Cyber Security
Cyber Security Products and Implementation Services
ONGSEC addresses corporate cyber security needs end to end. This section details, by product family, which security technologies we can deploy, integrate and operate. Under every heading we provide not only product installation bu…
Scope of service
What we do under this heading
Endpoint Security
Endpoint Detection & Response (EDR) deployment, policy design and detection rule tuning; Endpoint Protection Platform …
VIEWNetwork, Perimeter and E-mail Security
Next-generation firewall (NGFW) design, deployment, migration and rule optimisation; Web application firewall (WAF) de…
VIEWIdentity and Access Management
Most attacks begin not with exploitation of a vulnerability but with valid credentials. The identity layer is therefor…
VIEWData Security and Leakage Prevention
Data discovery and classification: mapping structured and unstructured data; Labelling policy design and rollout on th…
VIEWCloud Security
Misconfiguration detection with cloud security posture management (CSPM); Cloud workload protection (CWPP) and virtual…
VIEWApplication and Software Supply Chain Security
Establishing a secure software development lifecycle (SSDLC) and threat modelling; Integrating static code analysis (S…
VIEWThreat Intelligence and Brand Protection
Collection, enrichment and prioritisation of cyber threat intelligence (CTI) feeds; Dark web and underground forum mon…
VIEWVulnerability and Configuration Management
Establishing continuous vulnerability scanning infrastructure and defining asset scope; Prioritising vulnerabilities b…
VIEWEndpoint Security
- Endpoint Detection & Response (EDR) deployment, policy design and detection rule tuning
- Endpoint Protection Platform (EPP) / antivirus migration and central management
- Extended detection and response (XDR) architecture and data source integration
- Applying server and workstation hardening templates
- Application allow-listing and execution control
- Disk encryption (BitLocker, LUKS) and central key management
- Mobile device and endpoint management (MDM / UEM), corporate profiles and remote wipe
- Removable media control and USB policy management
- Ransomware-specific protection layers and rollback capabilities
- Principal solutions used: SentinelOne, Palo Alto Cortex, Microsoft Defender, ESET, SOTI
Network, Perimeter and E-mail Security
- Next-generation firewall (NGFW) design, deployment, migration and rule optimisation
- Web application firewall (WAF) deployment, signature and learning mode management
- API security: discovery, schema validation, rate limiting and abuse detection
- DDoS protection solutions and carrier-level scrubbing integration
- DNS security and malicious domain blocking
- Secure web gateway (SWG) and URL filtering
- E-mail security: phishing protection, sandbox analysis, SPF/DKIM/DMARC implementation
- Anomaly detection in encrypted traffic with network detection and response (NDR)
- Secure browser and isolated desktop solutions
- Principal solutions used: Fortinet, Cisco, Check Point, Palo Alto, WatchGuard, SonicWall, Huawei, Wallarm, HYAS, Surf
Identity and Access Management
Most attacks begin not with exploitation of a vulnerability but with valid credentials. The identity layer is therefore placed at the centre of the security architecture.
- Privileged access management (PAM): vaulting, session recording, just-in-time privilege and password rotation
- Identity governance and administration (IGA): role-based access, entitlement review campaigns
- Multi-factor authentication (MFA) rollout and exception management
- Single sign-on (SSO), SAML/OIDC federation and application integrations
- Enterprise PKI deployment, certificate lifecycle and code signing infrastructure
- Inventorying and bringing service accounts and machine identities under control
- Active Directory security assessment and attack path analysis
- Principal solutions used: Delinea, Segura
Data Security and Leakage Prevention
- Data discovery and classification: mapping structured and unstructured data
- Labelling policy design and rollout on the user side
- Data loss prevention (DLP): policy deployment across endpoint, network and e-mail channels
- False positive tuning and phased enforcement (monitor → warn → block)
- Encryption and data masking solutions, key management
- Database activity monitoring (DAM) and sensitive query auditing
- File-level persistent protection with digital rights management (DRM)
- Secure file transfer and control of sharing channels with external parties
- Principal solutions used: Safetica, GTB Technologies, Geodi
Cloud Security
- Misconfiguration detection with cloud security posture management (CSPM)
- Cloud workload protection (CWPP) and virtual machine/container security
- Cloud access security broker (CASB) and shadow IT visibility
- Transition planning to SASE / ZTNA architecture
- Identity and entitlement management (CIEM), excessive privilege detection
- Integration of cloud log sources into the SIEM
- Consistent policy management across multi-cloud and hybrid environments
Application and Software Supply Chain Security
- Establishing a secure software development lifecycle (SSDLC) and threat modelling
- Integrating static code analysis (SAST) and dynamic application testing (DAST) into CI/CD
