3CORESec
3CORESec is a Lisbon-based cybersecurity vendor that sells a cloud-native MDR platform combining SIEM, SOAR, cloud security, and ML-based threat prediction to enterprises, MSSPs, and field operators via subscriptions and a partner channel.
- Company typePrivate
- Founded2019
- HeadquartersLisbon, Portugal
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What 3CORESec does
3CORESec (legal entity 3CSEC-IT INFRASTRUCTURE SECURITY LDA) is a privately held Portuguese cybersecurity vendor founded in 2019 and headquartered in Lisbon, with a second European office in Rijswijk, Netherlands. The company builds a cloud-native, vertically integrated cybersecurity platform that combines Managed Detection & Response (MDR), next-generation SIEM and Data Lake (Atalaia), Security Orchestration and Automation (vSOC), Cloud Security, and the Preemptive Threat Landscape (PTL), an ML-based anomaly detection and threat forecasting module. Adjacent solutions include Detection as a Service (DaaS) for subscription-based detection rulesets, Lawmaker for Suricata IDS sensor management, the RADR self-contained hardware unit for field incident response, and platform-neutral Advisory Services. The stack is built on a real-time API-based architecture processing 400,000 events per second, with native integrations into AWS Security Hub (validated through AWS Foundational Technical Review), Azure Sentinel, Suricata, and six SIEM engines.
The company operates a horizontal go-to-market targeting organizations from startups to multinationals, with Managed Security Service Providers (MSSPs) as a primary channel segment alongside direct enterprise customers. Revenue is generated primarily through recurring subscriptions across MDR, DaaS, and Lawmaker SaaS, complemented by hardware sales (RADR), professional services (Advisory), and partner-led distribution via the 3CORESec Partner Program (3PP). Pricing is quote-based with no public tiers, and the company positions affordability relative to legacy enterprise security platforms as a differentiator. The firm is founder-led by CEO Tiago Faria, maintains a sub-ten-person team, has recorded no external funding rounds in the available data, and has not disclosed revenue, customer counts, or contractual metrics, which constrains direct measurement of commercial scale.
3CORESec firmographics
Firmographics- Name
- 3CORESec
- Legal name
- 3CSEC-IT INFRASTRUCTURE SECURITY LDA
- Website
- https://3coresec.com
- Company type
- Private
- Founded year
- 2019
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- 3CORESec is a Lisbon-based cybersecurity vendor that sells a cloud-native MDR platform combining SIEM, SOAR, cloud security, and ML-based threat prediction to enterprises, MSSPs, and field operators via subscriptions and a partner channel.
- Ownership category
- akta.pro rank
3CORESec industry classification
Industry- Product category
- Cybersecurity Software (Managed Detection & Response)
- NAICS
- Computer Systems Design and Related Services (5415), Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (518210)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Prepackaged Software (7372)
- akta.pro primary industry
- Managed Detection & Response (MDR) & SOC Services (HDADAGAG)
- akta.pro secondary industries
- Security Operations Center (SOC) as a Service (BPAEADAB), Threat Intelligence Services (BPAEADAC), Network Security Managed Services (Firewall/IDS/IPS/SASE) (BPAEADAG), Cybersecurity & Identity Consulting (BPAHAEAG)
Keywords
Where 3CORESec is headquartered
LocationHeadquarters
- HQ city
- Lisbon
- HQ country
- Portugal
- HQ region
- Europe
Offices2 records
Markets served
3CORESec business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Supply Chain
Revenue model
- Platform Subscription (MDR): Fully managed subscription-based MDR platform providing real-time visibility, control and remediation. Includes all platform components (SIEM, SOAR, Cloud Security, PTL) with continuous updates and expert management.
- Lawmaker SaaS: SaaS subscription for Suricata IDS sensor management with multi-tenancy, RBAC, and signature validation features. OEM integration available for partners bypassing subscription model.
- Detection as a Service: Subscription-based service providing actionable threat detection rulesets with continuous integration and delivery. Includes support and implementation assistance.
- Advisory Services: Expert advisory consulting services spanning cloud security, detection engineering, threat hunting, and network security. Platform-neutral approach that enhances existing security tools.
