ICDATT NG delivers defensive cyber capability as three joined-up disciplines rather than a product drop: continuous observability of the hybrid network, threat detection with investigation and response across the full attack chain, and exposure management that proves posture is actually improving.
Observability — see everything across the environment. We continuously analyse network traffic and identity activity across the data centre, multi-cloud estates, Microsoft 365, edge sites and IoT/OT plant to build one live view of devices, users, service accounts and automated agents. That answers the two questions most institutions cannot answer today: who is doing what on the network, and where are we exposed.
Observability — discover every asset and identity. Every device and workload communicating on the network is inventoried continuously, including managed, unmanaged, transient and third-party systems. Unlike a static asset register or a quarterly scan, the picture is built from real-time activity, so hidden and forgotten assets that create exposure surface instead of sitting in a spreadsheet nobody trusts.
Observability — identify risky access paths. Authentication and access behaviour is analysed across both human and machine identities to reveal how an attacker could move through the estate. Weak, stale, over-privileged and misused identities are named, so the accountable officer can see where identity-driven risk is concentrated and reduce it before it is exploited.
Detection — quality over volume. Behavioural detections sit alongside signatures and threat intelligence to reveal genuine attacks as they unfold, including inside encrypted enterprise traffic, without decryption that would degrade performance and widen data-protection exposure. Coverage spans the whole kill chain across on-premises, multi-cloud, identity, Microsoft 365, edge and IoT/OT: credential abuse and privilege escalation, advanced command-and-control and defence evasion, north-south and east-west lateral movement from on-premises into cloud, and data access and exfiltration.
Detection — automated alert management. Suspicious activity is attributed and connected to the entity behind it, whether identity or device; activity known to be benign in that specific environment is triaged out; remaining activity is correlated and mapped to known attack profiles; and the entity is scored and escalated on attack progression, speed and urgency. Analysts spend their time on real attacks instead of queue clearance.
Investigation — full attack narratives. Entity-centric prioritisation contextualises an attack across dozens of data sources and hundreds of fields: dynamic attack graphs showing how the attacker moves between domains, a step-by-step breakdown of attacker activity by kill-chain stage, and natural-language querying with AI assistance so a mid-tier analyst can go deep without writing query syntax.
Response — containment long before impact. Response is taken automatically or authorised by an analyst from inside the investigation workflow: lock down a compromised identity, isolate an endpoint, and interrupt lateral movement at the firewall. Every action is recorded against the incident for the post-incident review.
Threat hunting — proactive, not reactive. A single console covers hunting across the hybrid estate, with pre-built short-form hunts for policy violations and everyday threats and a regular release cadence of new hunts driven by fresh CVEs and emerging tradecraft. This supports institutions with experienced hunters and those standing up a hunting function from nothing.
Exposure management — assess, improve, prove. We identify risky access paths, excessive permissions, weak identity hygiene, unsafe connections and the gaps an attacker is most likely to use, then tighten controls to limit blast radius. Prioritised risk, detection trends and response performance are tracked so repeat offenders and remediation outcomes are visible, and triage workflows are refined against real activity.
Exposure management — audit-ready evidence. Exposure reduction, response effectiveness and posture gains are reported with defensible evidence, mapped to recognised frameworks including MITRE ATT&CK and the compliance standards the institution answers to, and translated into executive-level reporting for the board and the regulator.
Every engagement is scoped in writing, delivered against a schedule, and reported to the accountable officer, with operator and analyst training so the capability stays inside the institution.