Skip to main content
Cybersecurity service24/7 MONITORING

SOCaaS / MDR — Security Operations Center

Continuous 24/7 monitoring of your infrastructure with expert analysts and advanced detection technology. Proactive threat hunting, real-time threat detection, and managed response — without building your own SOC.

NIS2DORAMITRE ATT&CK24/7/365
Typical duration
Ongoing
Deliverables
6+
Methodologies
MITRE ATT&CK · NIST 800-61 · SANS IH
Next response SLA
< 24h
6DeliverablesInternal analysisInternal Hodeitek analysis: real count of the deliverables and phases defined for this service.
4Process phasesInternal analysisInternal Hodeitek analysis: real count of the deliverables and phases defined for this service.
0Zero production impactInternal analysisInternal Hodeitek analysis: an operating commitment for the service, not an audited metric.

Why do you need SOCaaS / MDR — Security Operations Center?

Building an in-house SOC means hiring analysts for three shifts, licensing detection technology, and maintaining the operation — before detecting a single threat

You can't afford a threat going unnoticed outside business hours

Your security tools generate thousands of daily alerts that nobody reviews

NIS2 requires 24/7 detection and response capabilities and your team can't cover it

What makes us different

Four pillars that apply to every service and every solution, not a one-off slogan.

Offensive + defensive + AI

The same team that attacks in the pentest runs the SOC and builds the AI models. Offensive insight informs defense, and AI is applied where we already operate, not bolted on as an extra layer.

Compliance in weeks, not months

HodeiShield, our own platform, automates continuous assessment, control mapping, and evidence generation — so manual work no longer sets the pace of regulatory compliance.

Sovereignty and proximity

Infrastructure on OVHcloud (France/EU). You speak with the people who sign off on the work, not an account manager who forwards your request to another department.

Our own product

HodeiShield isn't a third-party product we resell: we build and operate it ourselves, and that's what lets us offer faster compliance and evidence that's always current.

What's included

Deliverables and results you will receive with this service.

24/7/365 Monitoring

Operations center with Tier 1, 2, and 3 analysts monitoring your infrastructure in real time. Complete, uninterrupted coverage.

Advanced Detection (EDR/XDR)

Deployment and management of EDR/XDR agents on endpoints, servers, and cloud. Event correlation with threat intelligence.

Proactive Threat Hunting

Our analysts actively hunt for threats that evade automated detections. Hypotheses based on MITRE ATT&CK TTPs.

Managed Detection & Response (MDR)

When we detect a real threat, we act: endpoint isolation, IP blocking, disabling compromised accounts.

Vulnerability Management (VMaaS)

Continuous vulnerability scanning, risk-based prioritization, and remediation tracking.

Executive Reporting

Monthly reports with security metrics, detected threats, SLA compliance, and improvement recommendations.

Methodology

Discovery, execution, delivery, and follow-up — the framework we follow on every project.

Discovery

Discovery

We assess your environment, data sources, and current tools to design monitoring coverage before deploying anything.

Execution

Execution

We deploy agents and sensors, connect your data sources, and establish your environment's normal behavior to tune detections.

Delivery

Delivery

We go into 24/7/365 operations: uninterrupted monitoring, detection, investigation, and response by our analyst team.

Follow-up

Follow-up

Monthly reports, quarterly reviews, and ongoing tuning of rules and playbooks as the threat landscape evolves — the service doesn't end, it improves.

How we work

Structured methodology to ensure measurable and repeatable results.

1

Onboarding and Deployment

Ramp-up phase: we assess your environment, deploy agents and sensors, configure rules, and connect your data sources.

2

Baseline and Tuning

We establish the normal behavior of your environment to minimize false positives and tune detections before going into operations.

3

Continuous 24/7/365 Operations

From here the service does not end: uninterrupted monitoring, detection, investigation, and response by our analyst team, every day of the year.

4

Continuous Improvement, Always On

A recurring cycle within operations: monthly reports, quarterly reviews, and ongoing tuning of rules and playbooks as the threat landscape evolves.

Operational example

A real scenario of how we work, not a marketing figure.

An EDR generates an alert for obfuscated PowerShell execution on a server at 2am. A Tier 1 analyst investigates it, correlates it with MITRE ATT&CK TTPs, and — once confirmed as a real threat — escalates to Tier 2 to isolate the machine from the network, without waiting for someone to review it the next morning.

Is it for your company?

This service is designed for organizations that identify with these profiles.

Companies needing 24/7 monitoring without building a SOC
Organizations with NIS2/DORA continuous detection requirements
Companies with IT staff but no security analysts
Companies looking to outsource security operations

Compared to a generalist integrator

No names — here's how we work differently, with verifiable facts.

CriteriaGeneralist integratorHodeitek
FocusDozens of business lines; cybersecurity is just one of them100% cybersecurity and AI
Point of contactAn account manager who forwards your request to another departmentDirect contact with the founders
Regulatory complianceOne-off reports per regulation, manual evidence managementHodeiShield automates evidence and cross-framework NIS2/ENS/DORA mapping
ProductResells third-party licensesBuilds and operates HodeiShield, its own platform

How does it compare to the alternatives?

