Under attack?
Managed Security Service

24/7 Managed SOC

Your teams cannot stay on watch around the clock. We do it for them, with analysts based between Côte d’Ivoire and Morocco and a cloud SaaS infrastructure or one deployed on your own premises.

  • 24/7 monitoring
  • Threat intelligence
  • Dark web watch
  • Vulnerability management
  • Sovereignty
The problem

An alert nobody handles is an alert wasted

Most serious incidents do not begin with an invisible signal: they begin with a signal nobody looked at. Building an in-house team able to cover nights, weekends and public holidays is out of reach for most organisations.

A managed SOC provides that permanent watch without the structural cost. You keep control of your data and your decisions; we bring the monitoring, the analysis and the qualification.

Security operations room: an analyst facing a wall of monitoring screens
What the service covers
  • Monitoring and detection of security events, 24 hours a day, 7 days a week
  • Threat intelligence contextualised to your sector and your brand
  • Dark web watch on leaks and mentions concerning you
  • Detection and monitoring of vulnerabilities affecting your components
  • Availability monitoring of your SIEM infrastructure
  • SIEM administration and operational maintenance
  • Ongoing compliance with the applicable standards and regulations
  • Remote assistance on security matters
  • Technology watch across the SOC perimeter
How it works

From raw event to decision

Each stage reduces the volume and increases the value of the signal passed on to your teams.

Detection chain: collection, correlation, human qualification, alert
1

Collection

Onboarding and normalisation of sources: systems, network, security, applications, cloud.

2

Detection

Use cases aligned with MITRE ATT&CK, correlation and enrichment through threat intelligence.

3

Qualification

Tier 1 then tier 2 human analysis. False positives removed before any notification.

4

Notification

A qualified, contextualised and prioritised alert, delivered through the agreed channel and within the agreed time.

5

Support

Containment and remediation recommendations, remote assistance throughout the response.

Service levels

A setup sized to your exposure

ComponentEssentialAdvancedExtended
Monitoring coverage8×5 business hours12×5 extended24×7 continuous
Alert qualificationTier 1Tiers 1 and 2Tiers 1, 2 and threat hunting
Threat intelligenceGeneric feedsSector-contextualisedContextualised to organisation and brand
Dark web watchMonthlyContinuous
ReportingMonthlyMonthly plus quarterly steering meetingWeekly plus monthly steering meeting
Incident assistanceBusiness hoursExtendedContinuous, with on-call cover

Indicative table. The final setup is agreed at the end of the scoping workshop, based on data volume, number of sources and your regulatory obligations.

Frequently asked

What we are asked most often

Where is our data hosted?

Three options: on your own infrastructure (on-premise), in a sovereign private cloud, or on our SaaS platform with an isolated data space. The choice is made during scoping, based on your regulatory obligations. We never move security data outside the agreed framework.

Do we need a SIEM already?

No. If you have one, we operate it — Splunk, Sentinel, Elastic, ArcSight or Wazuh. If you do not, we deploy it as a separate project and then run it. See our SIEM deployment page.

Does a managed SOC replace our in-house team?

It complements it. We take on the permanent watch and the qualification work; your teams keep the decisions, the action on systems and the business knowledge. We work towards skills transfer as a matter of course.

How is service quality measured?

Through contractual indicators: acknowledgement time, qualification time, false positive rate, MITRE ATT&CK coverage of the use cases, platform availability. These indicators are reported at the security steering meeting.

What happens during a major incident?

An escalation procedure is defined at the outset: contacts, channels, response times and on-call levels. We support you remotely on containment and remediation, and produce a post-mortem incident report.

Let us assess your current setup

The scoping workshop produces an honest picture: what is covered, what is not, and what needs addressing first. Two hours, no commitment.