SOCaaS / MDR — Security Operations Center
Continuous 24/7 monitoring of your infrastructure with expert analysts and advanced detection technology. Proactive threat hunting, real-time threat detection, and managed response — without building your own SOC.
Correlated alert · endpoint isolated
- Correlated alert · endpoint isolatednow
- Identity anomaly under investigation−8s
- Compromised account disabled−12s
- Event correlated in the SIEM−16s
Example activity and illustrative indicators, not real client data.
Why do you need SOCaaS / MDR — Security Operations Center?
Building an in-house SOC means hiring analysts for three shifts, licensing detection technology, and maintaining the operation — before detecting a single threat
You can't afford a threat going unnoticed outside business hours
Your security tools generate thousands of daily alerts that nobody reviews
NIS2 requires 24/7 detection and response capabilities and your team can't cover it
What makes us different
Four pillars that apply to every service and every solution, not a one-off slogan.
Offensive + defensive + AI
The same team that attacks in the pentest runs the SOC and builds the AI models. Offensive insight informs defense, and AI is applied where we already operate, not bolted on as an extra layer.
Compliance in weeks, not months
HodeiShield, our own platform, automates continuous assessment, control mapping, and evidence generation — so manual work no longer sets the pace of regulatory compliance.
Sovereignty and proximity
Infrastructure on OVHcloud (France/EU). You speak with the people who sign off on the work, not an account manager who forwards your request to another department.
Our own product
HodeiShield isn't a third-party product we resell: we build and operate it ourselves, and that's what lets us offer faster compliance and evidence that's always current.
What's included
Deliverables and results you will receive with this service.
24/7/365 Monitoring
Operations center with Tier 1, 2, and 3 analysts monitoring your infrastructure in real time. Complete, uninterrupted coverage.
Advanced Detection (EDR/XDR)
Deployment and management of EDR/XDR agents on endpoints, servers, and cloud. Event correlation with threat intelligence.
Proactive Threat Hunting
Our analysts actively hunt for threats that evade automated detections. Hypotheses based on MITRE ATT&CK TTPs.
Managed Detection & Response (MDR)
When we detect a real threat, we act: endpoint isolation, IP blocking, disabling compromised accounts.
Vulnerability Management (VMaaS)
Continuous vulnerability scanning, risk-based prioritization, and remediation tracking.
Executive Reporting
Monthly reports with security metrics, detected threats, SLA compliance, and improvement recommendations.
Methodology
Discovery, execution, delivery, and follow-up — the framework we follow on every project.
Discovery
We assess your environment, data sources, and current tools to design monitoring coverage before deploying anything.
Execution
We deploy agents and sensors, connect your data sources, and establish your environment's normal behavior to tune detections.
Delivery
We go into 24/7/365 operations: uninterrupted monitoring, detection, investigation, and response by our analyst team.
Follow-up
Monthly reports, quarterly reviews, and ongoing tuning of rules and playbooks as the threat landscape evolves — the service doesn't end, it improves.
How we work
Structured methodology to ensure measurable and repeatable results.
Onboarding and Deployment
Ramp-up phase: we assess your environment, deploy agents and sensors, configure rules, and connect your data sources.
Baseline and Tuning
We establish the normal behavior of your environment to minimize false positives and tune detections before going into operations.
Continuous 24/7/365 Operations
From here the service does not end: uninterrupted monitoring, detection, investigation, and response by our analyst team, every day of the year.
Continuous Improvement, Always On
A recurring cycle within operations: monthly reports, quarterly reviews, and ongoing tuning of rules and playbooks as the threat landscape evolves.
Operational example
A real scenario of how we work, not a marketing figure.
An EDR generates an alert for obfuscated PowerShell execution on a server at 2am. A Tier 1 analyst investigates it, correlates it with MITRE ATT&CK TTPs, and — once confirmed as a real threat — escalates to Tier 2 to isolate the machine from the network, without waiting for someone to review it the next morning.
Is it for your company?
This service is designed for organizations that identify with these profiles.