- RADR Hardware/Unit: Self-contained cybersecurity unit sold as a complete package including hardware and software for field deployment. Requires only electrical power to operate.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Contact sales for custom pricing based on organization size and requirements |
Go-to-market motion2 records
Distribution channels2 records
Marketing channels7 records
3CORESec product offering
Product offeringCore offering
3CORESec develops and sells a fully managed, vertically integrated cybersecurity platform that combines Managed Detection & Response, Cloud Security, Security Orchestration & Automation (vSOC), and an ML-based Preemptive Threat Landscape. It complements this platform with standalone solutions such as Detection as a Service (DaaS) threat-detection rulesets, Lawmaker for Suricata IDS management, RADR as a self-contained field-deployed response unit, and Advisory Services for expert-led consulting. The platform targets organizations ranging from startups to multinationals, with particular emphasis on MSSPs and security providers seeking turnkey, multi-tenant detection and response capabilities.
Product overview
3CORESec offers a unified cybersecurity platform combining Managed Detection & Response (MDR), Cloud Security, Security Orchestration & Automation (vSOC), and Preemptive Threat Landscape (PTL). The platform is enhanced by specialized solutions including Detection as a Service (DaaS) providing actionable detection rulesets, Lawmaker for Suricata IDS management, Rapid and Assisted Detection & Response (RADR) for field incident response, and Advisory Services for expert guidance. Additional offerings include Atalaia (next-gen SIEM and data lake) and 3CS for AWS integration. The ecosystem supports 6 SIEM engines and integrates with AWS Security Hub and Azure Sentinel.
Differentiator
Problem solved
Functional benefit
Brands
- Atalaia: Next-gen SIEM & Data Lake for optimization, threat hunting, detection, and response at any scale.
- Lawmaker
- RADR
- DaaS
- vSOC
- PTL
Products and services
- Managed Detection & Response (MDR) Fully managed SIEM-based managed detection and response platform that delivers real-time visibility, control, and remediation. Processes 400,000 events per second, with sub-10-minute deployment and sub-10-second response time, integrating SIEM, SOAR, cloud security, and ML-based threat prediction.
- Cloud Security Cloud-native security platform offering automated compliance checks, intrusion detection, and ML-powered anomaly detection across cloud workloads. Integrates with AWS Security Hub and Azure Sentinel and includes 400+ detection capabilities covering 90% of the Cloud ATT&CK Matrix.
- Security Orchestration & Automation (vSOC) Virtual Security Operations Center (vSOC) with intelligent playbook integration and a virtual assistant for incident response automation. Enables one-click playbook activation with sub-10-second automated remediation and provides mean time to detect under 20 seconds and mean time to respond under 40 seconds.
- Preemptive Threat Landscape (PTL) Advanced machine learning platform for early threat prediction and anomaly detection using behavioral analysis and threat modeling. Provides 99% model accuracy, 500ms decision time, and processes 10M+ data points for predictive security.
- Detection as a Service (DaaS) Subscription-based service providing actionable threat detection rulesets delivered via CI/CD pipeline automation to enrich existing security tooling. Includes over 1,500 signatures achieving 85% MITRE ATT&CK Enterprise Coverage across six SIEM engines.
- Lawmaker SaaS platform for Suricata Network IDS sensor management with multi-tenancy, role-based access control, device health monitoring, and signature validation. Supports seamless integration with any Suricata deployment, with OEM integration available for partners.
- Rapid and Assisted Detection & Response (RADR) Self-contained cybersecurity unit — hardware and software — for rapid incident response and field usage. Ships fully configured for immediate threat detection, deployable in under 24 hours with 5-minute setup, featuring tamper-proof packaging and data self-deletion for client confidentiality.
- Advisory Services Expert advisory consulting services spanning cloud security, detection engineering, threat hunting, and network security, delivered with a platform-neutral approach that enhances existing security tools and frameworks.
- 3CS for AWS AWS-specific security offering providing real-time visibility, control, and remediation for AWS environments through the 3CORESec platform, validated under the AWS Foundational Technical Review (FTR) program.
- Atalaia Next-generation SIEM and Data Lake providing optimized data handling, threat hunting, detection, and response capabilities at any scale as part of the 3CORESec ecosystem.
Quantifiable outcome
- <10 minute deployment time for MDR platform
- +8 more outcomes
Companies that use 3CORESec
Customer profileSegments5 records
Ideal customer profiles3 records
3CORESec technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration4 records
AI capability7 records
Feature8 records
3CORESec partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- Amazon Web Services (AWS)core3CS for AWS partnership providing real-time visibility, control and remediation for AWS environments. The platform integrates with AWS Security Hub and offers specialized cloud security capabilities for AWS workloads. Includes NIDS (Network Intrusion Detection System) integration with AWS as an AWS FTR (Foundational Technical Review) validated solution.
Scale indicators17 records
Recent moves6 records
Expansion highlights4 records
3CORESec competitors and assessment
Company assessmentDirect peers
- Huntress: Managed detection and response vendor focused on SMB and the MSP/MSSP channel. Comparable to 3CORESec in its channel-first GTM, fully managed service delivery, and use of platform telemetry to deliver security outcomes without large customer-side teams.
