Skip to content
ICDATTNG

SL-03 — Service line

Cyber

Continuous network observability, AI-driven threat detection, investigation and response, and exposure management for institutions that hold sensitive operational and personal data.

ICDATT NG delivers defensive cyber capability as three joined-up disciplines rather than a product drop: continuous observability of the hybrid network, threat detection with investigation and response across the full attack chain, and exposure management that proves posture is actually improving.

Observability — see everything across the environment. We continuously analyse network traffic and identity activity across the data centre, multi-cloud estates, Microsoft 365, edge sites and IoT/OT plant to build one live view of devices, users, service accounts and automated agents. That answers the two questions most institutions cannot answer today: who is doing what on the network, and where are we exposed.

Observability — discover every asset and identity. Every device and workload communicating on the network is inventoried continuously, including managed, unmanaged, transient and third-party systems. Unlike a static asset register or a quarterly scan, the picture is built from real-time activity, so hidden and forgotten assets that create exposure surface instead of sitting in a spreadsheet nobody trusts.

Observability — identify risky access paths. Authentication and access behaviour is analysed across both human and machine identities to reveal how an attacker could move through the estate. Weak, stale, over-privileged and misused identities are named, so the accountable officer can see where identity-driven risk is concentrated and reduce it before it is exploited.

Detection — quality over volume. Behavioural detections sit alongside signatures and threat intelligence to reveal genuine attacks as they unfold, including inside encrypted enterprise traffic, without decryption that would degrade performance and widen data-protection exposure. Coverage spans the whole kill chain across on-premises, multi-cloud, identity, Microsoft 365, edge and IoT/OT: credential abuse and privilege escalation, advanced command-and-control and defence evasion, north-south and east-west lateral movement from on-premises into cloud, and data access and exfiltration.

Detection — automated alert management. Suspicious activity is attributed and connected to the entity behind it, whether identity or device; activity known to be benign in that specific environment is triaged out; remaining activity is correlated and mapped to known attack profiles; and the entity is scored and escalated on attack progression, speed and urgency. Analysts spend their time on real attacks instead of queue clearance.

Investigation — full attack narratives. Entity-centric prioritisation contextualises an attack across dozens of data sources and hundreds of fields: dynamic attack graphs showing how the attacker moves between domains, a step-by-step breakdown of attacker activity by kill-chain stage, and natural-language querying with AI assistance so a mid-tier analyst can go deep without writing query syntax.

Response — containment long before impact. Response is taken automatically or authorised by an analyst from inside the investigation workflow: lock down a compromised identity, isolate an endpoint, and interrupt lateral movement at the firewall. Every action is recorded against the incident for the post-incident review.

Threat hunting — proactive, not reactive. A single console covers hunting across the hybrid estate, with pre-built short-form hunts for policy violations and everyday threats and a regular release cadence of new hunts driven by fresh CVEs and emerging tradecraft. This supports institutions with experienced hunters and those standing up a hunting function from nothing.

Exposure management — assess, improve, prove. We identify risky access paths, excessive permissions, weak identity hygiene, unsafe connections and the gaps an attacker is most likely to use, then tighten controls to limit blast radius. Prioritised risk, detection trends and response performance are tracked so repeat offenders and remediation outcomes are visible, and triage workflows are refined against real activity.

Exposure management — audit-ready evidence. Exposure reduction, response effectiveness and posture gains are reported with defensible evidence, mapped to recognised frameworks including MITRE ATT&CK and the compliance standards the institution answers to, and translated into executive-level reporting for the board and the regulator.

Every engagement is scoped in writing, delivered against a schedule, and reported to the accountable officer, with operator and analyst training so the capability stays inside the institution.

Capability

  • 01Continuous observability across on-premises, multi-cloud, SaaS, edge and IoT/OT
  • 02Live inventory of devices, workloads, users, service accounts and machine identities
  • 03Identity and access path analysis: stale, weak, over-privileged and misused accounts
  • 04Behavioural threat detection across the full kill chain, including encrypted traffic without decryption
  • 05Detection of credential abuse, privilege escalation, command-and-control and defence evasion
  • 06Detection of north-south and east-west lateral movement, data access and exfiltration
  • 07Automated triage, entity attribution and attack-profile correlation with urgency scoring
  • 08Investigation with dynamic attack graphs, kill-chain narratives and natural-language querying
  • 09Response: identity lockdown, endpoint isolation and firewall-level containment
  • 10Threat hunting with pre-built hunts and a CVE-driven release cadence
  • 11Exposure assessment, control validation and posture improvement tracking
  • 12Audit-ready reporting mapped to MITRE ATT&CK and applicable compliance standards
  • 13Analyst, staff and operator training
Request a briefing

Capability pillars

How the capability is built

SL-03.A

Network observability

One live picture of the hybrid estate, built from real network and identity activity rather than a static asset register.

