SEKOIA REFLECTS ON INCIDENT MANAGEMENT EVOLUTION
An interesting post by David Bizeul, cofounder and Chief Scientist of SEKOIA :
Last week, someone asked me when I really started to work on SOC/SIEM?
I had to switch into archive mode during the weekend and finally found the document I was looking for: A SIEM white paper written in 2006 with Yann Fareau a friend of mine, when we both worked at Devoteam. If you read it, I warn you, there is not a single AI mention at this time
Many approaches, numbers and architectures are now obsolete, but guess what? Some ideas are still relevant today:
→ The importance of context was already there to classify and prioritize alerts
→ The real time enrichment was already proposed as an efficient to handle relevant events
→ Intelligence was already associated with context (threat intelligence will arrive 5 years later)
→ The possibility of automation after an alert was in scope (SOAR will be coined 12 years later)
→ Standardized formats for event normalization were already there (OCSF will arrive 16 years later)
What has changed / Fun facts:
→ The paper builds a worked example of a “reasonably sized” infrastructure with different components. It calculates the load at 400k events per hour and warns this is “impossible to process without automating the analysis.”~100 events per secon . That’s a quiet Tuesday for a single mid-size log source today. My laptop generates more telemetry.
→ The paper also worries, at length, that XML is too verbose for the available bandwidth. It proposes a compression algorithm as the fix. We now casually ship terabytes a day and complain about ingest pricing instead.
→ And it names IDMEF as “probably the future reference standard.” Reader, it was not. We went on to invent CEF, LEEF, ECS, OCSF and OTel, and we still normalise logs by hand.
What has not changed even slightly:
→ Level 1, Level 2, Level 3, Level 4. The SOC tiering model in this paper is probably the one in your org chart right now even if lines are moving now
→ The false positive / false negative tradeoff, drawn as two overlapping curves. Same picture in every vendor deck in 2026, except now the curve is “AI-powered.”
→ “Rule Based Correlation Engine” was a 2005 buzzword. It was sometimes renamed by vendors but today it is still, mostly, rules.
→ Push vs pull for integration strategies. Still true.
→ Clock synchronisation across sources is described as absolutely essential. Still essential.
The tooling got a thousand times better. The problem did not move.
AND THE OFFICIAL ANNOUNCEMENT OF THE LAUNCH OF THE BRAND NEW SEKOIA ELEVATE SYSTEM, WITH ITS FIRST AWESOME RESULTS
Sekoia, the European agentic cybersecurity company, today announced the general availability of Sekoia Elevate, the agentic AI layer of its autonomous SOC platform. Elevate’s AI agents investigate alerts end to end, directly from customers’ security data, and deliver an audit-ready verdict in 99 seconds on average, backed by a traceable record of every query and piece of evidence. With Elevate, the alert is no longer a request for human work. Machines perform the investigative work at speed, while security teams retain governance and control over final decisions.Security tools have spent twenty years producing better alerts, and SOC teams have grown to process them. As telemetry expands and attackers adopt AI, that model no longer scales. For each case, Elevate’s agents gather and correlate raw logs, detections, threat intelligence, runbooks and response context the manual groundwork that absorbs analyst time so security teams can apply their expertise where it protects the business, without giving up control.
Elevate reaches general availability after an Early Access program conducted in real production environments. During this phase, it was deployed to more than 2,000 customers and hundreds of SOC analysts, and completed more than 425,000 autonomous investigations, correlating evidence across all connected data sources. Leading managed security service providers (MSSPs) in Europe and the US report up to a fivefold reduction in overall investigation time, alongside deeper and more consistent threat analysis. And during the first week of production trials, investigations took 99 seconds on average.
Elevate draws on assets Sekoia has built for years: proprietary threat intelligence, security data infrastructure, deep integrations and investigation workflows across thousands of production environments. The platform is model-agnostic, choosing the right model for each task, and open by design, working across the customer’s existing security stack.
“The alert economy is ending,” said Freddy Milesi, CEO of Sekoia. “The model alone is not the moat. What makes an agent effective in the SOC is the system around it: threat intelligence, customer context, memory and the ability to act. Elevate is that system in production, delivering autonomous cyber defense independent of any single stack or model.”
“Elevate shifts the analyst’s role from data miner to decision-maker,” said Georges Bossert, Chief Technology and Product Officer at Sekoia. “Our agents do the exhaustive groundwork from raw data and explain every step, so security teams can focus on the decisions that protect the business, without giving up control.”
To learn more about Sekoia Elevate, visit and click here
POINTSHARP ACQUIRES MEAPLUS
Pointsharp, a Swedish provider of identity governance and administration, access management, and secure information with a strong presence in Germany where it took over CRYPTSHARE a few years ago exchange solutions backed by Main Capital Partners (“Main”), has acquired Meaplus AB and Nubibus Software AB (together, “Meaplus”), a Sweden-based provider of secure communication solutions for public sector customers. The acquisition strengthens Pointsharp’s secure information exchange offering, expands its position in the Swedish public sector, and represents another step in the company’s growth strategy.
Founded in 2015 and headquartered in Malmö, Sweden, Meaplus provides SEFOS, a secure digital communication platform designed for organizations that need to exchange sensitive and confidential information across organizational boundaries. The platform is widely used in the Swedish public sector and healthcare, as well as by private organizations communicating securely with public authorities and other organizations. SEFOS supports secure messaging, file sharing and secure video meetings, as well as integration of secure communication into customers’ own applications and digital services through APIs and the SEFOS SDK Access Point. The platform supports established identity and authentication standards such as SAML and OIDC, together with widely used Swedish electronic identification solutions including BankID and Freja eID. Meaplus serves more than 180 organizations in Sweden, with a particularly strong position among municipalities, regions, healthcare providers and other public-sector organizations.
HARFANGLAB IN THE BENELUX AND IN SWITZERLAND
On hosted HarfangLab holds its BeNeLux partners meetup at Infinigate Belgium.
Partnerships are key and it is important making sure partners are ready to position your solution. With a commercial and technical track, we gave hands-on information and tools to use. To make it more concrete, one of our partners also shared how they have been successful selling HarfangLab.
And has attended the Swiss IT Forum at Geneva, with the local partner E-Secure.



