TECHPERFORMANCE
Solution · Managed cybersecurity

No more background noise eating your backend.
Crowdsec + WAF + threat intel, run 24/7.

Brute-force, scraping, bot fingerprinting, custom scenarios for your workload. Stopped at the edge, not on your origin. NIS2-ready cyber posture, run by a real team.

The problem

Three things we see on practically every new client.

01
// anti-pattern · cybersecurity

Constant brute-force on logins, fail2ban on a node that does not talk to the rest.

Every server reacts in isolation, the same IPs are tried across the network, nobody shares what they already learned to block.

02
// anti-pattern · cybersecurity

Aggressive scraping that eats your bandwidth and database.

Bots making millions of requests disguised as real users, hot application paths under stress, cloud costs rising for traffic that converts nothing.

03
// anti-pattern · cybersecurity

No single view of what you are actually being hit with.

Logs scattered across ten machines, alerts arriving from five different sources, MTTR on a new threat measured in days instead of hours.

How we run it

An operated cyber posture, not one bought and forgotten.

Cybersecurity is not a product, it is a process. The stack is only the base — on top of it there is the daily reading of patterns, scenarios updated on your workload, the honest post-mortem when something got through.

  • →Same team from single site to HA cluster.
  • →Response within 1h with an SRE, not a dispatcher.
  • →Entirely EU infrastructure.
stack · managed cybersecurity
NIS2-ready
  • Crowdsec with community threat intel
    globally shared scenarios, distributed decisions, custom rules for your workload
  • Two-layer WAF
    edge protection (Cloudflare) + application WAF (ModSecurity + OWASP CRS 4) on the origin
  • iptables / nftables hardening
    CIS-aligned baseline, geo-rules, rate-limiting on sensitive endpoints
  • Pi-hole / AdGuard Home DNS filtering
    anti-tracking and anti-malware protection for the internal operational network
  • Log centralization on Loki
    cross-host correlation, Grafana dashboards for attack patterns, configurable retention
  • Multi-channel alerts + SRE on-call
    email/app/phone notification, response within 1h, no first-level chatbot
Expected results

What changes, measured on the real portfolio.

The operational advantage of running a portfolio: the patterns we discover on one client become rules for everyone, within hours.

at the edge

the vast majority of malicious traffic blocked before the backend, not on your origin

MTTR in hours

reaction time to a new threat measured in hours, not days — thanks to community + custom scenarios

single view

emerging patterns seen on one client become rules for everyone — the portfolio becomes shared intelligence

In production

Threat intel applied to the entire managed portfolio.

When a new scenario hits one of the outlets we run, we block it, isolate it, write the rule, propagate it. Every client receives it before seeing it. That is how a truly managed portfolio behaves.

See all case studies
Portfolio Tech Performance
Aggregated and anonymized data
Network · publishing + sport
edge
blocking level
< h
MTTR new threat
N → 1
shared rules

Aggregated pattern across Tech Performance clients: high-traffic digital publishing, Serie A sports clubs, local outlets, agencies. Same operational model, same shared threat intel.

FAQ

Questions we get from DPOs, CTOs, IT managers.

If yours is different, write to us: we reply within the day.

What changes compared to home-made fail2ban?
Fail2ban is a good base, but it lives on a single host. Crowdsec inherits the same philosophy and adds two things that change the posture: community threat intel (malicious IPs are shared by the global network, you do not wait to be hit to learn) and distributed decisions (the decision engine is not on the attacked node). On top of that, custom scenarios on your workload: WP brute-force, scraping of editorial patterns, anti-bot on ticketing.
How much does NIS2 weigh on these decisions?
NIS2 (D.Lgs. 138/2024) imposes cyber risk management measures on essential and important entities — categories that include relevant digital publishing, above-threshold e-commerce, and public administration. Managed cybersecurity is one of the most critical chapters of compliance: having a firewall is not enough, you must demonstrate active management, centralized logs, incident response time. What we deliver here is the operational base of a compliant posture — it does not replace a DPO, but gives them verifiable material.
Is it an alternative to an enterprise MSSP?
Depending on the scale. For SMBs, agencies and editorial networks up to a few dozen nodes, the Crowdsec + WAF + centralized logs stack operated by Tech Performance is enough and far more transparent than the base tiers of Italian MSSPs. Above certain sizes it complements rather than replaces a dedicated SOC.
My scenarios are specific, can they be customized?
Yes, that is the point. WordPress logins with custom plugins, ticketing areas, mobile APIs, scraping patterns that hit only you: Crowdsec scenarios are written in YAML, versioned in our client repo, deployed like the rest of the stack. No opaque vendor rules.
Free audit

Let’s talk about your stack,
free, no strings attached.

30 minutes with a Romiltec architect. Together we figure out whether Tech Performance is a fit, and if it isn’t, we tell you straight away. No cold pitch, no black-box quote.

Book a call cal.com/romiltec/tech-performance · 30 min call