Delivered as a managed service from our Kuwait City operations centre, or co-managed alongside your internal team. Every engagement includes onboarding, detection engineering and quarterly efficacy review.
DETECTAI Threat Detection (XDR)
Cross-domain correlation over endpoint, network, identity and cloud telemetry with LLM-assisted triage on every alert.
- ✓Behavioural baselining per asset class
- ✓Claude-generated alert narratives
- ✓Detection-as-code, version controlled
0.31% false-positive rate
DETECT24/7 SOC Monitoring
Three shifts of tier-1 to tier-3 analysts operating from our Kuwait City floor, with named escalation contacts.
- ✓Follow-the-sun analyst rotation
- ✓Named escalation path per client
- ✓Monthly efficacy review
MTTA 47 seconds
RESPONDIncident Response
Retained DFIR capability: containment, forensic imaging, root-cause analysis and regulator-ready reporting.
- ✓Memory and disk forensics
- ✓Ransomware negotiation advisory
- ✓Post-incident hardening plan
15-min retainer triage SLA
TESTPenetration Testing
Manual, scoped testing of external perimeter, internal networks, web and mobile applications and APIs.
- ✓OWASP ASVS and MASVS coverage
- ✓Retest included within 90 days
- ✓Developer remediation workshops
CREST-aligned methodology
TESTRed Teaming
Objective-based adversary emulation against your live estate, measured against your own detection stack.
- ✓Custom C2 infrastructure
- ✓Physical and social vectors on request
- ✓Purple-team replay session
12 detection gaps found / engagement
DETECTCloud Security Posture
Continuous misconfiguration and drift detection across AWS, Azure, GCP and Kubernetes estates.
- ✓IaC scanning in CI
- ✓Attack-path graph analysis
- ✓CIS benchmark reporting
1,240+ policy checks
DETECTIdentity & Access (ZTNA)
Zero-trust access brokerage, privilege analytics and continuous session risk scoring for workforce and third parties.
- ✓Standing-privilege elimination
- ✓Just-in-time elevation workflows
- ✓Third-party access governance
98.6% MFA coverage achieved
GOVERNCompliance & Audit
Readiness and evidence automation for ISO 27001, SOC 2, GDPR and Kuwait CITRA data-protection requirements.
- ✓Gap assessment and control design
- ✓Evidence collection automation
- ✓Auditor liaison and sampling support
Avg 11 weeks to certification
GOVERNSecurity Awareness Training
Role-based training with continuous phishing simulation and per-department risk scoring.
- ✓Arabic and English delivery
- ✓Executive-specific whaling drills
- ✓Manager dashboards
Click rate 22% → 3.1% in 6 months
GOVERNVulnerability Management
Discovery, exploitability-weighted prioritisation and remediation tracking across the full asset inventory.
- ✓Authenticated and agent-based scanning
- ✓SLA tracking per asset owner
- ✓Patch-window orchestration
EPSS + KEV weighted scoring
DETECTDark Web Monitoring
Credential, brand and data-leak collection across criminal forums, paste sites and initial-access broker listings.
- ✓Executive exposure monitoring
- ✓Broker listing early warning
- ✓Takedown coordination
3.4 M leaked credentials matched
DETECTOT / ICS Security
Passive monitoring for industrial and energy environments with Purdue-model segmentation review.
- ✓Modbus / DNP3 / S7 protocol parsing
- ✓Safety-instrumented system review
- ✓IEC 62443 alignment
Zero-impact passive taps