Cybersecurity as a service. A defence that decides, acts and learns.
Cybersecurity as a service: 24×7 operations and an AI layer that orchestrates the defence, validated continuously across the 7 information security domains and under your command.
What CIOC is.
O CIOC is Central IT's Centre for Cyber Intelligence and Operations: continuous monitoring and AI-powered threat detection across 7 information security domains. We identify, analyse and neutralise risk in real time, before the attack reaches the business. Blue and Red Team on a cycle, orchestrated by AICS (Cybersecurity Intelligence Agents) and senior analysts, with exportable evidence for the board, the auditor and the insurer.
The 7 information security domains (Blue and Red Team)
Red Team, Blue Team and AICS integrated. One operation, not 7 products.
What CIOTI is.
O CIOTI is CIOC's sibling centre: a Centre for IT Intelligence and Operations delivering, as a service, cognitive operations 24×7 across the 11 critical IT towers, orchestrated by an Autonomous NOC and HyperAgents (FAB.IA, VIG.IA) plus senior analysts, with sovereign on-premises AI and ITIL governance.
The 11 IT towers
Autonomous NOC, AIOps and HyperAgents integrated. One cognitive operation, not 11 silos.
Solutions, Operations and Intelligence. No one delivers just one.
Buying a tool without running it leaves it on the shelf. Running it without intelligence leaves alerts without action. This service brings all three together in a model you contract rather than build.
The three pillars
Solutions
Market-leading platforms, selected by maturity and criticality. Deployed, integrated and sustained.
Operations
SOC, NOC, Blue and Red Team sustaining the operation 24×7, continuous or on demand. Capability contracted, not built.
Cyber Intelligence
AI applied to cyber. It orchestrates solutions and operations into a single intelligence that decides, acts and learns.
The umbrella that delivers everything as a service.
A modular SaaS offering: people, technical towers and CITSmart Autonomous. All available together or tailored.
Teams and Services
- CIOTI, IT Intelligence
- CIOC, Cyber Intelligence
- NOC, Network Operations
- SOC, Security Operations
Observability
- APM, Application Performance Monitoring
- MMT, Monitoring & Metric Tracing
- Event Management
Operational Intelligence
- AIOps, AI for IT Operations
- RCA, Root Cause Analysis
- Predictive Maintenance
- Anomaly Detection
Digital Experience
- DEM, Digital Experience Monitoring
- RUM, Real User Monitoring
- Synthetic Monitoring
Business and Services
- BAM, Business Activity Monitoring
- Operational Resilience
- Topology & Dependency Mapping
- Access Control (MFA, IGA)
Security and Compliance
- SIEM
- SAST, DAST, IAST
- Safe-Check (Pentest, BAS, Vulnerability)
- Anti-Ransomware
- SecAIOps
Assessment, process mapping and rollout consulting included in any format or combination.
NOC and SOC sharing the same intelligence.
The Centre for IT Intelligence and Operations (CIOTI) and the Centre for Cyber Intelligence and Operations (CIOC) run integrated, not in silos.
Infrastructure brain
Centre for IT Intelligence and Operations
- Autonomous NOC
- Observabilidade cognitiva + AIOps
- HyperAgentes + FAB.IA + VIG.IA
- CITSmart ITSM, 24 processos ITIL
Cybersecurity brain
Centre for Cyber Intelligence and Operations
- Continuous Red Team + Blue Team
- SOC/MDR 24×7 com SLA
- AICS + Autonomous (SecOps com IA)
- 10+ leading platforms operated
Shared intelligence. An infrastructure event can reveal a security threat. A security threat can reveal an operational failure.
From your current posture to a validated defence, in four phases.
Assessment reveals, Hardening closes, Monitoring watches, Validation tests. Each phase builds on the last, with no regression.
Assessment
Where you stand today, with evidence.
- Assessment across the 7 security domains
- Maturity baseline and a map of critical gaps
- Hardening plan prioritised by risk
Hardening
The highest-risk gaps close first.
- Defensive controls implemented in waves
- Focus on the highest-risk gaps first
- Evidence for every instrumented control
Monitoring
SOC/MDR 24×7 with an SLA.
- Threat hunting and CTI feeding prevention
- Response orchestrated by AICS and L3 analysts
- Detection under 4h, response under 24h on critical
Continuous validation
The defence tested before the real adversary.
- Red Team cycling through the 7 security domains
- Closed loop: attack, detection and adjustment
- Posture tested every day, on a cycle
The intelligence that orchestrates the defence, inside your perimeter.
