- 84% reduction in alert noise and false urgency through continuous threat exposure operationalization and agentic filtering.
- 75+ industrial vendors supported by Holm Security's non-intrusive OT vulnerability assessment engine.
- €900 million annual revenue for ACP Group AG, a major European IT service provider endorsing the Holm-Sekoia integration.
Experts would likely conclude that the Holm-Sekoia integration represents a significant advancement in European cybersecurity, combining autonomous AI with high-fidelity contextual data to enhance threat detection and reduce operational inefficiencies.
Building the Autonomous, Sovereign SOC: How Holm Security and Sekoia Are Rewiring European Cybersecurity
By Matthew Richardson
STOCKHOLM and PARIS – September 17, 2026 – For years, the modern Security Operations Center (SOC) has been defined by a chronic deficit not of data, but of context. Industry studies reflect that human tier-one analysts routinely spend up to 60 percent of their triage time "swivel-chairing"—manually copying IP addresses, hostnames, and hash values into independent vulnerability managers, configuration databases, and identity controllers just to understand what they are looking at. Without continuous exposure context, standard security systems treat an exploit attempt against an invulnerable host with the same urgency as an attack on a business-critical database carrying an unpatched, remotely exploitable vulnerability.
Today, a new technology alliance aims to close this operational chasm. Holm Security, a European leader in exposure and vulnerability management, and Sekoia, the Paris-based agentic cybersecurity company, have announced a native technology integration linking Holm's vulnerability intelligence directly with Sekoia's autonomous SOC platform.
Through a dedicated, bi-directional connector, live asset inventory, vulnerability telemetry, and risk classifications are fed directly into Sekoia’s intelligence layer. The integration, which is immediately available to enterprise customers and Managed Security Service Providers (MSSPs), represents a significant leap forward in how artificial intelligence investigates threats and how European enterprises defend their digital sovereignty.
Feeding the Autonomous SOC: How Rich Exposure Data Fuels Agentic AI
The next frontier of security operations is not simply building larger language models, but feeding autonomous AI agents high-fidelity contextual data. An AI agent cannot effectively triage a threat if it does not know what resides on the other end of the network connection.
The integration is anchored by a dedicated API connector that terminates in Sekoia Reveal, the platform’s asset intelligence and cyber asset attack surface management (CAASM) module. It imports asset metadata, software bills of materials (SBOM), Common Vulnerability Scoring System (CVSS) vectors, and weaponization flags. This data serves as the critical sensory input for Sekoia Elevate, the platform's agentic AI engine.
When a live alert triggers—such as an anomalous outbound connection—Sekoia’s AI agents autonomously query Reveal to evaluate if the target host actually runs the vulnerable component in question. If a signature targets an unpatched vulnerability on an asset tagged by Holm Security as exposed, the alert priority escalates immediately. Conversely, if the asset is verified as immune or patched, the alert is autonomously deprioritized. Early operational metrics indicate that this continuous threat exposure operationalization, combined with agentic filtering, consistently reduces alert noise and false urgency by up to 84 percent.
“Holm Security brings valuable device and vulnerability intelligence into Reveal, Sekoia’s asset intelligence layer. We can combine that with asset context and security signals from across a customer’s environment to calculate risk and understand what needs attention first, consistently across technologies and vendors,” said Anders Olsson, VP Strategy at Sekoia. “For enterprises and MSSPs, that means reducing exposure before attackers can exploit it, while giving analysts and AI agents better context to investigate and respond when an attack is already underway.”
Furthermore, the integration is bi-directional. While Holm feeds vulnerability status downstream to enrich live alerts, Sekoia can signal detection events and confirmed compromises back into Holm's exposure prioritization models, dynamically elevating an asset's risk index upon active attack.
Closing the Chasm Between Pre-Attack Posture and Live Incident Response
The convergence of Information Technology (IT) and Operational Technology (OT) represents one of cybersecurity's most vulnerable frontiers, and it is here that the Holm-Sekoia integration offers profound operational relief.
Legacy industrial environments—encompassing Supervisory Control and Data Acquisition (SCADA) nodes and Programmable Logic Controllers (PLCs)—were engineered for operational reliability, not network security. Traditional IT vulnerability scanners use aggressive network sweeps that can cause legacy PLCs to fault or crash, posing catastrophic risks to physical industrial processes. Consequently, industrial operators often resist vulnerability management, leaving OT assets completely invisible to corporate SOC teams.
Holm Security bypasses this limitation through a dedicated industrial assessment engine built on low-impact, protocol-aware mechanisms. It detects vulnerabilities across more than 75 industrial vendors using non-intrusive queries designed for protocols such as Modbus/TCP, Profinet, EtherNet/IP, and Siemens S7. By ingesting this highly specialized OT telemetry directly into Reveal, Sekoia establishes continuous situational awareness across the industrial perimeter without sending active, disruptive probe packets into fragile networks.
If Sekoia detects suspicious IT activity, such as credential harvesting on an enterprise domain, its AI agents can immediately cross-reference Reveal to verify whether those specific credentials have access paths leading into the OT demilitarized zone or vulnerable SCADA engineering stations.
“Security teams do their best work when they can see their real risk. AI is at the heart of how we find, prioritize, and test vulnerabilities across IT and OT,” said Marcus Kaber, CEO of Holm Security. “Bringing that intelligence into Sekoia means an analyst or an AI agent can see the assets at stake and the risk behind an alert, and spend their time on what truly matters.”
The Rise of European Sovereign Cyber Alliances Against Big Tech Monoliths
Beyond technical operational efficiency, the Holm-Sekoia alliance arrives amidst intense regulatory restructuring of the European technology landscape. The enforcement of the EU NIS2 Directive and the Digital Operational Resilience Act (DORA) has placed unprecedented pressure on enterprises to manage supply-chain risk and avoid single-vendor monocultures.
European enterprises operating under strict confidentiality regimes—including defense, critical infrastructure, and healthcare—are increasingly scrutinizing monolithic platforms subject to the US CLOUD Act. Both Holm Security and Sekoia guarantee EU-only data residency and private-cloud AI inference, ensuring zero customer telemetry is passed to third-party foreign foundation model providers.
This shift from monolithic, walled-garden consolidation to open, API-centric best-of-breed alliances is rapidly gaining traction among major European IT service providers. ACP Group AG, one of Central Europe's largest independent B2B IT service providers with roughly €900 million in annual revenue, has formally endorsed and validated the integration.
“When ACP committed to a European vendor strategy, one requirement was non-negotiable: every technology we bring into the SOC has to be API-centric, so the modules form an ecosystem instead of a collection of consoles,” said Markus Riegler, Lead Solution Consultant Security at ACP Group. “Holm Security and Sekoia went a step further and built the integration between vulnerability scanning and SIEM/XDR themselves. For our SOC that means one central integration point, and asset context that finally works in both directions.”
Vendor-built API interoperability allows European MSSPs to field competitive, fully sovereign Managed Extended Detection and Response (MXDR) services without the high egress and switching costs associated with incumbent US megavendors.
To demonstrate the practical application of this sovereign, agentic architecture, Holm Security and Sekoia will host a joint, demo-led webinar on October 15. The session will trace a real vulnerability from its initial non-disruptive discovery through to a contextualized, autonomous decision executed by AI agents in the SOC, offering the industry a live look at the future of integrated European cybersecurity.
Topics & Related
📝 This article is still being updated
Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.
Contribute Your Expertise →