Detect threats faster. Respond to incidents smarter. Build resilience with managed security services that reduce breach risk and speed recovery.
Detect faster, respond smarter, recover stronger
Cyber operations face unprecedented pressure. As cyber threats become faster, more sophisticated and more persistent, organizations must defend increasingly complex environments spanning cloud, hybrid infrastructure, SaaS applications, operational technology (OT) and identity platforms. Nearly seven in ten large businesses reported a cybersecurity breach or attack in the past year. Yet many security teams struggle with high alert volumes, fragmented security tools and inconsistent response processes, limiting their ability to detect and respond effectively.
DXC Cyber Transformation & Operations together administer detection and response (MDR) managed extended detection and response (MXDR), continuous threat exposure management (CTEM), incident response (IR), agentic SOC modernization and digital forensics and incident response (DFIR). Working as an extension of your team, DXC helps you detect threats earlier, respond faster and build operational resilience. Thousands of DXC cybersecurity professionals monitor threats 24x7, combining AI-assisted detection, threat intelligence and expert analysis to manage the full lifecycle of security incidents. With decades of experience processing billions of security events annually, we know what real threats look like and which alerts can safely be deprioritized.
Large Australian travel & transportation organization
DXC helped this customer create a more proactive approach to cyber security management. Its cyber security operations and technology solutions for cyber transformation involve capabilities such as logging, threat management, vulnerability scanning and managed endpoint protection to minimize the likelihood and impact of cyber attacks, while also building other services to improve security visibility and uplift cyber maturity.
Security Operations Center
Italy's Institute for Insurance Against Accidents at Work has an ongoing goal to work with DXC to continuously and proactively improve its security practices and technology to deal with threats and other cyber incidents . By improving the effectiveness and timeliness of threat detection and responses, INAIL is reducing the potential for harmful security events.
DXC provides ongoing enterprise cyber security monitoring and operations to check endpoints, review employee access, oversee ticketing and remediation, assess risks, patch servers and provide periodic audits to ensure System and Organization Controls (SOC) 1 and 2 operational compliance. The company looks to DXC to help protect the IT environment and secure the operational technologies that automate its manufacturing processes.
Leonardo embraces cybersecurity transformation services
DXC has had a long-standing partnership with Leonardo, a global leader in aerospace and defense, and has been instrumental in helping the company remove security obsolesence and operational risk as part of the company's application modernization work.
Solutions to Your Business Challenges
Managed Detection and Response (MDR)
We collect and analyze security telemetry across your endpoints, networks, cloud environments and identity infrastructure. Using threat intelligence, AI-assisted detection and expert analysis, we rapidly distinguish genuine threats from routine security noise. When suspicious activity is identified, our cybersecurity analysts investigate, validate alerts, advise on containment actions and coordinate response. Delivered 24x7, our MDR service extends your security operations without requiring you to build and maintain a dedicated in-house monitoring team. Our MDR service integrates with leading security ecosystems, including Fortinet technologies and FortiSOAR automation capabilities, to streamline detection and response workflows.
Managed Extended Detection and Response (MXDR)
We unify threat detection, investigation and response across endpoints, identities, email, cloud workloads and applications using leading XDR platforms, including Microsoft Defender XDR and CrowdStrike Falcon. We manage deployment, tuning and 24x7 monitoring while applying automation, threat intelligence and expert analysis to accelerate response. Automated workflows help contain common threats and reduce analyst workload, while our cybersecurity professionals investigate high-risk incidents and coordinate remediation activities. This is particularly effective for organizations looking to maximize the value of their Microsoft 365 or CrowdStrike security ecosystem.
Continuous Threat Exposure Management (CTEM)
We continuously identify and assess vulnerabilities, misconfigurations and attack-path exposures across your environment. Using threat intelligence, exploitability analysis and business context, our cyber security operations consulting service experts prioritize the issues that pose the greatest risk to your organization and provide actionable remediation guidance. By focusing resources on the exposures most likely to be targeted by attackers, we help you reduce risk faster and strengthen operational resilience.
When a cyber incident occurs, rapid response can significantly reduce business impact. DXC provides 24x7 incident response services with guaranteed response times, including a 15-minute verification call and full mobilization within one hour. Our DFIR specialists investigate attacks, contain threats, preserve legally defensible evidence, perform forensic analysis and identify root causes while supporting executive, legal and stakeholder communications. Delivered through a retainer-based model, our experts provide immediate access to advanced incident response and forensic capabilities whenever they are needed.
