Overview
Updated Jun 27, 2026
Current S21sec-domain cybersecurity pages now serve Thales-branded cybersecurity services, so this profile reflects the current Thales/S21sec successor positioning rather than a standalone legacy S21sec MDR package. Thales Cyber Detection and Response combines a global network of SOCs, AI, automation, cyber threat intelligence, proactive threat hunting, vulnerability management, DFIR and rapid incident response for critical sectors. It is strongest for large enterprises, public-sector and critical-infrastructure buyers that need a global services firm with local European, MEA and APAC SOC coverage. Public pages do not publish MDR pricing, named technology stack defaults, MTTD/MTTR, response-action runbooks or contractual SLA terms.
Buyer fit
Good fit when
- ✓Critical infrastructure and public-sector buyers that need Thales/S21sec regional cyber detection and response
- ✓Large enterprises that want global SOC coverage with local European delivery options
- ✓Organizations that need MDR alongside CTI, DFIR, CERT, vulnerability management and OT/ICS monitoring
Watch out when
- ×Buyers that need a standalone legacy S21sec-branded MDR package
- ×SMBs that want transparent per-endpoint MDR pricing
- ×Teams that require public response runbooks, portal details, MTTD/MTTR and service-credit SLAs before sales engagement
Coverage
2 of 6 attack surfaces in the base price; the rest are separately priced.
EDR
SIEM
Cloud
Additional capabilities
Incident response
Pricing
Custom quote for Thales Cyber Detection and Response, Managed Security Services.
How pricing works+−
Public prices are not published.
Not published
Cost caveats
- –The current S21sec domain routes to Thales-branded services, so buyers wanting legacy S21sec-specific delivery should confirm contracting entity, SOC location and delivery team.
- –Public pages do not publish prices, minimum terms, service credits, MTTD/MTTR or formal MDR SLAs.
- –Thales offers a broad cybersecurity services portfolio; buyers should separate base MDR scope from CTI, DRPS, DFIR, CERT, ICS monitoring and advisory services.
2 more+−
- –Named endpoint, identity and cloud containment actions are not public and should be confirmed tool by tool.
- –Data retention, raw log access, offboarding and detection-content export rights are not described publicly.
What costs extra (9)+−
- –DFIR scope and retainer terms
- –CERT incident response scope
- –ICS and OT monitoring
- –Cyber Threat Intelligence
- –Digital Risk Protection Services
- –Attack surface and vulnerability management
- –Technology integration services
- –Data retention and log storage
- –Real-world attack simulations
Warranty conditions+−
No public breach warranty found for Thales/S21sec SOC and MDR.
Team and access
Certifications
Reputation
The current public evidence is strong for Thales-branded global SOC, MDR, CTI, DFIR and critical-infrastructure detection and response, but weak for S21sec as a standalone public MDR brand. Buyers should validate current delivery model, SOC location, response authority, pricing and whether the contract is with Thales/S21sec in the relevant country.
What customers praise
- ✓Global SOC network with local European, MEA and APAC coverage
- ✓Strong fit for critical infrastructure and regulated sectors
- ✓Broad adjacent capabilities across CTI, DFIR, CERT, DRPS, vulnerability management and OT monitoring
Common complaints
- ×Legacy S21sec branding is not clearly separate from current Thales branding
- ×No public MDR pricing or contractual SLA
- ×Named response actions, default technology stack and portal experience are not public
No meaningful Reddit signal found for S21sec or Thales MDR specifically.
Questions to ask
- 1.
Is our contract delivered by Thales, S21sec, or a local Thales/S21sec entity?
- 2.
Which SOC location will monitor us, and where will logs, tickets and reports reside?
- 3.
Which security tools and SIEM platforms are included by default?
- 4.
Which response actions can Thales execute directly, and which require our approval?
- 5.
Is DFIR and CERT incident response included in MDR or quoted separately?
- 6.
What is included in base SOC and MDR versus CTI, DRPS, vulnerability management and ICS monitoring add-ons?
- 7.
What contractual SLA applies to triage, notification, containment and escalation?
- 8.
What reports, detections, playbooks, tickets and historical logs can we export during offboarding?
Evidence
Sources reviewed
Main public source used for the provider profile.
Official Thales cybersecurity services page used to verify 8 threat-intelligence and AI-driven SOCs, 400 supervised critical-information-system customers, detection and response service scope, 24x7 expert teams and sector focus.
Current S21sec-domain page used to verify that the legacy S21sec candidate now resolves to Thales-branded Cybersecurity Services content rather than a separate public S21sec MDR package.
Shortlisted legacy official S21sec/Thales SOC datasheet URL. Direct access is protected by anti-bot controls, and text-render retrieval resolved to current Thales Cybersecurity Services content, supporting the successor-branding treatment.
Public-data caveats
- –No public contractual response-time SLA is recorded for this profile.
- –No public fixed price is recorded; compare only after a scoped quote.
- –No public breach warranty is recorded.
- –Response authority may depend on pre-approval and contract scope.
Also consider
Further reading
Independent research. Verify details directly with the provider before making decisions.
