Skip to main content
Cybersecurity

Cybersecurity as a service. A defence that decides, acts and learns.

Cybersecurity as a service: 24×7 operations and an AI layer that orchestrates the defence, validated continuously across the 7 information security domains and under your command.

7 domains of security validated continuously
24×7 SOC/MDR with SLA and orchestrated response
On-premises sovereign AI, aligned with the LGPD
Definition · CIOC

What CIOC is.

O CIOC is Central IT's Centre for Cyber Intelligence and Operations: continuous monitoring and AI-powered threat detection across 7 information security domains. We identify, analyse and neutralise risk in real time, before the attack reaches the business. Blue and Red Team on a cycle, orchestrated by AICS (Cybersecurity Intelligence Agents) and senior analysts, with exportable evidence for the board, the auditor and the insurer.

The 7 information security domains (Blue and Red Team)

Red Team
01 Identity and Access Accounts, access and privileges
02 Web and APIs Applications and web exposure
03 Network and Infrastructure Perimeter and segmentation
04 Cloud Posture and configuration
05 Endpoints Workstations and servers
06 Email and Collaboration Phishing and data leakage
07 Social Engineering The human factor
Blue Team

Red Team, Blue Team and AICS integrated. One operation, not 7 products.

Definition · CIOTI

What CIOTI is.

O CIOTI is CIOC's sibling centre: a Centre for IT Intelligence and Operations delivering, as a service, cognitive operations 24×7 across the 11 critical IT towers, orchestrated by an Autonomous NOC and HyperAgents (FAB.IA, VIG.IA) plus senior analysts, with sovereign on-premises AI and ITIL governance.

The 11 IT towers

01 Applications
02 Operating systems
03 Databases
04 Backup
05 Cloud
06 Monitoring
07 Networks
08 Virtualization
09 Security
10 Middleware
11 Storage

Autonomous NOC, AIOps and HyperAgents integrated. One cognitive operation, not 11 silos.

O modelo

Solutions, Operations and Intelligence. No one delivers just one.

Buying a tool without running it leaves it on the shelf. Running it without intelligence leaves alerts without action. This service brings all three together in a model you contract rather than build.

The three pillars

what you buy

Solutions

Market-leading platforms, selected by maturity and criticality. Deployed, integrated and sustained.

who runs it

Operations

SOC, NOC, Blue and Red Team sustaining the operation 24×7, continuous or on demand. Capability contracted, not built.

who orchestrates

Cyber Intelligence

AI applied to cyber. It orchestrates solutions and operations into a single intelligence that decides, acts and learns.

CaaS · Cyber Intelligence as a Service

The umbrella that delivers everything as a service.

A modular SaaS offering: people, technical towers and CITSmart Autonomous. All available together or tailored.

Teams and Services

  • CIOTI, IT Intelligence
  • CIOC, Cyber Intelligence
  • NOC, Network Operations
  • SOC, Security Operations

Observability

  • APM, Application Performance Monitoring
  • MMT, Monitoring & Metric Tracing
  • Event Management

Operational Intelligence

  • AIOps, AI for IT Operations
  • RCA, Root Cause Analysis
  • Predictive Maintenance
  • Anomaly Detection

Digital Experience

  • DEM, Digital Experience Monitoring
  • RUM, Real User Monitoring
  • Synthetic Monitoring

Business and Services

  • BAM, Business Activity Monitoring
  • Operational Resilience
  • Topology & Dependency Mapping
  • Access Control (MFA, IGA)

Security and Compliance

  • SIEM
  • SAST, DAST, IAST
  • Safe-Check (Pentest, BAS, Vulnerability)
  • Anti-Ransomware
  • SecAIOps
CITSmart AutonomousDecision and execution. The layer that orchestrates the six towers.

Assessment, process mapping and rollout consulting included in any format or combination.

Diferencial integrado

NOC and SOC sharing the same intelligence.

The Centre for IT Intelligence and Operations (CIOTI) and the Centre for Cyber Intelligence and Operations (CIOC) run integrated, not in silos.

CIOTI

Infrastructure brain

Centre for IT Intelligence and Operations

  • Autonomous NOC
  • Observabilidade cognitiva + AIOps
  • HyperAgentes + FAB.IA + VIG.IA
  • CITSmart ITSM, 24 processos ITIL
CIOC

Cybersecurity brain

Centre for Cyber Intelligence and Operations

  • Continuous Red Team + Blue Team
  • SOC/MDR 24×7 com SLA
  • AICS + Autonomous (SecOps com IA)
  • 10+ leading platforms operated

Shared intelligence. An infrastructure event can reveal a security threat. A security threat can reveal an operational failure.

A jornada

From your current posture to a validated defence, in four phases.

Assessment reveals, Hardening closes, Monitoring watches, Validation tests. Each phase builds on the last, with no regression.

Fase 01 · Onboarding

Assessment

Where you stand today, with evidence.

  • Assessment across the 7 security domains
  • Maturity baseline and a map of critical gaps
  • Hardening plan prioritised by risk
Fase 02 · Closing gaps

Hardening

The highest-risk gaps close first.

  • Defensive controls implemented in waves
  • Focus on the highest-risk gaps first
  • Evidence for every instrumented control
Fase 03 · Always-on

Monitoring

SOC/MDR 24×7 with an SLA.