Many organizations operate legacy security operations centers (SOCs) with fragmented tools, manual processes and increasing analyst fatigue. DXC provides a cybersecurity transformation service to assess your current operating model, rationalize technology, standardize workflows and help modernize security operations to improve efficiency, visibility and resilience. We work with your teams to reduce operational complexity, strengthen detection and response capabilities, and establish a roadmap toward more intelligent and automated security operations.
DXC Agentic SOC combines AI-powered security agents, automation and expert analyst oversight to investigate, contextualize and respond to threats at machine speed. Autonomous agents continuously analyze alerts across cloud, identity, endpoint and network environments, accelerating detection and reducing manual effort while operating within customer-defined policy guardrails. The result is faster response, greater operational efficiency and enhanced cyber resilience. Based on proven deployment within DXC's own global operations, Agentic SOC helps organizations scale security operations without proportionally increasing analyst workloads.
Integrate our MDR service with Fortinet technologies and FortiSOAR automation capabilities to streamline detection and response workflows.
Unify threat detection, investigation and response across endpoints, identities, email, cloud workloads and applications using Microsoft Defender XDR, while leveraging Microsoft Sentinel for centralized security analytics, threat detection and SOC operations.
Maximize the value of your CrowdStrike security ecosystem with unified threat detection, investigation and response, from endpoints, to cloud workloads to applications.
Transform your security operations by shifting SOC investigation work to AI agents for exponentially faster, more consistent, efficient results.
How We Operationalize Cyber Operations
Our model is: Advise, Implement, Operate, Improve. It's an integrated cycle, not disconnected phases.
Advise : We assess your security posture, review your threat landscape and identify priorities. Deliverables: baseline, roadmap, business-aligned strategy.
Implement : We design and deploy security capabilities aligned to your priorities. This includes tool selection, integration, customization and team training.
Operate : DXC delivers 24x7 monitoring, detection, response and threat hunting. Our operational metrics let you see what's happening.
Improve : As threats and business needs change, we conduct regular assessments, playbook refinement and team upskilling.
Connect with an Intelligent Cyber expert
Find out how DXC's Cyber Transformation & Operations solutions can help you address a convergence of pressures — expanding attack surfaces, faster adversaries, regulatory demands and a widening skills gap.
WHY choose dxc for cyber operations?
DXC has been delivering security operations services for more than 30 years. We combine proven global SOC delivery, advanced automation, AI-powered security operations and deep cybersecurity expertise to help organizations detect threats earlier, respond faster and strengthen operational resilience. Supported by more than 3,200 cybersecurity professionals across a global network of security operations centers, we provide the scale required by global enterprises while bringing industry-specific expertise to highly regulated environments.
Five security trends shaping the future
DXC CISO Mike Baker identifies five emerging trends that are transforming how we defend against cyber threats.
DXC Named a Leader in the 2025 IDC MarketScape for Managed Detection and Response Services
IDC named DXC Technology a Leader in managed detection and response services.
Cyber resilience: Prepare, protect, detect, respond, recover
Is your business prepared to handle and swiftly recover from a cyber-attack? Even after operational recovery, the financial and reputational consequences can linger for years. To help minimize the impact of a cyber-attack it is important for an organisation to implement a cyber operations and resilience strategy.
Cybersecurity operations refer to the ongoing, day-to-day activities and processes that organizations implement to protect their systems, networks, and data from cyber threats. It's the operational execution side of a cybersecurity program.
DXC Cyber Transformation & Operations is a comprehensive managed security service that combines managed detection and response, incident response, threat and exposure management, and SOC modernization. The service provides 24x7 monitoring from 12 global security operations centers using AI-assisted detection and expert analysis across 450+ global customers in 40+ countries. With 3,200+ dedicated cybersecurity professionals, DXC handles the complete lifecycle of a security incident—from threat detection through incident containment to forensic investigation and recovery. The service addresses the fundamental reality that most organizations cannot hire enough security talent internally or afford the cost of true 24x7 monitoring, so DXC provides both at scale.
