Secuwall
Defensive Security

Incident Response

When it happens, you don’t start from zero.

24/7 hotline · NDA before any technical detail · You don’t have to be a client already

Positioning

Most breaches aren’t missed for lack of tools. They’re missed because the log that would have shown them was never sent.

A broken security telemetry pipe revealing a missing event before it reaches monitoring

You bought the firewall. You bought the EDR. You bought the IPS.

Then an incident happens, and what’s missing isn’t analysis — it’s data. A sensor that’s switched on but not recording the event class that matters. Logs that stop at the appliance. A source that went quiet six months ago and nobody noticed. Or logs that arrive carrying nothing to say which system they came from.

So we work in this order: clear the log pipes, monitor 24/7 on an AI-integrated platform, respond when it happens. Skip the first and the other two are theatre.

24/7 SOC monitoring

Round-the-clock monitoring. The AI reads first. A human decides.

Aletheia is our own SOC platform. Everything from your estate is normalised into one schema, then run through three detection layers that overlap on purpose: baseline rules, real-time behavioural correlation, and threat hunting. Miss a technique at one layer and two more are still in front of it.

Two synchronized SOC centres feeding an AI-assisted detection core

Every alert gets triaged — every one, not every batch

An AI agent reads each alert against its context: that user, that host, what happened either side of it. It comes back with a verdict, its reasoning, and a confidence level. It does this at 03:00 as readily as at 15:00, and it doesn’t depend on whether the shift had time to look.

Analysts make the call

The AI proposes. It does not act. The platform will not isolate a host, disable an account or block an address on its own. A human closes every case, and that verdict feeds back: noisy rules get down-weighted or muted, good conclusions get remembered and reused. The platform gets quieter the longer you run it.

The AI runs on your hardware. Your logs stay home.

The models run on GPUs on site. No public AI service is called. If you’re a bank, an insurer, a telco, or anyone with data residency obligations, that’s a precondition — not a premium tier.

We’ll tell you what we can’t see

Counting rules isn’t measuring coverage. A rule that matches nothing looks exactly like a clean estate. Our platform separates wired — the platform would run it — from proven to fire — something repeatable shows that it does. You get both numbers, and the list of what’s still a blind spot.

Incident Response

When it happens, you don’t start from zero.

Our responders work on the same platform already watching your estate. The case opens with the timeline, the IOCs, the affected hosts and accounts, and the investigation tasks already in it. No scramble to pull logs out of six teams first.

Not a monitoring client? We still take the call. The first job then is standing up emergency collection, so there’s something to investigate.

Incident timeline reconstruction and controlled containment
What to expect
On contactWe pick up and steady the situation.

One technical lead is assigned to you. NDA signed. We tell you what to do now — and what not to do, so the evidence survives.

Stage 1We classify it and draw the first boundary.

Ransomware, BEC, data theft, insider misuse. Which systems are in scope.

Stage 2We reconstruct the timeline.

How they got in. How they moved. What they touched. Whether data left.

Stage 3We contain it.

You approve the containment plan before we run it. We don’t cut production systems on our own authority.

CloseWe report and hand over.

Findings, prioritised remediation, and new detections deployed into monitoring so the next attempt surfaces sooner.

Incident report, attack timeline, and verified remediation deliverables
What you’ll receive

An incident report your board can read. What happened, how far it went, what evidence backs that. Technical detail goes in the appendix, not the summary.

The attack timeline and the IOC list. Ready to sweep the rest of your estate, and ready to hand to a partner or a regulator if it comes to that.

A prioritised remediation plan including the new detections already live in monitoring, so you can show the gap is closed, not just logged.

Six incident types connected to a central response hub
Incident types we handle

Ransomware

data encrypted, usually with a threat to leak it.

Business email compromise (BEC)

a mailbox taken over to redirect payments or read quietly.

Data breach

customer or internal data taken out of the estate.

Web application compromise

a vulnerability exploited to plant a backdoor.

Insider risk

legitimate access used for something it wasn’t granted for.

Third-party breach

a supplier is compromised and it reaches you.

Targeted intrusions and APT

The alert is not the intrusion. It’s the first thing that happened to be visible — and it’s late.

A targeted intruder is found late by definition. So the investigation runs backwards toward the entry path, not outward from the alert: how long, how far, how they got in.

Targeted intrusion path reconstructed backwards from a visible alert

Months of history, queryable.

Every hunt re-runs across retained data — which is how an exfiltration spread thinly over a fortnight gets found at all.

Related alerts become one case.

Alerts sharing an entity fold into a single campaign instead of forty tickets that each look minor.

Every case opens with its neighbourhood.

One hop of the entity graph comes attached, so lateral movement is visible rather than reconstructed.

Severity follows the asset.

Malware on a payment host means segmentation, jump host and application auth were already crossed. The case says which — and that says where to look next.

AI-assisted investigation preparing evidence for a human-controlled verdict
What the AI does in an investigation

It performs the steps an analyst repeats identically every time:

  • pulls the context around the alert — that user, that host, either side of it
  • expands entities one hop and attaches the neighbourhood
  • enriches every indicator against reputation and intelligence
  • drafts the timeline, the IOC list and the affected assets into the case
  • seeds the standard investigative tasks, so the process holds at 4am
  • proposes a verdict with its reasoning and a confidence level

An analyst decides. The AI does not contain, isolate, disable or block.