- eSentire: Pure-play MDR provider offering 24/7 SOC services across network, endpoint, and cloud. Directly comparable to 3CORESec's MDR platform with overlapping capabilities in SIEM/SOAR-style orchestration and managed threat response.
- Expel: MDR vendor delivering transparent SOC-as-a-service with strong SOAR-driven automation and integrations across cloud and SaaS. Comparable to 3CORESec in transparent managed service model, SOAR-led response, and integration with existing customer tooling.
- Arctic Wolf: Pure-play MDR / SOC-as-a-service vendor targeting SMB and mid-market via MSSP and channel partners. Closely comparable to 3CORESec in managed detection positioning, fully managed service model, and emphasis on operational simplicity without in-house security staff.
Broad incumbents
- Sophos (Sophos MDR): Established cybersecurity vendor with a managed detection and response service built on its own endpoint, network, and cloud controls. Comparable to 3CORESec's MDR + SIEM/SOAR stack but as a much larger incumbent with broader portfolio.
- SentinelOne: Endpoint and cloud security vendor with XDR, MDR-style managed services, and a growing SIEM/data lake offering (Singularity Data Lake). Directly overlaps with 3CORESec's platform modules but with substantially larger R&D and sales footprint.
- Elastic Security: SIEM and security analytics platform built on the Elastic stack with detection, threat hunting, and response capabilities. Comparable to 3CORESec's Atalaia SIEM/Data Lake offering, with stronger enterprise brand but less bundled managed service.
- CrowdStrike: Leading XDR/EDR platform that has expanded into SIEM (LogScale), SOAR, MDR (Falcon Complete), and cloud security. Overlaps with 3CORESec across MDR, cloud detection, and SOAR but at vastly larger scale and platform breadth.
- Rapid7: Security analytics and MDR vendor combining SIEM (InsightIDR), vulnerability management, and managed detection services. Comparable to 3CORESec in combining SIEM + MDR with managed SOC options for mid-market and enterprise customers.
Emerging players
- Todyl: SMB-focused security platform that bundles SASE, EDR, SIEM, and MDR-style managed services into a single console for MSPs. Comparable to 3CORESec's horizontally integrated, channel-first approach targeting non-enterprise customers.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
3CORESec social profiles
Digital presence3CORESec financial estimates
Financial estimateRevenue estimate
Valuation estimate
3CORESec leadership team
Management profileNumber of profiles
Profiles1 record
3CORESec funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
3CORESec M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about 3CORESec
What does 3CORESec do?
3CORESec develops and sells a fully managed, vertically integrated cybersecurity platform that combines Managed Detection & Response, Cloud Security, Security Orchestration & Automation (vSOC), and an ML-based Preemptive Threat Landscape. It complements this platform with standalone solutions such as Detection as a Service (DaaS) threat-detection rulesets, Lawmaker for Suricata IDS management, RADR as a self-contained field-deployed response unit, and Advisory Services for expert-led consulting. The platform targets organizations ranging from startups to multinationals, with particular emphasis on MSSPs and security providers seeking turnkey, multi-tenant detection and response capabilities.
Is 3CORESec a public or private company?
3CORESec is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was 3CORESec founded?
3CORESec was founded in 2019. It employs 1 to 10 people.
Where is 3CORESec based?
3CORESec is headquartered in Lisbon, Portugal, in the Europe region.
How does 3CORESec make money?
Five revenue lines are on record. Platform Subscription (MDR) is the primary driver. The others are lawmaker SaaS, detection as a Service, advisory Services and RADR Hardware/Unit.
Who are 3CORESec's main competitors?
Direct peers on record are Huntress, eSentire, Expel and Arctic Wolf. Broad incumbents are Sophos (Sophos MDR), SentinelOne, Elastic Security, CrowdStrike and Rapid7. Todyl is listed as an emerging player.
Does 3CORESec have an API?
Yes. 3CORESec platform processes, normalizes, alerts and enriches data in real-time through its API-based intrusion detection. The platform offers a real-time API for data integration, visualization, and threat detection with 400,000 events per second processing capability.
What industry is 3CORESec in?
3CORESec's product category is Cybersecurity Software (Managed Detection & Response). Its primary akta.pro industry code is HDADAGAG, Managed Detection & Response (MDR) & SOC Services, with a secondary code of BPAEADAB, Security Operations Center (SOC) as a Service. Its NAICS code is 5415 and its SIC code is 7370.