OmniSOC
OmniSOC is a shared 24/7 security operations center operated by Indiana University that delivers SIEM-based threat monitoring, threat intelligence, and incident response on a subscription basis to colleges, universities, research networks, NSF facilities, and federal agencies.
- Company typePrivate
- Founded2018
- HeadquartersBLOOMINGTON, Indiana, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What OmniSOC does
OmniSOC is a shared security operations center for higher education institutions, research and education networks, NSF research facilities, and select federal agencies, founded in 2018 and operated as an entity of Indiana University in Bloomington, Indiana. It provides 24/7/365 monitoring, threat intelligence, incident notification, threat hunting, security event analysis, and call-center services across member institutions, processing on average 22.5 billion events per day and roughly 23 TB of telemetry. The underlying platform is an Elasticsearch-based SIEM with Kafka streaming architecture, augmented by machine learning for threat detection and correlation, the STINGAR honeypot system (developed by Duke University) for attacker trapping, and a tiered analyst escalation model (Tier 1 triage, Tier 2 deep analysis with on-call coverage).
Revenue is generated primarily through annual membership subscriptions priced at higher-education-sector-appropriate levels that scale with institutional size, supplemented by add-on modules — Hosted SIEM, Virtual Cybersecurity Services (virtual CISO/engineer/team), Vulnerability Scanning, and Research Proposal Support. The ResearchSOC sub-brand, funded by the NSF, extends coverage to open science and NSF Major Facilities with regulatory alignment to NIST 800-171 and CIS Controls v8.1. Go-to-market is community-led, relying on REN-ISAC peer networks, NSF research relationships, annual joint events (RIMM / OmniSOC Con), webinars, whitepapers, and direct outreach to institutional CISOs through Indiana University channels; no self-service or marketplace channel exists.
OmniSOC firmographics
Firmographics- Name
- OmniSOC
- Legal name
- OmniSOC
- Website
- https://omnisoc.iu.edu
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- OmniSOC is a shared 24/7 security operations center operated by Indiana University that delivers SIEM-based threat monitoring, threat intelligence, and incident response on a subscription basis to colleges, universities, research networks, NSF facilities, and federal agencies.
- Ownership category
- akta.pro rank
OmniSOC industry classification
Industry- Product category
- Managed Security Operations Center (SOC) Services
- NAICS
- Security Systems Services (except Locksmiths) (561621), Security Systems Services (56162)
- SIC
- Services-Facilities Support Management Services (8744), Services-Business Services, Nec (7389)
- akta.pro primary industry
- IT Governance, Risk & Compliance (IT GRC) Platforms (HDAEALAK)
Keywords
Where OmniSOC is headquartered
LocationHeadquarters
- HQ city
- BLOOMINGTON, Indiana
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
OmniSOC business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Infrastructure, Technology or R&D, Operations, Marketing or Sales
Revenue model
- OmniSOC Core Membership: Annual membership fee-based model providing access to core SOC services including 24/7 monitoring, threat intelligence, incident notifications, information sharing, threat hunting, analysis, and call center services. Membership fees are described as 'higher education sector-appropriate' and scale with institutional size. All OmniSOC members receive core services as part of their annual membership fee.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | OmniSOC Core Membership — base tier for all members |
| Subscription | Annual | Hosted SIEM — add-on for member security staff |
| Subscription | Annual | Virtual Cybersecurity Services — partial-FTE security professionals |
| Subscription | Annual | Vulnerability Scanning — add-on service |
Go-to-market motion1 record
Distribution channels2 records
Marketing channels10 records
OmniSOC product offering
Product offeringCore offering
OmniSOC is a shared 24/7/365 security operations center that delivers high-priority, actionable network alerts to higher education, research, and government member institutions. Its core offering combines monitoring, triage, threat hunting, threat intelligence, incident notifications, and call center services, with cross-member indicator of compromise searching that creates a collective defense effect. Add-on services include ResearchSOC for NSF research facilities, Hosted SIEM, Virtual Cybersecurity Services (virtual CISO/team), Vulnerability Scanning, and Research Proposal Support, all delivered under a sector-appropriate annual membership model.
Product overview
OmniSOC is a shared security operations center (SOC) for higher education, research institutions, and regional networks, founded in 2018 as an entity of Indiana University. The core offering is OmniSOC Core Services—a 24/7 managed SOC providing high-quality, actionable network alerts through monitoring, threat intelligence, threat hunting, and incident notification. This core platform is extended through add-on modules: ResearchSOC (specialized cybersecurity for NSF research facilities with honeypots and dedicated liaisons), Hosted SIEM (enabling members to independently view security data), Virtual Cybersecurity Services (fractional security staffing), Vulnerability Scanning, and Research Proposal Support. The architecture processes member data through Kafka and Elasticsearch, with STINGAR providing additional threat intelligence through honeypot deployments. All services are designed for the higher education sector and emphasize collaborative defense across member institutions.