Every step it took is recorded in order and can be replayed — you audit its work, not just its conclusion.

One defensive response platform connected to cloud, containers, on-premise systems, and an OT boundary
Where we respond

Cloud & SaaS

Control-plane and audit trails normalised like any endpoint log, so a cloud step and a host step land on one timeline.

Containers & Kubernetes

Cluster audit, workload events, runtime security, and the virtualisation layer under them. A pod that is gone cannot be imaged — which is why collection is continuous, not reactive.

On-premise

Windows, Linux, macOS, firewalls, proxies, VPN, directory, network sensors. No central logging? We collect with the free forensic toolkit and replay it into the same pipeline.

OT, ICS & IoT

See below — the limits matter more than the claim.

OT, ICS and IoT. We work where OT incidents are actually investigated: the IT side of the boundary — engineering workstations, HMIs, historians, jump hosts. We do not install agents on PLCs or RTUs, and we do not touch controllers on a running process. OT assets are recognised by host naming and vendor stack and weighted at the top of the criticality scale, with the controls an alert there implies were already crossed: the IT/OT boundary, the DMZ historian relay, engineering-workstation access.

What we don’t claim: ICS protocol content — Modbus, DNP3, S7comm, IEC-104 — is not parsed into detections. ICS network visibility reaches us through the IDS feed; safety-instrumented systems are out of scope.

Deployment

On-premise, on-cloud, or split. Same platform, different address.

The platform runs entirely inside your infrastructure, on infrastructure we operate, or across both. This doesn’t change what gets detected. It changes where the trust boundary sits — and that’s your call, not your vendor’s.

On-premise, cloud, and hybrid deployment models with explicit trust boundaries

On-premise

Entirely inside your infrastructure

Data residency obligations. Isolated networks. You already have an infrastructure team.

SOC-as-a-service (on-cloud)

Infrastructure we run, separated per client

You want a SOC quickly and don’t want to run a platform or staff a 24/7 rota.

Hybrid

Collected and normalised on site, analysed centrally

Sensitive data has to stay put, but you still want an outside monitoring team.

One thing holds across all three: the AI runs on local GPUs, and your logs are never sent to a public AI service. For fully isolated networks, the platform can demonstrate continuously that it has no route to the internet — evidence you can hand an auditor.

We operate from Vietnam and the UAE. So a data residency conversation in Southeast Asia or the Gulf starts with a team already in the region, not one flying in.

Log Plumber

Before you buy anything else, find out whether what you already own is talking.

We call it plumbing for security data. We walk the path from sensor to storage and find the blockages, the leaks, and the pipes pointing the wrong way.

It’s usually the cheapest line in a security budget. It’s also the difference between having a SOC and having a SOC that works.

Security telemetry pipelines exposing blind spots before repair

Part 1: Log Coverage Audit

We compare three things: the sources you think you collect, the sources actually arriving, and the sources you need to catch the techniques that matter, mapped to MITRE ATT&CK.

Those three sets almost never agree.

You get a coverage map by ATT&CK technique, a list of silent sources with the date each went quiet, blind spots ranked by risk, and a plan to close them in order.

Part 2: Sensor Hardening

Security products ship configured not to bother anyone. They log little, keep it briefly, and leave the forensically expensive event classes switched off. We reconfigure them to say something usable:

  • Endpoint security / EDR — turn on the process, command line, module load and file access events an investigation actually needs.
  • Firewall / IPS / IDS — log what’s allowed as well as what’s blocked, with enough fields to follow a session end to end.
  • NSM — put the sensor where the traffic really is, and capture session metadata and DNS rather than packet counts.
  • Servers, applications, cloud — enable audit logging, record command history, keep access logs at a level an investigation can use.

Two things go with this that almost nobody does. We load test it, so switching on more logging doesn’t take down the appliance producing it. And we verify it by attack simulation — we generate the attacker behaviour ourselves and confirm it shows up in your logs.

Correct on paper but silent under attack is still a blind spot.

Part 3: Open source vs commercial, against your budget

We don’t resell licences, so we have no reason to push you toward the expensive answer.

We sort your stack on one principle: open source where the real cost is people and you keep control; commercial where you’re buying response time, proprietary intelligence, or somebody else’s liability.

You get a layer-by-layer comparison with three-year TCO — staff included, not just licence price — a phased migration path, and a straight list of where open source is the wrong answer, with reasons.

What makes us different

Two centres, two countries

Our analysts work from Ho Chi Minh City and Dubai, both on a 24/7 rota. Two power grids, two internet paths, two public holiday calendars. When one centre goes dark, the other is already watching.

The AI runs inside your estate

None of your logs go to a public AI service. If you’re under data residency rules, that’s the difference between workable and not — not a feature to compare on a grid.

A human signs the verdict

The AI does the heavy, repetitive work. An analyst reaches the conclusion and owns it. We don’t sell automated response, because a wrong action on a production system usually costs more than the incident that triggered it.

We can measure what we detect

We separate rules that are wired from rules that are proven to fire. Every reporting cycle you get both numbers and the list of what’s still a blind spot. A coverage figure nobody can check isn’t a coverage figure.

In an incident, or trying to avoid one?

In one. Call the hotline. We take the call first and do the paperwork after.

Not in one. Start with a log coverage assessment. Fixed scope, fixed duration. The findings will tell you what to do next — including when the answer is “you don’t need a managed SOC yet”.

Book a log coverage assessment