days instead of months
Soteria started as a consulting and advisory firm focused on penetration testing and incident response. Co-founder and managing principal Paul Ihme describes the company's growth from there as organic, expanding into virtual CISO work, offensive security, managed detection and response, and Microsoft 365 security products.
Soteria’s first attempt at monitoring was a hardware project: rack-mounted network sensors built on Security Onion, Suricata, and Zeek. Within a year, the build costs and the consultative sales cycle required to sell network monitoring made the approach unworkable.
As ransomware shifted from individuals to enterprises, Soteria moved to endpoint security and faced a build versus buy decision, weighing LimaCharlie against other EDR vendors.
The bigger vendor names carried more brand recognition, but Ihme worried what that meant for a small customer: "Are they going to pick up the phone when we call if we have a problem? We wanted somebody who was going to approach this with the same tenacity as ours."
Soteria bet on LimaCharlie and during one of their first incident response engagements, the team mentioned a capability they wished existed. It shipped that same night. "That's when committed as a company," Ihme says. "This is exactly who we need to be partnered with."
Rather than build its own EDR, Soteria spent two to three months with four people learning LimaCharlie's telemetry and building detection and response rules, alongside its own workflow tooling for alert escalation and reporting. That rule-building work later became a product in its own right: when another organization asked about pre-built rule sets, Soteria and LimaCharlie published some of Soteria's rules to the LimaCharlie marketplace in about a week.
Rules tuned for Soteria's first ten customers didn't always hold once an eleventh, the size of the first ten combined, came aboard. Alert volume climbed, and the team had to keep distinguishing legitimate developer activity, like unusual PowerShell use, from techniques malware authors use for the same purpose. Soteria's answer was to split the difference: false positives that held true across every environment went into a shared rule base, while anything specific to one customer's setup got handled through per-tenant configuration layered on top.
Change management scaled the same way. Keeping every environment current without violating individual customers' change control policies was easy at three customers and hard at a hundred. Soteria's fix was treating detections as code: rules, Hive configurations, and false positive handling live in a central GitHub repository, deployed through GitHub Actions and a service account.
Onboarding improved the same way. What used to take a six-page internal document now takes about two minutes: Soteria enters a new customer's name, device count, and required services, and an API call to LimaCharlie creates the organization, sets quotas, generates an installation key, and deploys Soteria's rule sets and collection configurations.
When LimaCharlie added vulnerability reporting, built on its existing ability to list installed OS packages against vulnerability databases, Soteria turned it into a client offering within days. The team piloted it free with a few customers, then built reporting around it: which vulnerabilities matched CISA's Known Exploited Vulnerabilities list, and how many findings a customer had cleared since the last report.
"It's been a great way to add value to what we're doing with our clients without having to do a ton of lift. It was a fairly straightforward implementation for you all, and for us it was just, let's extend what we're already doing."
Ihme sees it as a way to show value during the stretches when nothing is on fire, which matters because a well-run MDR practice shouldn't generate constant alerts. Concrete numbers, alerts triaged and vulnerabilities closed, fill that gap.
Asked what he'd tell someone evaluating an unproven platform the way Soteria did, Ihme points to maintenance. Most teams underestimate how much time goes into scaling infrastructure they built themselves, even with trusted open source components underneath it.
"Do I want to continue getting up at two o'clock in the morning because something is wrong, or do I want to outsource that infrastructure piece to somebody who is actually good at this?" Ihme says. "That way I can focus on what I'm doing."
Ihme frames LimaCharlie as a hyperscaler for cyber security operations, the way AWS became one for IT teams: a functional setup takes about a week, and what gets built on top of it after that is open ended.
"You can spend the next five years building on top of it," he says. "It's a good idea factory. You start tinkering with it and ideas just start flowing out."
To see how LimaCharlie can help you build and scale a managed detection and response practice, try the SecOps Cloud Platform for free or book a demo at limacharlie.io.