Differentiator
Problem solved
Functional benefit
Brands
- ResearchSOC: A specialized service offering for National Science Foundation (NSF) research facilities, providing cybersecurity technologies, training, and personnel specifically designed for NSF research needs.
Products and services
- OmniSOC Core Services 24/7/365 managed SOC offering combining monitoring, distilling, analyzing, investigating, and triaging to deliver high-quality, actionable network alerts to members. Includes cyber threat intelligence, incident notifications, information sharing, threat hunting, security event analysis, monitoring and triage, and call center services. Targeted at higher education institutions, research facilities, R&E networks, and federal agency members.
- ResearchSOC Specialized cybersecurity service package of technologies, training, and personnel designed for NSF research facilities and open science projects. Includes honeypots (STINGAR decoy computers), dedicated project liaison analysts, project management, technical expertise, and metrics reporting. Targeted at NSF Major Facilities and federally funded research operators.
- Hosted SIEM Add-on service providing member institution security staff the same SIEM view as OmniSOC analysts, enabling independent monitoring alongside OmniSOC's managed alerting. Available for an additional nominal fee beyond core membership.
- Virtual Cybersecurity Services Flexible fractional security staffing options including Virtual Security Team, Virtual CISO, Virtual Security Engineer, and CISO Advisory. Provides partial-FTE security professionals to address personnel shortfalls without requiring full-time hires. OmniSOC provides benefits and career progression to the assigned staff.
- Vulnerability Scanning External scanning of member-owned internet-accessible IP addresses to identify known software vulnerabilities, end-of-life software, and configuration weaknesses before they can be exploited. Provided as an add-on to core membership.
- Research Proposal Support Assistance for NSF research facilities in incorporating ResearchSOC cybersecurity services into grant proposals, including customized collaboration letters and service level consultation prior to submission.
Quantifiable outcome
- Average 23 TB of data processed per day across all members
- +4 more outcomes
Companies that use OmniSOC
Customer profileNamed customers23 records
Segments5 records
Ideal customer profiles5 records
OmniSOC technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature6 records
OmniSOC partnerships and signals
Strategic signalPartnerships
Seven partnerships are on record, tiered minor and core.
- International Cybersecurity Threat Intelligence Sharing Partners (Australia, Canada, UK)minorOmniSOC collaborates with counterparts in Australia, Canada, and the UK in a cybersecurity threat intelligence-sharing partnership announced in 2021.
- GlobalNOC (Indiana University)coreOmniSOC operates in conjunction with the formidable capabilities of the Global Network Operations Center (GlobalNOC) housed at Indiana University. OmniSOC leverages GlobalNOC's extensive experience in supporting R&E networks. GlobalNOC provides network operations capabilities and infrastructure that underpin OmniSOC's security operations.
- REN-ISAC (Research and Education Networks Information Sharing and Analysis Center)coreREN-ISAC is housed at Indiana University alongside OmniSOC. OmniSOC uses threat intelligence insights from REN-ISAC. The two organizations co-host the annual RIMM (REN-ISAC Member Meeting) and OmniSOC Con as a joint event. OmniSOC shares threat intelligence with REN-ISAC for distribution to members.
- Trusted CI (NSF Cybersecurity Center of Excellence)coreOmniSOC (including ResearchSOC) has adopted the Trusted CI Framework for its own security program. OmniSOC provides advice to members on using the Framework. ResearchSOC leverages the Trusted CI Framework to align with the needs of science and research cybersecurity requirements.
- Duke University (STINGAR)coreResearchSOC uses STINGAR (Sharing Threat Intelligence for Network Gatekeeping with Automated Response), developed by Duke University, for deploying honeypots (decoy computers) on research facility networks to trap attackers and provide increased threat intelligence.
- Elastic (SIEM Platform)coreOmniSOC uses Elasticsearch as the core SIEM platform for indexing, analyzing, and correlating security event data from member institutions. The organization provides an Elastic SIEM Guide as a partner resource.
- NSF ResearchSOC (National Science Foundation)coreResearchSOC, the NSF Research Security Operations Center, is a service offered by OmniSOC and funded by the NSF in 2018. It is the only collaborative SOC supporting NSF research with an institutional data-sharing agreement for researchers. NSF funding enables provision of cybersecurity for the nation's greatest research.