Sovereign AI, on premises, on dedicated GPU. Specialised agents that detect, decide, act and learn, under a global kill switch and human in the loop.
Autonomous
Full incident response cycle. Multi-agent, with a kill switch and human in the loop.
AICS
Autonomous AI agents that transform your SOC and amplify every analyst and every service, running 24×7 with no operational or decision fatigue.
HyperAgents
Agents specialised in infrastructure, cloud and critical operations, acting on the environment through MCP.
FAB.IA
Natural-language triage, generates scripts and suggests actions in seconds.
VIG.IA
Audits executions, automations and production changes, with continuous compliance.
Autonomous NOC
Discovers, learns and predicts failures before they happen, integrated with the SOC.
NOC and SOC integrated
CIOTI and CIOC share the same intelligence. An infrastructure event can reveal a security threat, and the other way round. Not in silos.
Exportable posture
Defence validated continuously across the 7 domains, with evidence ready for the board, the auditor and the insurer. You demonstrate rather than promise.
On-premises AI
AI processing on dedicated GPU, in your environment or in Central IT's. Zero dependency on public cloud, aligned with the LGPD.
Tested every day
Red Team cycling against the 7 domains. The defence is validated before the real adversary, in a closed loop of attack, detection and adjustment.
It all starts with a Security Assessment.
What is cybersecurity as a service?
Cybersecurity delivered as a service: leading platforms, 24×7 operations (SOC, NOC, Blue and Red Team) and an AI layer that orchestrates it all. A defence validated continuously across the 7 information security domains, that decides, acts and learns.
Do I have to replace my security tools?
No. We select and operate market-leading platforms by maturity and criticality, and integrate with what you already have. The operation starts from your environment, without demanding a full replacement.
Where does the AI run? Does my data leave the environment?
The AI runs on premises, on dedicated GPU, in your data centre or in Central IT's. Your data does not leave your perimeter: the operation is sovereign, auditable and aligned with the LGPD, with a global kill switch and human in the loop.
How do I prove our posture to the board and the insurer?
The defence is validated continuously across the 7 domains, with exportable evidence. Every instrumented control and every response is recorded, ready for the board, the auditor and the insurer.
Are NOC and SOC the same operation?
Yes. IT operations (CIOTI) and cyber operations (CIOC) share the same intelligence. An infrastructure event can reveal a threat, and a threat can reveal an operational failure. One operation, not silos.
What is the difference between building your own SOC and buying SOC as a service?
An in house SOC requires a team across three shifts, correlation tooling, detection engineering and threat intelligence, all maintained internally, with turnover and scale that are hard to sustain. As a service, you join an operation that already exists, already runs 24x365 and has already accumulated detection experience. The real difference is not price: it is time until you are actually protected.
How much does SOC as a service cost?
Cost is sized by volume and attack surface: number of assets and identities monitored, event and log volume, integrated sources, retention period, the response level contracted and whether the AI runs on our infrastructure or yours. The initial assessment measures the real surface before scope is proposed.
How long until monitoring is live?
The gain is staged. The highest value sources come first, usually identity, endpoint and perimeter, which delivers visibility quickly. The remaining integrations follow, along with detection tuning and false positive reduction, which is the work that makes an alert trustworthy.
Can you respond to an incident that is already underway?
Yes. Incident response is its own track: containment, eradication, recovery and root cause investigation, with a record of what happened and what changed afterwards. If you are under attack right now, direct contact is faster than the form.
How does a security operation help with data protection compliance?
Data protection law requires technical safeguards and incident notification within a deadline. A monitored operation produces both: the control that demonstrates diligence and the trail that lets you state what was accessed, when and by whom. We work aligned with LGPD, NIST CSF 2.0, CIS Controls and ISO 27001/27002 when defining those controls.
Do we need an internal security team to contract this?
No. The operation works as an extension of what already exists, even when that is one person covering security alongside infrastructure. What must stay on the client side is the decision: who authorises a containment action that takes a service down, and within what authority.
How do I buy this?
Through four routes: direct sales, AWS Marketplace, SERPRO and TELEBRAS. Public bodies often find the shortest path through the state owned companies they already contract with. The detail of each route is at centralit.com.br/en/how-to-buy.
When the adversary arrives, your defence will already be ready.
Do not wait for the incident to find out where the gaps are. It all starts with a Security Assessment.
Book a Security Assessment