SOC & Managed detection and response (MDR)
24/7 cyber defence powered by AI and expert analysts
Advanced detection and response deliver real-time cyber defence across IT, cloud, OT and industrial environments. SOC and MDR enable threat hunting and coordinated response, building on MSS foundations.
Next-generation SOC and MDR services
Proactive detection and rapid response to advanced cyber threats
-
24/7 SOC operations
Continuous monitoring and response delivered by eight global Security Operations Centres. Including regional CERT capabilities to provide localised incident response when required.
-
Human-led MDR
Expert analysts investigate, respond, remediate and recover from cyber incidents.
-
AI-driven automation
AI-driven automation and SOAR reduce response times and alert fatigue. Agentic AI enables automated triage and first-level resolution, escalating complex cases to human experts.
-
Full visibility
Detection across IT, cloud, OT, IoT and industrial environments.
-
Industry expertise
Sector-specific detection and threat intelligence for regulated industries.
-
Compliance & Trust
Services aligned with NIS2, DORA, SOCI Act SOC2, ISO 27001 and more.
Modern SOC and MDR Services
Thales SOC and MDR services combine expert analysts, AI‑powered automation and proven processes to detect, investigate and respond to cyber threats in real time. Delivered 24/7 in complex and regulated environments, all alerts are handled through documented playbooks, automatically enriched and tracked via integrated ticketing systems.
Our monitoring includes endpoint detection, public cloud detection, and application-level detection, all while ensuring compliance with national regulations such as LPM (France), SOCI Act (Australia), SOC 2, Esquema Nacional de Seguridad (Spain), as well as European regulations including NIS 2 and DORA, with ENS Level High certification providing a strong foundation to support DORA requirements.
© 123RF
Thales delivers SOC and MDR services through an open, best-of-breed technology ecosystem. Detection and response leverage leading SIEM platforms (IBM QRadar, Microsoft Sentinel, Google SecOps, Splunk, Sekoia) combined with NDR technologies (Nozomi, Gatewatcher, CrowdStrike), endpoint protection (ESET, HarfangLab, SentinelOne), and SOAR orchestration (Palo Alto Cortex XSOAR, The Hive). Our SOC leaves you free to use any security products without being tied to specific vendors. Our highly skilled security analysts hold industry-recognised certifications across these leading security products.
Core SOC and MDR capabilities
Thales SOC team structure
Three pillars of excellence in a 24/7 model to protect your environment.
© 123RF
- SOC analysts serve as the first line of defence, conducting thorough initial assessments of all detections to distinguish true positives from noise, with seamless shift handovers for continuous investigations.
- SOC engineers and AI data engineers optimise detection capabilities through deep infrastructure understanding, providing tailored setup advice and fine-tuning rules to eliminate false positives while leveraging AI and automation to uncover genuine threats.
- SOC administrators manage technical deployment and operational infrastructure, acting as the critical bridge between clients, vendors, and our operations team to ensure smooth incident coordination across diverse technologies.