  • Threat hunting and CTI feeding prevention
  • Response orchestrated by AICS and L3 analysts
  • Detection under 4h, response under 24h on critical
Fase 04 · Red Team always-on

Continuous validation

The defence tested before the real adversary.

  • Red Team cycling through the 7 security domains
  • Closed loop: attack, detection and adjustment
  • Posture tested every day, on a cycle
The AI layer

The intelligence that orchestrates the defence, inside your perimeter.

Sovereign AI, on premises, on dedicated GPU. Specialised agents that detect, decide, act and learn, under a global kill switch and human in the loop.

SecOps with AI

Autonomous

Full incident response cycle. Multi-agent, with a kill switch and human in the loop.

Cybersecurity Intelligence Agents

AICS

Autonomous AI agents that transform your SOC and amplify every analyst and every service, running 24×7 with no operational or decision fatigue.

Agent factory

HyperAgents

Agents specialised in infrastructure, cloud and critical operations, acting on the environment through MCP.

Operational copilot

FAB.IA

Natural-language triage, generates scripts and suggests actions in seconds.

Process auditor

VIG.IA

Audits executions, automations and production changes, with continuous compliance.

Infrastructure brain

Autonomous NOC

Discovers, learns and predicts failures before they happen, integrated with the SOC.

On-premises AIDedicated GPULGPD complianceNIST CSF 2.0CIS Controls v8ISO 27001MITRE ATT&CK
01
One operation

NOC and SOC integrated

CIOTI and CIOC share the same intelligence. An infrastructure event can reveal a security threat, and the other way round. Not in silos.

02
Evidence

Exportable posture

Defence validated continuously across the 7 domains, with evidence ready for the board, the auditor and the insurer. You demonstrate rather than promise.

03
Sovereignty

On-premises AI

AI processing on dedicated GPU, in your environment or in Central IT's. Zero dependency on public cloud, aligned with the LGPD.

04
Always-on

Tested every day

Red Team cycling against the 7 domains. The defence is validated before the real adversary, in a closed loop of attack, detection and adjustment.

Frequently asked questions

It all starts with a Security Assessment.

What is cybersecurity as a service?

Cybersecurity delivered as a service: leading platforms, 24×7 operations (SOC, NOC, Blue and Red Team) and an AI layer that orchestrates it all. A defence validated continuously across the 7 information security domains, that decides, acts and learns.

Do I have to replace my security tools?

No. We select and operate market-leading platforms by maturity and criticality, and integrate with what you already have. The operation starts from your environment, without demanding a full replacement.

Where does the AI run? Does my data leave the environment?

The AI runs on premises, on dedicated GPU, in your data centre or in Central IT's. Your data does not leave your perimeter: the operation is sovereign, auditable and aligned with the LGPD, with a global kill switch and human in the loop.

How do I prove our posture to the board and the insurer?

The defence is validated continuously across the 7 domains, with exportable evidence. Every instrumented control and every response is recorded, ready for the board, the auditor and the insurer.

Are NOC and SOC the same operation?

Yes. IT operations (CIOTI) and cyber operations (CIOC) share the same intelligence. An infrastructure event can reveal a threat, and a threat can reveal an operational failure. One operation, not silos.

What is the difference between building your own SOC and buying SOC as a service?

An in house SOC requires a team across three shifts, correlation tooling, detection engineering and threat intelligence, all maintained internally, with turnover and scale that are hard to sustain. As a service, you join an operation that already exists, already runs 24x365 and has already accumulated detection experience. The real difference is not price: it is time until you are actually protected.

How much does SOC as a service cost?

Cost is sized by volume and attack surface: number of assets and identities monitored, event and log volume, integrated sources, retention period, the response level contracted and whether the AI runs on our infrastructure or yours. The initial assessment measures the real surface before scope is proposed.

How long until monitoring is live?

The gain is staged. The highest value sources come first, usually identity, endpoint and perimeter, which delivers visibility quickly. The remaining integrations follow, along with detection tuning and false positive reduction, which is the work that makes an alert trustworthy.

Can you respond to an incident that is already underway?

Yes. Incident response is its own track: containment, eradication, recovery and root cause investigation, with a record of what happened and what changed afterwards. If you are under attack right now, direct contact is faster than the form.

How does a security operation help with data protection compliance?

Data protection law requires technical safeguards and incident notification within a deadline. A monitored operation produces both: the control that demonstrates diligence and the trail that lets you state what was accessed, when and by whom. We work aligned with LGPD, NIST CSF 2.0, CIS Controls and ISO 27001/27002 when defining those controls.

Do we need an internal security team to contract this?

No. The operation works as an extension of what already exists, even when that is one person covering security alongside infrastructure. What must stay on the client side is the decision: who authorises a containment action that takes a service down, and within what authority.

How do I buy this?

Through four routes: direct sales, AWS Marketplace, SERPRO and TELEBRAS. Public bodies often find the shortest path through the state owned companies they already contract with. The detail of each route is at centralit.com.br/en/how-to-buy.

Next step

When the adversary arrives, your defence will already be ready.

Do not wait for the incident to find out where the gaps are. It all starts with a Security Assessment.

Book a Security Assessment