Scale indicators7 records
Recent moves6 records
Expansion highlights6 records
OmniSOC competitors and assessment
Company assessmentDirect peers
- eSentire: Managed detection and response and SOC services provider with 24/7 global security operations centers. Direct peer in delivering continuous monitoring, threat hunting, and incident response as a managed service to organizations lacking in-house SOC capacity.
- Expel: Managed detection and response (MDR) provider delivering 24/7 SOC-as-a-service using transparent, cloud-native architecture. Direct peer to OmniSOC's managed monitoring, threat hunting, and incident notification model, though serving enterprise customers across many verticals.
- Binary Defense: Managed detection and response provider offering 24/7 SOC-as-a-service with threat hunting. Comparable to OmniSOC's tiered analyst model and continuous monitoring approach, though primarily serving mid-market commercial customers.
- ReliaQuest: Enterprise managed security and SaaS-based SOC operations provider delivering 24/7 threat monitoring, detection, and response. Direct peer to OmniSOC's managed SOC model, though serving enterprise customers across multiple verticals rather than higher ed.
- Arctic Wolf: Commercial Security Operations cloud vendor offering managed detection and response (MDR) and managed SOC services to organizations of all sizes. Directly comparable to OmniSOC as an outsourced SOC delivering 24/7 monitoring and threat response, but serves the broad commercial market rather than the higher-ed vertical.
Broad incumbents
- Sophos MDR: Cybersecurity incumbent with a managed detection and response service line serving SMB and mid-market education customers. Comparable as an MDR/SOC service but broader portfolio across endpoint, network, and email security rather than OmniSOC's pure-play SOC focus.
- CrowdStrike (Falcon Complete MDR): Endpoint security leader with its own Falcon Complete MDR offering providing 24/7 managed SOC operations. Comparable to OmniSOC in delivering managed monitoring and remediation but backed by CrowdStrike's massive endpoint telemetry and AI stack.
- Secureworks (Taegis): Long-standing managed security services provider offering Taegis MDR/XDR and managed SOC services. Directly comparable to OmniSOC's managed SOC model but with broader enterprise/government customer base and commercial SaaS delivery.
Others
- Internet2: Non-profit U.S. research and education network consortium providing cybersecurity services and InCommon identity federation. Adjacent peer in serving the higher-ed/ResearchSOC audience with network and security capabilities, often as a complementary infrastructure provider.
- REN-ISAC: Research and Education Networks Information Sharing and Analysis Center, co-located at Indiana University with OmniSOC. Comparable as a community/peer organization serving higher ed security with threat intelligence sharing and joint events (RIMM), but focuses on threat intel rather than managed SOC operations.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks1 record
Key highlights6 records
Customer concentration
OmniSOC social profiles
Digital presenceOmniSOC financial estimates
Financial estimateRevenue estimate
Valuation estimate
OmniSOC leadership team
Management profileNumber of profiles
Profiles2 records
OmniSOC funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
OmniSOC M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about OmniSOC
What does OmniSOC do?
OmniSOC is a shared 24/7/365 security operations center that delivers high-priority, actionable network alerts to higher education, research, and government member institutions. Its core offering combines monitoring, triage, threat hunting, threat intelligence, incident notifications, and call center services, with cross-member indicator of compromise searching that creates a collective defense effect. Add-on services include ResearchSOC for NSF research facilities, Hosted SIEM, Virtual Cybersecurity Services (virtual CISO/team), Vulnerability Scanning, and Research Proposal Support, all delivered under a sector-appropriate annual membership model.
Is OmniSOC a public or private company?
OmniSOC is a private company. It is classified as state government owned and is currently operating.
When was OmniSOC founded?
OmniSOC was founded in 2018. It employs 11 to 50 people.
Where is OmniSOC based?
OmniSOC is headquartered in BLOOMINGTON, Indiana, United States, in the North America region.
How does OmniSOC make money?
One revenue line is on record: omniSOC Core Membership.
Who are OmniSOC's main competitors?
Direct peers on record are eSentire, Expel, Binary Defense, ReliaQuest and Arctic Wolf. Broad incumbents are Sophos MDR, CrowdStrike (Falcon Complete MDR) and Secureworks (Taegis). Others are Internet2 and REN-ISAC.
Does OmniSOC have an API?
No public API is recorded for OmniSOC.
What industry is OmniSOC in?
OmniSOC's product category is Managed Security Operations Center (SOC) Services. Its primary akta.pro industry code is HDAEALAK, IT Governance, Risk & Compliance (IT GRC) Platforms. Its NAICS code is 561621 and its SIC code is 8744.