Defensio SOC
SOC as a service: EU-sovereign managed detection and response

The command centre of the Defensio ecosystem. It receives telemetry from the sensors and the scanning engines, runs it through a multi-stage AI pipeline, and brings analysts only what deserves a human decision.

Two ways to have it. As a managed MDR service, where the sensors installed at your site connect to Fidem’s operations centre — or under licence, for companies and partners who buy the SOC and run it themselves, with their own control room, their own sensors and their own customers connected. Both are in production today.

What the SOC gives you

Choosing the SOC gives you the complete operations centre. The other components of the ecosystem switch on when you need them — the SOC is the point of command, not a closed bundle.

Connected sensors

The Defensio Sensor units linked to the centre for continuous monitoring of internal networks.

Dedicated scanning engines

External scanning instances tied to the centre, redundant, each with its own dedicated public address.

Multi-stage AI pipeline

Automated triage with context enrichment, independent cross-validation and deep reasoning, run entirely on premises.

Next-generation reporting

Compliance-ready documents — executive, technical, compliance and custom — generated and distributed on schedule.

Control room

Analysts for tactical assessment, guided escalation and incident response, working from Italy.

The pipeline: staged, cross-checked, human at the end

Every alert passes through a chain of progressive checks. A machine-learning gatekeeper filters out ordinary noise in milliseconds. What survives is enriched with context — the asset involved, its known vulnerabilities, any contact with the decoy services, historical behaviour, address reputation, lateral movement patterns. Triage then turns technical detail into a clear explanation. An independent cross-validation has the evidence reassessed a second time; when the two do not agree, the case is escalated to deep reasoning, which maps the attack to MITRE ATT&CK, correlates events across different sensors and prepares the tactical briefing.

The analyst receives investigations that are already assembled and decides on containment — and every confirmation or correction they make flows back into the system. The whole pipeline runs on premises, on Fidem infrastructure in Italy, air-gapped, with defences against prompt injection on incoming data. No customer data leaves the perimeter.

What that looks like in the control room

A morning briefing summarises the night. An incident storyline reconstructs attack chains by correlating events across sources. An escalation inbox records every analyst decision in a complete audit trail.

Inside the control room

Fleet management

The health of every sensor in the fleet — hardware, services, engines — and remote management of all of them from one place.

Threat detection

Triage dashboards with severity classification and intelligent grouping by signature and by customer, over an investigable history.

Threat intelligence

Continuous enrichment from institutional and global sources: actively exploited vulnerabilities, exploitation probability, address reputation.

Task orchestration

Centralised scheduling of scans across the whole fleet, and report generation for each customer separately.

Customer control centre

A per-customer view of active engines, scan tasks and reporting, so nothing is shared between tenants.

Advisory SOAR

Response actions suggested by the system stay recommendations subject to human approval. No blind automation on your network.

Three ways to run triage

The mode is chosen by the organisation, and it can change. Human oversight is structural in all three.

Manual

Analysts run triage through the correlation dashboard, with enrichment and correlation done by hand. For organisations that want complete human control over every judgement made.

Hybrid

The gatekeeper filters noise automatically while assessment and final correlation stay with the analysts. If quality metrics fall below threshold the system steps back to manual on its own.

Full pipeline

The complete chain is active — enrichment, triage, independent cross-validation and deep reasoning with technique mapping. Investigations reach the analyst ready for a decision.

Privacy by design

The AI architecture is built to run fully air-gapped. Models execute locally on dedicated infrastructure: no customer network data ever leaves the perimeter, no third-party cloud, no external calls for analysis. Fidem is certified to ISO/IEC 27001, 27017, 27018 and ISO 9001, and Defensio is registered at CSA STAR Level 1.

Defensio SOC and NIS2

The directive is not satisfied with documentation: it asks for operating infrastructure. The SOC answers the technical obligations of Article 21, component by component.

  • Sensor — continuous internal network monitoring, vulnerability assessment and anomaly detection (Art. 21 §2(b)).
  • External scanning engines and XT — monitoring of the external attack surface and the digital supply chain (Art. 21 §2(d)).
  • Staged triage — the ability to identify and classify significant incidents within the time the notification process assumes (24h early warning, 72h formal notification).
  • Reporting — automated compliance-ready documents for inspections, as a documentary evidence pack.
  • Control room — the human presence expected of essential entities in critical sectors.
  • On-premise AI — all data stays on Italian infrastructure, nothing sent to foreign clouds, meeting both data residency and GDPR expectations.

Fidem runs the full compliance programme in Italy: NIS2 compliance with Fidem.

Common questions

Can the SOC act directly on our systems?

The model is advisory. The SOC detects, correlates, decides severity and guides you with precise containment instructions. Actions on your infrastructure stay agreed with your team — there is no blind automation on your network.

Does the AI replace the analysts?

No, it multiplies them. It removes noise and prepares investigations; tactical decisions stay with identifiable professionals, and every piece of feedback they give improves the system.

Where is the data processed?

Entirely on Fidem infrastructure in Italy, with on-premise air-gapped AI: no third-party cloud and no external calls for analysis.

Can we start with one component and move to the SOC later?

Yes. Sensor, XT and SECaaS can each be bought on their own, and the link to the operations centre is switched on when you want it, without redoing anything.

Can we buy the SOC and run it ourselves?

Yes. Companies and partners licence the SOC and operate it with their own control room, their own sensors and their own customers connected. It is not exclusive to Fidem’s own service.

Talk to us about the SOC

From SMEs to enterprise, finance, healthcare and public administration — the centre scales with the volume and the complexity you actually have.

Request a SOC walkthrough

Do not need the full centre? Defensio Sensor · Defensio XT · Defensio SECaaS · Identity Shield · All products