Most security teams drown in false positives, with tools generating thousands of alerts daily while analysts can investigate only 5% of them, allowing real threats to hide in the noise. DXC consolidates detection signals from endpoints, cloud systems, identity, and applications into one unified platform, then applies AI-assisted triage to dramatically reduce false positives. Automated playbooks handle routine containment without analyst intervention, freeing security analysts to focus on actual threats instead of chasing false alarms. This combination of unified visibility, intelligent filtering, and automation transforms security teams from reactive firefighters into threat hunters capable of proactive defense.
The DXC Digital Forensics and Incident Response (DFIR) retainer provides pre-committed 24x7 access to DXC's team of 30+ certified forensics experts — with a 15-minute callback SLA and response initiated within 1 hour of escalation. The entry package starts at 120 hours per year, usable for reactive incident response or proactive services including advanced threat hunting, penetration testing, red team exercises, tabletop simulations and a one-time dark web . Unused hours convert to proactive services rather than expiring. A comprehensive Incident Conclusion Report is delivered within 10 business days of case closure. Technology-agnostic delivery; available to all private and public sector organizations in non-restricted countries.
DXC differentiates through four key capabilities: Global scale with local expertise—operating 12 SOCs across 40+ countries provides 24x7 coverage in multiple time zones with localized knowledge of regional compliance (GDPR, NIS2, sector-specific rules); AI and automation with mandatory human oversight—AI accelerates triage and initial investigation, but every alert receives human analyst review and every containment decision requires approval; unified platform approach—most customers operate fragmented tools from multiple vendors, while DXC uses an integrated platform that unifies signals and eliminates visibility gaps; and best-in-class incident response—15-minute response SLA with incident response teams on retainer, proprietary forensic tools built in-house, and staff with industry certifications, law enforcement backgrounds and government agency experience.
Upon threat detection, DXC's team initiates incident verification within 15 minutes and mobilizes full response within one hour—closing the window before attackers can move at their current machine speed (average eCrime breakout is 27 seconds). During the first hour, DXC assigns a dedicated incident response coordinator, conducts preliminary triage and scope assessment, provides initial containment guidance to prevent lateral movement and data exfiltration, and begins forensic collection and analysis if a breach has occurred. This rapid response is enabled by 3,200+ pre-trained professionals positioned 24x7 across global SOCs, pre-established playbooks for common threat types, and access to proprietary threat intelligence that accelerates threat identification and classification.
Organizations face a critical skills shortage: a skilled security analyst costs $120,000–$180,000 annually and organizations need at least 10–15 for true 24x7 coverage—totaling $1.5–2.7 million per year in headcount alone. Hiring is slow, retention is poor due to SOC burnout, and maintaining expertise requires continuous training and certification. Simultaneously, threat velocity has accelerated dramatically (27-second eCrime breakout time, 150% year-over-year increase in state-actor activity) and regulatory mandates increasingly require proof of incident response capability. MDR shifts the burden from customer budgets to the provider while delivering 3,200+ professionals with centralized threat intelligence, proven playbooks, and economies of scale—enabling faster detection, better investigation quality, and regulatory compliance at lower cost than in-house SOCs.
DXC Cyber Transformation & Operations works with your existing infrastructure rather than requiring complete replacement. Integration approaches vary by offering: Managed Detection and Response integrates with your current endpoints, networks, and cloud environments through API connections and agent deployment; Managed XDR specifically leverages Microsoft Defender XDR or CrowdStrike deployments you already own, with DXC managing deployment, tuning, and 24x7 monitoring; SOC Modernization assesses your current tool stack, consolidates overlapping tools, standardizes playbooks across platforms, and retrains staff on integrated workflows. DXC's approach is to enhance and optimize your existing environment rather than mandate wholesale replacement, reducing implementation cost and preserving investments in current technologies while eliminating fragmentation that slows investigations.
DXC serves customers across all industries with specialized expertise for each: Financial Services — detection and response tuned to data theft, fraud and compliance pressure (SOX, PCI DSS); Healthcare — rapid response to ransomware targeting patient-care systems and strict HIPAA compliance; Manufacturing — monitoring of both IT and OT (operational technology) environments for production-disrupting attacks; Energy and Utilities — NERC CIP compliance support and infrastructure-critical response prioritization for SCADA and operational technology systems; Government and Public Sector — Five Eyes cleared personnel, FedRAMP/FISMA compliance and secure facilities for national security requirements; and Retail and E-commerce—POS attack prevention and PCI DSS compliance support. This breadth of industry expertise, combined with global threat intelligence shared across 450+ customers, enables DXC to identify threats and trends earlier than single-industry competitors.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
