HodeiShield: The European TPRM platform with native NIS2, ENS, and DORA
Continuous 24/7 monitoring of your infrastructure with expert analysts and advanced detection technology. Proactive threat hunting, real-time threat detection, and managed response — without building your own SOC.
Correlated alert · endpoint isolated
Example activity and illustrative indicators, not real client data.
Building an in-house SOC means hiring analysts for three shifts, licensing detection technology, and maintaining the operation — before detecting a single threat
You can't afford a threat going unnoticed outside business hours
Your security tools generate thousands of daily alerts that nobody reviews
NIS2 requires 24/7 detection and response capabilities and your team can't cover it
Four pillars that apply to every service and every solution, not a one-off slogan.
The same team that attacks in the pentest runs the SOC and builds the AI models. Offensive insight informs defense, and AI is applied where we already operate, not bolted on as an extra layer.
HodeiShield, our own platform, automates continuous assessment, control mapping, and evidence generation — so manual work no longer sets the pace of regulatory compliance.
Infrastructure on OVHcloud (France/EU). You speak with the people who sign off on the work, not an account manager who forwards your request to another department.
HodeiShield isn't a third-party product we resell: we build and operate it ourselves, and that's what lets us offer faster compliance and evidence that's always current.
Deliverables and results you will receive with this service.
Operations center with Tier 1, 2, and 3 analysts monitoring your infrastructure in real time. Complete, uninterrupted coverage.
Deployment and management of EDR/XDR agents on endpoints, servers, and cloud. Event correlation with threat intelligence.
Our analysts actively hunt for threats that evade automated detections. Hypotheses based on MITRE ATT&CK TTPs.
When we detect a real threat, we act: endpoint isolation, IP blocking, disabling compromised accounts.
Continuous vulnerability scanning, risk-based prioritization, and remediation tracking.
Monthly reports with security metrics, detected threats, SLA compliance, and improvement recommendations.
Discovery, execution, delivery, and follow-up — the framework we follow on every project.
We assess your environment, data sources, and current tools to design monitoring coverage before deploying anything.
We deploy agents and sensors, connect your data sources, and establish your environment's normal behavior to tune detections.
We go into 24/7/365 operations: uninterrupted monitoring, detection, investigation, and response by our analyst team.
Monthly reports, quarterly reviews, and ongoing tuning of rules and playbooks as the threat landscape evolves — the service doesn't end, it improves.
Structured methodology to ensure measurable and repeatable results.
Ramp-up phase: we assess your environment, deploy agents and sensors, configure rules, and connect your data sources.
We establish the normal behavior of your environment to minimize false positives and tune detections before going into operations.
From here the service does not end: uninterrupted monitoring, detection, investigation, and response by our analyst team, every day of the year.
A recurring cycle within operations: monthly reports, quarterly reviews, and ongoing tuning of rules and playbooks as the threat landscape evolves.
A real scenario of how we work, not a marketing figure.
An EDR generates an alert for obfuscated PowerShell execution on a server at 2am. A Tier 1 analyst investigates it, correlates it with MITRE ATT&CK TTPs, and — once confirmed as a real threat — escalates to Tier 2 to isolate the machine from the network, without waiting for someone to review it the next morning.
This service is designed for organizations that identify with these profiles.
No names — here's how we work differently, with verifiable facts.
| Criteria | Generalist integrator | Hodeitek |
|---|---|---|
| Focus | Dozens of business lines; cybersecurity is just one of them | 100% cybersecurity and AI |
| Point of contact | An account manager who forwards your request to another department | Direct contact with the founders |
| Regulatory compliance | One-off reports per regulation, manual evidence management | HodeiShield automates evidence and cross-framework NIS2/ENS/DORA mapping |
| Product | Resells third-party licenses | Builds and operates HodeiShield, its own platform |
An honest comparison, with no named competitors: how Hodeitek differs from native tooling, doing it with your own team, or a generic integrator — and when we are NOT the right fit.
How what this service already includes relates to NIS2, DORA, and the AI Act — article by article, with no invented coverage.
| Framework | Article | What it requires | How this service helps |
|---|---|---|---|
| NIS2 | Art. 21(2)(b) | Have incident-handling capability. | 24/7/365 monitoring, EDR/XDR detection, and managed response (MDR) provide the incident-handling capability this article asks for, running every day of the year. |
| NIS2 | Art. 23 | Notify significant incidents: early warning within 24h, incident notification within 72h, and a final report within 1 month. | Our analysts investigate and classify every alert in real time, as in this service's operational example — that early detection and triage is the basis for meeting those deadlines; the formal notification to the competent authority remains your organization's responsibility. |
| DORA | Art. 17–23 | Establish an ICT incident management, classification and reporting process. | Monthly executive reporting and MITRE ATT&CK TTP-based investigation of every alert give your compliance team the classification and history this DORA block requires you to document. |
Informational mapping, not legal advice: it describes how what we already do in this service helps comply with or provides evidence for each article — it doesn't replace a compliance assessment tailored to your organization.
Talk to our team of experts to design a plan tailored to your organization's needs.
Response within 24h
How we've applied this service in real projects.
Assess, monitor, and govern the cybersecurity risk introduced by your vendors, third-party software, and your organization's Nth-party dependencies.
Comprehensive guidance to achieve and maintain compliance with the European NIS2 cybersecurity directive.
Hodeitek's team are Spanish regulatory specialists as well as ransomware responders: the controls below apply everywhere, and where we reference Spain's National Security Framework (ENS, set by Spain's National Cryptologic Center, CCN) or the EU's DORA regulation, that's Spain- or EU-specific context for organizations operating there or in its regulated sectors. Comprehensive strategy for prevention, early detection, and rapid response to ransomware attacks.