Silent Push partners with Vexelon to bring preemptive cyber defense to the Western Balkans

Brad Taylor
Brad Taylor
Global Head of Strategic Partnerships and Alliances, Silent Push

I’m excited to announce our strategic partnership with Vexelon, a cybersecurity firm providing managed security operations, incident response, and advisory services across the Western Balkans. Through this partnership, Vexelon clients gain access to the Silent Push Preemptive Cyber Defense platform, bringing upstream infrastructure visibility into the heart of a managed SOC operation serving one of Europe’s most actively targeted regions.

Vexelon runs round-the-clock security operations for organisations across North Macedonia and Kosovo, with a team certified across OSCP, OSWE, CEH, and ISO 27001. Their work covers SOC-as-a-Service, managed detection and response, attack surface management, incident response, and compliance readiness. For a lot of their clients, Vexelon is the security team, full stop. That kind of relationship is where preemptive intelligence really earns its keep.

A region that has learned the hard way

The Western Balkans has spent the past few years learning something the rest of Europe is still working through. Cyber threats here are targeted, they tie into bigger geopolitical tensions, and they keep picking up pace.

Since Russia’s full-scale invasion of Ukraine, state-linked actors have used the Balkans as a testing ground for hybrid warfare tactics. Russian-speaking groups disrupted Montenegrin government services for weeks in 2022. Iranian-linked actors hit Albanian parliament and critical infrastructure, leading Albania to sever diplomatic ties with Tehran. Kosovo faced attacks on telecommunications and media bodies. North Macedonia has experienced relentless targeting of state institutions, from the Health Insurance Fund to the Agriculture Ministry, often leaving agencies without systems for weeks at a time. In March 2026, Iranian-linked hackers from Homeland Justice again targeted Albanian institutions, publishing sensitive parliamentary data.

There’s a familiar pattern running through these incidents. Attackers set up their infrastructure quietly, get their staging grounds in place, and start operating well before anyone notices. By the time a SOC alert goes off, the prep work is done and the attacker already has a head start.

What changes when the SOC starts earlier

Vexelon’s clients have outsourced their security operations entirely. What Vexelon can see, act on, and prevent directly determines what those organisations experience. That dependency makes the quality of the underlying data more important than in almost any other model.

A lot of SOC workflows kick in too late in the story. The alert lands once the attacker is already up and running, so the analyst is triaging, investigating, and responding against infrastructure that’s been live for weeks. The SOC is genuinely good at the job. The trouble is the starting position, which the adversary set in advance.

The Context Graph changes that starting position. It continuously maps how infrastructure is created, managed, and connected across DNS, WHOIS, certificates, and hosting data at internet scale. When the management patterns match the TTPs adversaries use to build and coordinate campaigns, the Context Graph surfaces those clusters as Indicators of Future Attack® (IOFA): verified signals that a staging ground exists before it has been pointed at anyone. Vexelon’s SOC now has an average of 154 days of lead time before a campaign reaches a client’s perimeter.

That lead time helps both human analysts and automated detection and response workflows. Vexelon runs these automated workflows for their clients, and the Context Graph was built to be machine-readable from day one, with APIs made for automated enrichment and triage and signals that carry clear data provenance. Feed IOFA into those workflows and automated triage gets to work from deterministic infrastructure facts instead of probabilistic scores and noisy feeds. False positives go down, decisions speed up, and the team can actually stand behind the actions those workflows take.

For a managed SOC running security on behalf of organisations that have no in-house capability to fall back on, that difference matters every single day.

Adversary operations are built on infrastructure that is assembled long before execution is visible to a SOC. Traditional detection starts at telemetry, which is already post-deployment from an attacker’s perspective. By integrating upstream infrastructure intelligence into our SOC pipeline, we extend visibility into the adversary’s build phase, allowing us to identify staging activity before it becomes an active threat.

Valon Dauti
Founder & CEO, Vexelon Cybersecurity

The right moment for the region

The Western Balkans is undergoing a significant shift in how it approaches cybersecurity. EU accession requirements are driving NIS2 alignment across the region. Countries including Albania, Montenegro, and North Macedonia are investing in national cybersecurity capacity after years of fragmented, reactive frameworks. Organisations that previously had no formal security posture are now building one, and many are turning to managed service providers like Vexelon to do it.

That’s where the foundation really matters. Organisations standing up their security programs for the first time get to build on preemptive intelligence from the start. Bringing the Context Graph into Vexelon’s managed SOC gives their clients a security operations capability that can spot adversary infrastructure being assembled before it’s ever turned against them.

To learn more about how Silent Push and Vexelon can protect your organisation, visit vexelon.io or book a walkthrough with our team.