SOC 360 — MDR BY CROWDSTRIKE FALCON
SOC 360: managed detection and response
An alert is only the beginning. We handle what comes next: 24/7/365 monitoring, isolation, investigation and coordination with your insurer, in a single contract.
24/7/365
Monitoring
< 2h
Investigation start
EN / FR
Languages supported
[ 01 ] — THE REAL PROBLEM
Most SOCs stop at the alert
When the attack is real, the business is left on its own to find a responder, reach its insurer and document the claim, while the attacker keeps moving.
Who sees the alert at 3 a.m. Who is authorized to isolate the device. Who calls your insurer and breach coach. Who investigates and restores your systems. With SOC 360, one answer: ITCS.
SOC 360 brings together our 24/7 monitoring experts and our incident response team in a single contract, powered by CrowdStrike Falcon: one team, from the first signal to business recovery, with no hand-offs between vendors.
[ 02 ] — WHAT'S INCLUDED
A complete SOC, from alert to recovery
24/7/365 monitoring
Our experts watch your endpoints and servers around the clock and proactively hunt for threats.
Your dedicated team
ITCS experts reachable 24/7, in English and French, one point of contact.
Endpoint and server protection
Next-gen antivirus, EDR/XDR and asset inventory on a single lightweight agent.
Isolation and remediation
Endpoint isolated, processes killed, persistence removed, no reimaging.
CISO as a Service
Review or drafting of your incident response plan, ready for day one.
Expert and DFIR hour bank
Annual hours included for advisory work and investigation.
Onboarding
Isolatable assets, contacts, escalation rules
Initial investigation
Included up to confirmation of the attack
Coordination
Insurer and breach coach reached right away
Compliance
Law 25 and PIPEDA built in
[ 03 ] — THE SOC 360 CYCLE
Before, during and after an attack
One team, ours, from the first signal to business recovery. No hand-offs between vendors, no time lost.
DETECT
Monitoring and hunting
24/7/365 monitoring and threat hunting on your endpoints and servers.
CONTAIN
Targeted isolation
Endpoint or server isolated per your rules, no reimaging.
INVESTIGATE
Initial investigation
Initial ITCS investigation included, up to confirmation of the attack.
RESPOND
Response and recovery
Forensics, insurer, breach coach, business recovery.

[ 04 ] — FULL SERVICE COVERAGE
Included for every endpoint and server
[ 05 ] — WHY ITCS
A SOC that doesn't stop at detection
Beyond the alert
Attack confirmed: our investigators take over, forensics, ransomware crisis management, restoration.
Insurance
Trusted by the largest cyber insurers and breach coaches in Canada, with claim-ready reports.
Leading technology
Fixed monthly cost per endpoint, no hiring and no tools to run, with a Canadian team.
[ 06 ] — THREAT HUNTING BY THE NUMBERS
Why a second look
82% of intrusions observed in 2025 were malware-free: stolen credentials, legitimate tools. Automated detections alone are no longer enough.
82%
of 2025 intrusions were malware-free
280+
adversary groups tracked
6.2 trillion
events analyzed per day
1,800+
hunting patterns added per year
100
serious intrusions detected per day
Source: CrowdStrike, 2026.
[ 07 ] — OPTION FOR MICROSOFT ENVIRONMENTS
Keep Defender. We add a second layer.
SOC 360 adds CrowdStrike technology and threat hunting alongside Microsoft Defender, without replacing it.
You keep
- Microsoft Defender
- Microsoft 365 licenses
- Your processes
We add
- Lightweight sensor
- AI detections
- 24/7 hunting
- ITCS team and DFIR
Deploy
Lightweight sensor installed alongside Defender, nothing replaced.
Detect
AI detections and intelligence to see what Defender misses.
Hunt
Experts track stealthy activity 24/7 and escalate threats.
Respond
Threats eradicated. ITCS isolates, investigates and calls your insurer.
Ideal for
- Organizations standardized on Defender
- Microsoft 365 customers wanting a 2nd look
- IT teams without threat hunters
- One partner, from alert to claim
Microsoft and Defender are trademarks of Microsoft Corporation; CrowdStrike is not affiliated with Microsoft. CrowdStrike and Falcon are trademarks of CrowdStrike, Inc. Option valid only while the customer remains a Microsoft Defender user.
[ 08 ] — ADD-ON MODULES
Extend coverage to your needs
[ 09 ]
Discover our other services
A comprehensive approach to cybersecurity
[ 10 ] · Frequently asked questions
Frequently asked questions
The short answers our clients and their insurers ask for most often.
- /01
What is SOC 360 and how does it differ from a traditional SOC?
- Most monitoring services stop at the alert: it is left to you to find a responder, reach your insurer and document the claim. SOC 360 combines, in one contract powered by CrowdStrike Falcon, 24/7/365 monitoring, isolation and remediation, an included initial investigation and coordination with your insurer and breach coach.
- /02
How quickly does the initial investigation start?
- The initial investigation starts under 2 hours and is included up to confirmation or dismissal of the attack. Our analysts monitor your endpoints and servers 24/7/365 and isolate the affected asset under rules agreed with you, without reimaging.
- /03
Does SOC 360 replace our Microsoft Defender antivirus?
- Not necessarily. With the SOC 360, Defender option, you keep Microsoft Defender, your Microsoft 365 licenses and your current processes; we add a lightweight sensor, AI detections and 24/7 threat hunting from the ITCS team. This option remains valid only while you stay a Microsoft Defender customer.
- /04
What is not covered by SOC 360?
- SOC 360 is a detection and response service: patch management, vulnerability remediation and ransom negotiation or payment are not part of it. Those needs are covered by our penetration testing and incident response services, or by your internal teams.
- /05
Does SOC 360 work with our cyber insurer?
- Yes. As soon as an attack is confirmed, we coordinate with your insurer and breach coach and produce reports designed to support the claim, meeting the notification deadlines of Law 25 and PIPEDA.
- /06
What is the commitment term and how is pricing set?
- SOC 360 runs for 12 or 36 months, with guided onboarding and a custom quote based on the number of endpoints and servers to protect. No pricing is published: contact us for a proposal tailored to your organization.
Ready to move from an alert to a complete response?
Custom quote, 12 or 36 month term, guided onboarding.