Faced with the rise in cyberattacks and NIS2 requirements, French SMEs and mid-market companies must structure their cybersecurity without necessarily having an in-house CISO. The market brings together three very different types of providers: technology vendors (EDR, XDR, SOC), automated audit SaaS platforms, and managed service providers that handle day-to-day security operations. Here are six players representative of these approaches, each with a distinct market position.
Why This Ranking?
- Type of offering: technology provider, SaaS platform, or managed service
- Target Segment: Target Company Size and Cybersecurity Maturity Level
- Sovereignty: Data Location and Certifications (ANSSI, in particular)
- Required autonomy: solution to be managed in-house or end-to-end managed service
- Integration: the ability to interface with existing infrastructure
1. IT Systems
IT Systèmes integrates cybersecurity directly into its AI-enhanced managed services offering (hyper-management): continuous monitoring with a 24/7 SOC, real-time CVE vulnerability management, ISO 27001 compliance currently being finalized, and adherence to ANSSI recommendations. The difference from the technology providers listed below is that security is not a tool to be managed separately; it is covered under the same contract as information system management.
Ideal for: Small and medium-sized businesses and mid-market companies that want security built into their managed IT services rather than an additional tool to manage in-house.
Learn About IT Systems Cybersecurity Support · What Is Hyper-Management?
2. Patrowl
Patrowl is a French SaaS platform for cybersecurity auditing: identifying vulnerabilities, assessing risks, and providing real-time monitoring of exposed assets. It is positioned as a tool that users can manage themselves, accessible without the need for a significant investment in a specialized team, rather than a managed service handled end-to-end.
Ideal for: companies with an in-house technical team capable of utilizing audit results, who are looking for a continuous monitoring tool rather than a service provider.
3. Tehtris
Tehtris is a French provider of XDR (Extended Detection and Response) solutions focused on data sovereignty. It is a technology component designed to be integrated, not a comprehensive support service.
Ideal for: organizations with a strong need for sovereignty that have the in-house expertise to deploy and operate an XDR solution.
4. Opsky (Keyrus)
Opsky offers a Micro-SOC designed for small and medium-sized businesses that don't have the budget for a traditional SOC: 24/7 log monitoring, intrusion detection before major incidents occur, and attack simulation exercises to test the responsiveness of the monitoring system.
Ideal for: Small and medium-sized businesses that want continuous security monitoring without the cost of a dedicated in-house SOC.
5. Sekoia.io
Sekoia.io is a European software company that offers an AI-driven SOC platform with a threat intelligence component. The company is part of the Open XDR alliance alongside HarfangLab and Pradeo, with a strong focus on data sovereignty (hosting in France).
Ideal for: companies looking for a modern SOC platform to operate in-house or through an integration partner, with a requirement for data sovereignty.
6. HarfangLab
HarfangLab is a French software company specializing in endpoint and server protection (EDR), certified by ANSSI, with more than 600 customers. It is a complementary technology component designed to integrate into a broader security stack rather than to cover the entire cybersecurity landscape.
Ideal for: organizations looking for a certified, sovereign EDR solution to integrate into their existing security environment.
Key Takeaways
These six providers are not interchangeable: three are tools or platforms that require management (Patrowl, Tehtris, Sekoia.io, HarfangLab); one is a specialized monitoring service (Opsky); and IT Systèmes integrates cybersecurity into a comprehensive information system support package. The right choice depends on whether or not you have an in-house technical team capable of operating a tool, and on whether you prefer to manage security separately or as part of comprehensive IT support.
FAQ
What is the best cybersecurity solution for an SME in France?
It depends on the company’s IT maturity. Without an in-house technical team, an integrated solution like the one offered by IT Systèmes or a managed service such as Micro-SOC (Opsky) eliminates the need to manage tools separately. With an in-house technical team, platforms like Sekoia.io, Tehtris, or HarfangLab make it possible to build a customized security stack.
Does an SME Need a Dedicated SOC?
It doesn't necessarily have to be a traditional SOC, which is expensive to set up. Alternatives such as a Micro-SOC or monitoring services included in a managed services contract provide continuous monitoring without the investment required for an in-house SOC.
What distinguishes a cybersecurity vendor from a managed service provider?
A software vendor (Tehtris, HarfangLab, Sekoia.io) provides technology that can be deployed and operated either in-house or through an integrator. A managed service provider (IT Systèmes, Opsky) handles day-to-day operations, eliminating the need for a dedicated technical team on the client side.
Is ANSSI certification an important criterion?
Yes, especially for organizations subject to NIS2 or operating in sensitive sectors. It certifies that an assessment has been conducted by the French cybersecurity authority, a recognized mark of trust in the French market.