Compared to a generalist integrator
No names — here's how we work differently, with verifiable facts.
| Criteria | Generalist integrator | Hodeitek |
|---|---|---|
| Focus | Dozens of business lines; cybersecurity is just one of them | 100% cybersecurity and AI |
| Point of contact | An account manager who forwards your request to another department | Direct contact with the founders |
| Regulatory compliance | One-off reports per regulation, manual evidence management | HodeiShield automates evidence and cross-framework NIS2/ENS/DORA mapping |
| Product | Resells third-party licenses | Builds and operates HodeiShield, its own platform |
How does it compare to the alternatives?
An honest comparison, with no named competitors: how Hodeitek differs from native tooling, doing it with your own team, or a generic integrator — and when we are NOT the right fit.
When NOT to choose Hodeitek
- You already run a mature in-house SOC with 24/7 coverage and only need point tools, not an external team.
- Your event volume is low enough that your SIEM's alerts, reviewed manually during business hours, are already sufficient.
- You're optimizing purely for the lowest market price and don't need traceability over who analyzes your alerts.
Regulatory compliance
How what this service already includes relates to NIS2, DORA, and the AI Act — article by article, with no invented coverage.
| Framework | Article | What it requires | How this service helps |
|---|---|---|---|
| NIS2 | Art. 21(2)(b) | Have incident-handling capability. | 24/7/365 monitoring, EDR/XDR detection, and managed response (MDR) provide the incident-handling capability this article asks for, running every day of the year. |
| NIS2 | Art. 23 | Notify significant incidents: early warning within 24h, incident notification within 72h, and a final report within 1 month. | Our analysts investigate and classify every alert in real time, as in this service's operational example — that early detection and triage is the basis for meeting those deadlines; the formal notification to the competent authority remains your organization's responsibility. |
| DORA | Art. 17–23 | Establish an ICT incident management, classification and reporting process. | Monthly executive reporting and MITRE ATT&CK TTP-based investigation of every alert give your compliance team the classification and history this DORA block requires you to document. |
- Framework
- NIS2
- Article
- Art. 21(2)(b)
- What it requires
- Have incident-handling capability.
- How this service helps
- 24/7/365 monitoring, EDR/XDR detection, and managed response (MDR) provide the incident-handling capability this article asks for, running every day of the year.
- Framework
- NIS2
- Article
- Art. 23
- What it requires
- Notify significant incidents: early warning within 24h, incident notification within 72h, and a final report within 1 month.
- How this service helps
- Our analysts investigate and classify every alert in real time, as in this service's operational example — that early detection and triage is the basis for meeting those deadlines; the formal notification to the competent authority remains your organization's responsibility.
- Framework
- DORA
- Article
- Art. 17–23
- What it requires
- Establish an ICT incident management, classification and reporting process.
- How this service helps
- Monthly executive reporting and MITRE ATT&CK TTP-based investigation of every alert give your compliance team the classification and history this DORA block requires you to document.
Informational mapping, not legal advice: it describes how what we already do in this service helps comply with or provides evidence for each article — it doesn't replace a compliance assessment tailored to your organization.
Frequently asked questions
How do you cover 24/7?
What's your response SLA?
How much does it cost compared to an in-house SOC?
What technologies do you use?
How long does onboarding take?
Can we keep our current tools?
How are you different from a generalist integrator?
Is SOCaaS/MDR the same across sectors?
24/7 monitoring without expanding your team
Talk to our team of experts to design a plan tailored to your organization's needs.
Response within 24h
Case studies
How we've applied this service in real projects.
Related services
Solutions that apply this service
Third-Party & Supply Chain Risk Management
Assess, monitor, and govern the cybersecurity risk introduced by your vendors, third-party software, and your organization's Nth-party dependencies.
NIS2 Compliance
Comprehensive guidance to achieve and maintain compliance with the European NIS2 cybersecurity directive.
Ransomware Protection and Response
Hodeitek's team are Spanish regulatory specialists as well as ransomware responders: the controls below apply everywhere, and where we reference Spain's National Security Framework (ENS, set by Spain's National Cryptologic Center, CCN) or the EU's DORA regulation, that's Spain- or EU-specific context for organizations operating there or in its regulated sectors. Comprehensive strategy for prevention, early detection, and rapid response to ransomware attacks.