  • Continuous analysis of network traffic and identity activity across data centre, multi-cloud, Microsoft 365, edge sites and IoT/OT plant
  • Live inventory of managed, unmanaged, transient and third-party devices, workloads and service accounts
  • Risky access-path mapping across human and machine identities
  • One view that answers who is doing what on the network, and where the institution is exposed
Network observability console showing a hybrid estate topology across data centre, multi-cloud, SaaS and IoT zones with device and identity inventory panels
SL-03.B

Threat detection, investigation and response

Behavioural detection across the full kill chain, automated triage, entity-level attack narratives and containment from inside the investigation.

  • Behavioural detections alongside signatures and threat intelligence, including inside encrypted traffic without decryption
  • Coverage of credential abuse, privilege escalation, command-and-control, defence evasion, lateral movement and exfiltration
  • Automated triage: benign activity suppressed, real activity attributed to the entity, scored and escalated on attack progression
  • Dynamic attack graphs, kill-chain narratives and natural-language querying with AI assistance
  • Response actions — identity lockdown, endpoint isolation, firewall-level containment — recorded against the incident
Threat operations console showing a kill-chain attack graph, prioritised entities with urgency scores and containment actions for identity lockdown and endpoint isolation
SL-03.C

Network exposure management

Assess, reduce and prove posture: risky paths closed, blast radius limited, and evidence the board and regulator can rely on.

  • Identification of excessive permissions, weak identity hygiene, unsafe connections and likely attacker routes
  • Control tightening to limit blast radius, tracked against prioritised risk
  • Detection trends, response performance and repeat-offender visibility over time
  • Reporting mapped to MITRE ATT&CK and the institution's compliance obligations, translated for board level
Network exposure management dashboard showing a risk heat map, identity privilege paths converging on a critical asset, a falling exposure trend and compliance framework coverage tiles

Operating problem

What this service line exists to solve

SL-03.01

Nobody has the full asset picture

Static registers and periodic scans miss unmanaged, transient and third-party systems. Exposure sits in the assets no one knew were talking on the network.

SL-03.02

Identity is the soft route in

Stale accounts, shared service credentials and over-privileged access let an attacker move laterally using legitimate authentication that prevention tools wave through.

SL-03.03

Alert volume exceeds analyst capacity

Lean security teams drown in low-fidelity alerts. Real attacks are present in the queue but nothing in the tooling separates them from noise.

SL-03.04

Encryption hides the attack

Most enterprise traffic is encrypted, and decryption-based inspection degrades performance and creates its own data-protection liability.

SL-03.05

Hybrid estates break single-domain tooling

Attacks now cross from on-premises into cloud and SaaS in one chain, while tooling watches each domain separately and loses the thread at the boundary.

SL-03.06

Posture cannot be proven to the board or regulator

Leadership is asked to certify control effectiveness with no trend evidence that exposure is falling and response is getting faster.

Workflows

How the work runs, step by step

WF-01

Stand up observability

From first sensor placement to a trusted live inventory of the estate.

  1. Step 01

    Scope and sensor placement

    We agree the domains in scope — data centre, cloud tenants, Microsoft 365, edge sites, IoT/OT — and map traffic aggregation points, span/mirror sources and cloud flow feeds with the network owner.

  2. Step 02

    Deploy and connect

    Sensors are deployed out-of-band on the network and read-only connectors are authorised for cloud and identity providers. No agents on production endpoints are required, and no traffic is decrypted.

  3. Step 03

    Baseline the estate

    Two to four weeks of live activity builds the inventory of devices, workloads, users, service accounts and machine identities, including systems missing from the official register.

  4. Step 04

    Publish the picture

    The accountable officer receives the asset and identity baseline, the risky access paths found, and a named owner for each gap that needs closing.

WF-02

Detect and triage

How suspicious activity becomes a single, ranked incident.

  1. Step 01

    Behavioural detection fires

    Activity that matches attacker behaviour — credential abuse, privilege escalation, command-and-control, lateral movement, staging for exfiltration — is flagged across on-premises, cloud, identity and SaaS.

  2. Step 02

    Attribute to an entity

    The activity is attributed to the identity or device behind it, so a chain of events across domains resolves to one actor rather than a dozen unrelated alerts.

  3. Step 03

    Suppress the known-benign

    Behaviour proven benign in that specific environment is triaged out automatically, tuned against the institution's own baseline instead of a generic profile.

  4. Step 04

    Correlate and score

    Remaining activity is correlated, mapped to known attack profiles and scored on attack progression, speed and urgency. Analysts work a ranked list of entities, not a queue of alerts.

WF-03

Investigate and respond

From escalation to containment, with a defensible record.

  1. Step 01

    Open the attack narrative

    The analyst opens an entity and sees the full story: a dynamic attack graph of movement between domains and a step-by-step breakdown by kill-chain stage, contextualised across dozens of data sources.

  2. Step 02

    Question the data

    Natural-language querying with AI assistance lets a mid-tier analyst go deep — scope, blast radius, what else the identity touched — without writing query syntax.