An honest comparison, with no named competitors: how Hodeitek differs from native tooling, doing it with your own team, or a generic integrator — and when we are NOT the right fit.

DimensionHodeitekNative tool/SIEMIn-house (DIY)Generic integrator
Coverage and hours24/7/365: our own analysts during European business hours, with a specialized EU partner covering nights and weekends.The SIEM generates alerts 24/7, but no one reviews them outside your business hours unless you staff extra shifts.Requires hiring, training, and retaining analysts to cover 3 rotating shifts — before detecting a single real threat.Often subcontracts the night SOC to a third party with no visibility for the client into who is analyzing their alerts.
Reference frameworkMITRE ATT&CK and NIST 800-61 as the operating reference, documented case by case.Depends on the correlation rules you configure and keep up to date yourself.Triage criteria vary with the experience of each analyst you hire.Methodology not always public or auditable by the client.
Cost modelA recurring service, with no upfront investment in licenses, hardware, or building an in-house team.License and log-storage costs that grow with volume, even when nobody is actively monitoring the system.The cost of hiring and retaining several SOC analysts plus detection technology — a sizable investment before you're even operational.Variable cost depending on how much is subcontracted and the integrator's margin.
When it makes senseYou need continuous coverage and managed response without building the team yourself.You already have an in-house team that can operate and respond to the SIEM's alerts full-time.You have the budget and time to build, train, and retain your own SOC team long-term.You're optimizing purely for the lowest market price and can accept less traceability over who analyzes your alerts.

When NOT to choose Hodeitek

  • You already run a mature in-house SOC with 24/7 coverage and only need point tools, not an external team.
  • Your event volume is low enough that your SIEM's alerts, reviewed manually during business hours, are already sufficient.
  • You're optimizing purely for the lowest market price and don't need traceability over who analyzes your alerts.

Regulatory compliance

How what this service already includes relates to NIS2, DORA, and the AI Act — article by article, with no invented coverage.

  • Framework
    NIS2
    Article
    Art. 21(2)(b)
    What it requires
    Have incident-handling capability.
    How this service helps
    24/7/365 monitoring, EDR/XDR detection, and managed response (MDR) provide the incident-handling capability this article asks for, running every day of the year.
  • Framework
    NIS2
    Article
    Art. 23
    What it requires
    Notify significant incidents: early warning within 24h, incident notification within 72h, and a final report within 1 month.
    How this service helps
    Our analysts investigate and classify every alert in real time, as in this service's operational example — that early detection and triage is the basis for meeting those deadlines; the formal notification to the competent authority remains your organization's responsibility.
  • Framework
    DORA
    Article
    Art. 17–23
    What it requires
    Establish an ICT incident management, classification and reporting process.
    How this service helps
    Monthly executive reporting and MITRE ATT&CK TTP-based investigation of every alert give your compliance team the classification and history this DORA block requires you to document.

Informational mapping, not legal advice: it describes how what we already do in this service helps comply with or provides evidence for each article — it doesn't replace a compliance assessment tailored to your organization.

Frequently asked questions

How do you cover 24/7?
During business hours the SOC is run by Hodeitek's own team. Outside those hours, monitoring continues with a European partner working to our same procedures and escalation paths, so coverage never stops and the data stays in the EU.
What's your response SLA?
First response within 24 business hours of reaching out. If what you need is an exposure assessment, we deliver it in full within 48 business hours.
How much does it cost compared to an in-house SOC?
We don't publish a generic savings figure we can't back for your specific case: in-house SOC cost depends on your size and sector. We do always share a line-by-line comparison — three-shift analysts, licensing and 24/7 operations in-house versus our fee — so the decision is made on real numbers, not a marketing percentage.
What technologies do you use?
Sekoia.io (SIEM/XDR), market-leading EDR (Bitdefender, Kaspersky), and our own automation tools.
How long does onboarding take?
Initial deployment takes 2-4 weeks. The tuning phase is typically an additional 4-6 weeks.
Can we keep our current tools?
Yes. We integrate with your existing stack. If you need new tools, we deploy and manage them as part of the service.
How are you different from a generalist integrator?
A generalist integrator often subcontracts the SOC to a third party; at Hodeitek the analysts are our own team, referencing MITRE ATT&CK and NIST 800-61, and HodeiShield is our own tool for managing your vendor risk within the same service. You deal directly with the founders.
Is SOCaaS/MDR the same across sectors?
The 24/7 coverage and MITRE ATT&CK TTPs we monitor are the same, but playbooks are tailored: in industry/OT we include detection specific to industrial protocols; in financial services and the public sector, reporting aligns with DORA's and ENS's notification deadlines; for SMEs, it directly replaces an in-house SOC that wouldn't be viable to build on their budget.

24/7 monitoring without expanding your team

Talk to our team of experts to design a plan tailored to your organization's needs.

Response within 24h