24/7 Managed SOC
Your teams cannot stay on watch around the clock. We do it for them, with analysts based between Côte d’Ivoire and Morocco and a cloud SaaS infrastructure or one deployed on your own premises.
An alert nobody handles is an alert wasted
Most serious incidents do not begin with an invisible signal: they begin with a signal nobody looked at. Building an in-house team able to cover nights, weekends and public holidays is out of reach for most organisations.
A managed SOC provides that permanent watch without the structural cost. You keep control of your data and your decisions; we bring the monitoring, the analysis and the qualification.
- Monitoring and detection of security events, 24 hours a day, 7 days a week
- Threat intelligence contextualised to your sector and your brand
- Dark web watch on leaks and mentions concerning you
- Detection and monitoring of vulnerabilities affecting your components
- Availability monitoring of your SIEM infrastructure
- SIEM administration and operational maintenance
- Ongoing compliance with the applicable standards and regulations
- Remote assistance on security matters
- Technology watch across the SOC perimeter
From raw event to decision
Each stage reduces the volume and increases the value of the signal passed on to your teams.
Collection
Onboarding and normalisation of sources: systems, network, security, applications, cloud.
Detection
Use cases aligned with MITRE ATT&CK, correlation and enrichment through threat intelligence.
Qualification
Tier 1 then tier 2 human analysis. False positives removed before any notification.
Notification
A qualified, contextualised and prioritised alert, delivered through the agreed channel and within the agreed time.
Support
Containment and remediation recommendations, remote assistance throughout the response.
A setup sized to your exposure
| Component | Essential | Advanced | Extended |
|---|---|---|---|
| Monitoring coverage | 8×5 business hours | 12×5 extended | 24×7 continuous |
| Alert qualification | Tier 1 | Tiers 1 and 2 | Tiers 1, 2 and threat hunting |
| Threat intelligence | Generic feeds | Sector-contextualised | Contextualised to organisation and brand |
| Dark web watch | — | Monthly | Continuous |
| Reporting | Monthly | Monthly plus quarterly steering meeting | Weekly plus monthly steering meeting |
| Incident assistance | Business hours | Extended | Continuous, with on-call cover |
Indicative table. The final setup is agreed at the end of the scoping workshop, based on data volume, number of sources and your regulatory obligations.
What we are asked most often
Where is our data hosted?
Three options: on your own infrastructure (on-premise), in a sovereign private cloud, or on our SaaS platform with an isolated data space. The choice is made during scoping, based on your regulatory obligations. We never move security data outside the agreed framework.
Do we need a SIEM already?
No. If you have one, we operate it — Splunk, Sentinel, Elastic, ArcSight or Wazuh. If you do not, we deploy it as a separate project and then run it. See our SIEM deployment page.
Does a managed SOC replace our in-house team?
It complements it. We take on the permanent watch and the qualification work; your teams keep the decisions, the action on systems and the business knowledge. We work towards skills transfer as a matter of course.
How is service quality measured?
Through contractual indicators: acknowledgement time, qualification time, false positive rate, MITRE ATT&CK coverage of the use cases, platform availability. These indicators are reported at the security steering meeting.
What happens during a major incident?
An escalation procedure is defined at the outset: contacts, channels, response times and on-call levels. We support you remotely on containment and remediation, and produce a post-mortem incident report.
Let us assess your current setup
The scoping workshop produces an honest picture: what is covered, what is not, and what needs addressing first. Two hours, no commitment.