Safetech Innovations Webinar: MDR and SOC – from first aid to cybersecurity emergency room
On October 9, 2025, Safetech Innovations held the webinar “MDR and SOC: From First Aid to the Cybersecurity Emergency Room”, dedicated to understanding how Managed Detection and Response (MDR) and Security Operations Center as a Service (SOCaaS) cybersecurity services deal with the key challenges of today’s security operations. During the webinar, Cătălin Gherghiceanu, Presales Manager Safetech Innovations, presented seven major challenges in security operations, analyzing how they can be managed efficiently through MDR and SOCaaS services.
The Safetech Innovations specialist clarified the content of the two types of services, exemplifying the role of each in the security architecture of an organization. The event also included the presentation of the MDR and SOCaaS services provided by Safetech Innovations, based on the expertise and infrastructure of Safetech CERT (STI CERT)® – the first private Computer Emergency Response Team in Romania, active since 2015 and accredited as a Trusted Introducer.
Latest Trends in Digital Operations & Terminology Clarification: MDR vs SOC
Cătălin Gherghiceanu opened the webinar with a presentation of two important global trends in the field of digital operations. The first aims at the integration and convergence of IT Operations, CyberOps and DevOps in a unitary model – DevSecOps (Development, Security & Operations). This principle promotes continuous collaboration between the 3 traditional teams, for cost optimization.
The second trend is “Shift-Left” in security operations, which involves moving critical security activities as early as possible in the development cycle of a product/application. This is achieved through practices such as threat modeling in the design phase, Static Application Security Testing (SAST) or Infrastructure as Code (IaC) scanning, for early identification of vulnerabilities and reduction of cyber risks.
At the same time, the manager of Safetech Innovations provided clarifications on the concepts of IT Incident Management, SOC, CSIRT, CERT and MDR. “MDR focuses on rapid incident detection and response (EDR, NDR, XDR technologies), while a modern SOC includes extensive activities, such as vulnerability management, risk assessment and security posture optimization. Although the services may vary from one provider to another, we believe that flexibility is essential, adapting them to the needs and specifics of each client” , explained Catalin Gherghiceanu.
Managing Security Operations Challenges with MDR and SOCaaS
Next, the Safetech Innovations representative exemplified the differences between MDR and SOC by presenting seven common challenges in security operations in organizations, namely the volume and noise of alerts, lack of resources and skills, limited integrations, the need for 24×7 monitoring, the rapid evolution of threats, the need for compliance and cost efficiency.
For example, organizations that use a number of separate security tools face tens of thousands of alerts daily, many of which are false positives. Causes? The right tools are not used or misconfigured, there are not enough data sources to create meaningful context, or events and alerts are not correctly correlated. MDR services reduce this volume through Endpoint Detection and Response solutions, preconfigured for as many scenarios as possible, and through specialized L1–L3 teams that filter and escalate only real incidents. Safetech Innovations recommends the use of tools with modern AI/ML mechanisms, which can do effective filtering, so that specialized personnel can focus on a small number of alerts with the potential for escalation in incidents.
In addition to MDR, SOCaaS services use SIEM or XDR platforms with SIEM capabilities, which integrate data from multiple sources, which they enrich with context. In addition, they have UEBA (User and Entity Behavior Analytics) capabilities. The result: much more accurate filtering, reducing false positive alerts. Also, through SOAR (Security Orchestration, Automation, and Response) functionalities, SOCaaS provides rapid response capabilities.
Other challenges and use cases presented during the webinar:
- The global shortage of analysts and high recruitment costs make it difficult to form internal teams. MDR provides quick access to dedicated specialists through predictable contracts, and SOCaaS complements with a multidisciplinary team and access to up-to-date technical expertise gained by working with a broad customer base.
- Multiple security solutions that are difficult to unify reduce operational efficiency. MDR simplifies deployment and operation through a single EDR agent and provides consolidated visibility for endpoints (PCs, servers, smartphones, etc.), and SOCaaS adds a central SIEM and integrated SOAR automations with threat intelligence and vulnerability management modules.
- New types of attacks (fileless, supply-chain, zero-day, APT) require advanced detection capabilities. MDR responds with behavior-based detection and machine learning on endpoints, with immediate reaction and isolation, while SOCaaS complements with proactive threat hunting and integrates external threat intelligence sources.
For more details, we invite you to watch the full presentation of our colleague, in the video recording of the webinar “MDR and SOC: From first aid to the cybersecurity emergency room”.
What does MDR and SOCaaS provided by Safetech bring in addition
Next, Cătălin Gherghiceanu briefly presented the MDR and SOC capabilities that Safetech Innovations has been providing for about 10 years through its own security operations center, STI CERT, both in the IT and OT (Operational Technology)/SCADA areas.
“First of all, Safetech Innovations has a very flexible model for delivering these services. We can strictly connect to the technological tools and platforms made available by the client, we can make available the services that complement these tools, and we can also come up with platforms that allow the provision of these services or the improvement of the accuracy of our services. We can offer the solutions either as a tool or as part of SOC services, as we are MSSPs and have partnerships with a number of technology providers. We have our tenant and we can make it, in the form of a multi-tenancy, available to customers,” , added the manager from Safetech Innovations.
According to him, the philosophy of the Safetech Innovations team is to collect as much actionable data as possible, to capitalize on the security tools and solutions already existing in the customer’s network and to align the processes and procedures for delivering MDR and SOC services with the internal ones of each customer.
As we have already mentioned, Safetech Innovations offers complete managed security services through STI CERT,® accredited Trusted Introducer since 2015. The center operates 24/7 in three shifts, with certified specialists (ISC², ISACA, EC-Council, CREST), and provides monitoring, prevention and reporting of cyber incidents, using its own and/or customers’ platforms. The center’s services are covered by an insurance policy of 500,000 EUR, the platforms used by TSI CERT ingest over 100 billion events monthly, based on which CERT specialists analyze about 12,000 alerts and manage about 150 incidents. In 2024, Safetech Innovations was included in the Top 250 MSSPs worldwide, conducted by MSSP Alert.
For additional information, please contact us at sales @ safetech.ro or by phone +40 21 316 0565.