  3. Step 03

    Contain

    From inside the investigation, the analyst locks down the compromised identity, isolates the endpoint and interrupts lateral movement at the firewall. Pre-authorised actions can run automatically.

  4. Step 04

    Record and review

    Every detection, decision and action is recorded against the incident and issued to the accountable officer with a post-incident review and the control changes required.

WF-04

Manage exposure and prove posture

The continuous loop that makes the estate harder to attack.

  1. Step 01

    Assess

    Risky access paths, excessive permissions, stale and shared credentials, unsafe connections and the routes an attacker is most likely to use are identified and prioritised by impact.

  2. Step 02

    Reduce

    Controls are tightened with the system owners to close those paths and limit blast radius, with each change tracked to a named owner and a date.

  3. Step 03

    Hunt

    Pre-built short-form hunts cover policy violations and everyday threats, with new hunts released against fresh CVEs and emerging tradecraft, run either by the institution's hunters or by our analysts.

  4. Step 04

    Prove

    Exposure reduction, detection trends and response performance are reported with defensible evidence mapped to MITRE ATT&CK and the applicable compliance standards, in board- and regulator-ready form.

Delivered outcome

What the client gets back

One live picture of the estate

Devices, identities and connections across on-premises, multi-cloud, SaaS, edge and IoT/OT in a single view built from real activity, not paperwork.

More threats found, faster

Behavioural detection closes the gaps signature tooling leaves, surfacing attacker activity across domains and inside encrypted traffic as it unfolds.

Dramatically shorter detect-and-respond time

Automated triage and entity-level attack narratives cut mean time to detect and respond, taking incident handling from days to hours.

Higher operations efficiency from the same headcount

Noise and escalation volume fall sharply, freeing a small team to work proactive defence and hunting instead of queue clearance.

Contained before impact

Compromised identities locked down, endpoints isolated and lateral movement interrupted at the firewall, with every action recorded against the incident.

Defensible, audit-ready proof

Exposure reduction, control validation and response performance reported against MITRE ATT&CK and the institution's compliance obligations, in language the board can act on.

Frequently asked

Questions buyers ask before scoping

What does this service actually do?
It gives the institution continuous visibility of everything on its network, detects attacker behaviour that prevention tools let through, investigates it to a full attack narrative, contains it, and then reduces the exposure that made the attack possible. It is a delivered capability with named analysts and reporting, not a licence handover.
Is this a replacement for our firewall, antivirus or SIEM?
No. Prevention tools stop known bad; this service finds the attacker who is already inside and using legitimate credentials. It sits alongside existing controls and feeds them — enforcement still happens at your firewall and identity provider, and findings can be forwarded to an existing SIEM or ticketing system.
What data is analysed?
Network traffic metadata and behaviour, authentication and access activity for human and machine identities, cloud and Microsoft 365 audit events, and device and workload activity across edge and IoT/OT. Analysis is behavioural: we look at how identities and devices act, not at the content of business documents or private messages.
Do you decrypt our traffic?
No. Detection works inside encrypted enterprise traffic without decryption, which avoids the performance cost and the data-protection liability that man-in-the-middle inspection creates.
Where is our data held, and who can see it?
Data residency, retention period and access are fixed in the engagement agreement before deployment, including which of our named analysts hold access and how that access is logged. Nigerian data-protection obligations are treated as a hard requirement, not an optional annex.
What is required from us to deploy?
Traffic aggregation points (span, mirror or tap) at the sites in scope, read-only API access to cloud and identity providers, rack space and power for on-premises sensors, and a named technical owner on the client side. Agents on production endpoints are not required.
Will it disrupt operations?
Sensors are out-of-band and passive, so monitoring does not sit in the path of production traffic. The only changes that touch live systems are the containment actions and control tightening you authorise, which are scheduled with the system owners.
How long does deployment take?
Typically two weeks to first detections for a single-site estate and four to six weeks for a multi-site or multi-cloud estate: one week for scoping and access, one to two weeks for sensor deployment and connector authorisation, then two to four weeks of baselining before the estate picture and first exposure report are issued.
When do we start seeing value?
Asset and identity discovery produces findings in the first days, usually including systems absent from the official register. Detection quality improves through the baseline period as environment-specific benign behaviour is suppressed. Exposure trend reporting becomes meaningful from the second monthly cycle.
Who runs it day to day?
Either model works. We can run monitoring, triage and response as a managed service, or stand the capability up inside your team with analyst and operator training and a handover schedule. Most institutions start managed and transition over the first year.
How do you report to us?
Incidents are reported to the accountable officer as they are handled, with a post-incident review for anything containment touched. A monthly cycle covers exposure reduction, detection trends and response performance mapped to MITRE ATT&CK and your compliance obligations, with a board-level summary.
How is the engagement scoped and priced?
Scope is written against sites, network throughput, cloud tenants and identity count, with the service level and reporting cadence stated. Commercial terms are issued directly to the requesting institution through the client portal — nothing is published here.