- Software composition analysis (SCA) and open source library risk management
- Software bill of materials (SBOM) generation and version-level tracking
- Secret scanning in code repositories and leakage prevention
- Container image security, registry scanning and signing
- Build pipeline security and detection of unauthorised change
- Security assessment of supplier and subcontractor software
Threat Intelligence and Brand Protection
- Collection, enrichment and prioritisation of cyber threat intelligence (CTI) feeds
- Dark web and underground forum monitoring: detection of leaked credentials and corporate data
- Mapping the corporate digital footprint through open source intelligence (OSINT)
- Brand protection: detection of look-alike domains, fake mobile apps and social media accounts
- Managing takedown processes for malicious content and fraudulent sites
- Sector- and organisation-specific threat actor profiling and reporting
- Automatic feeding of intelligence output into SIEM and security devices
Vulnerability and Configuration Management
- Establishing continuous vulnerability scanning infrastructure and defining asset scope
- Prioritising vulnerabilities by business impact and exploitability
- Integration with the patch management process and closure tracking
- Applying a secure configuration baseline (CIS Benchmark) and drift monitoring
- Continuous monitoring of the external attack surface and detection of newly exposed services
- Reporting vulnerability metrics (mean time to close, ageing) to management
Zero Trust Architecture
Implicit trust based on network location is removed; every request is re-evaluated against identity, device posture and context.
- Identity-centric access policy design
- Device posture checks and quarantine for non-compliant devices
- Micro-segmentation and restriction of east-west traffic
- ZTNA for application-level access instead of VPN
- Continuous verification and session risk scoring
- Phased migration plan: pilot scope, measurement, rollout
Privileged Access Management (PAM)
Administrator accounts are the attacker’s first target. Privileged sessions are vaulted, recorded and granted for a limited time.
- Privileged account inventory and ownership assignment
- Password vault, automatic rotation and removal of shared accounts
- Session recording, monitoring and termination when required
- Just-in-time, time-bound elevation
- Vaulting of service and application account secrets
- Approval workflow and audit trail for privileged operations
WAF, API and Bot Security
Internet-facing applications and API endpoints are protected with signature, behaviour and rate-limiting layers together.
- Web application firewall deployment and rule tuning
- API discovery, schema validation and authorisation checks
- Rate limiting, bot management and credential-stuffing prevention
- False-positive reduction and rollout in learning mode
- API gateway authentication and quota management
- Verification against the OWASP API Top 10
DDoS Protection and Mitigation
Multi-layered mitigation for volumetric, protocol and application-layer attacks — designed before the incident, not during it.
- Traffic profiling and a baseline of normal behaviour
- Integration with carrier or cloud scrubbing services
- On-premise protocol and rate-based filtering
- Load distribution with anycast and CDN
- Attack-time runbook and carrier escalation chain
- Annual attack exercise and capacity validation
Container, Kubernetes and DevSecOps Security
Security is placed inside the build pipeline; image, cluster and runtime are each assessed separately.
- Image scanning, signing and trusted registry policy
- Kubernetes configuration review and CIS Benchmark compliance
- Network policy, service account and secret management
- Runtime behaviour monitoring and anomaly detection
- SAST, SCA and IaC scanning in the CI/CD pipeline
- Policy gates that stop risky builds from being deployed
Mobile Device and Endpoint Management (MDM / UEM)
Corporate data reaches personal devices too. Device management, app separation and remote wipe bring it under control.
- MDM / UEM deployment and enrolment flow
- Separation of corporate and personal data through containers
- Application allow-listing and minimum OS version enforcement
- Remote lock, wipe and lost-device procedure
- Conditional access that blocks non-compliant devices
- Mobile threat defence (MTD) integration
Deception Technology
Decoy assets seeded across the network catch a laterally moving attacker early and with very few false positives.
- Placement of decoy servers, shares and honeytokens
- A deception layer designed to resemble the production estate
- High-confidence alert integration with SIEM and SOAR
- Recording attacker behaviour and turning it into intelligence
- Periodic decoy refresh and scope expansion
On this page
- Endpoint Security
- Network, Perimeter and E-mail Security
- Identity and Access Management
- Data Security and Leakage Prevention
- Cloud Security
- Application and Software Supply Chain Security
- Threat Intelligence and Brand Protection
- Vulnerability and Configuration Management
- Zero Trust Architecture
- Privileged Access Management (PAM)
- WAF, API and Bot Security
- DDoS Protection and Mitigation
- Container, Kubernetes and DevSecOps Security
- Mobile Device and Endpoint Management (MDM / UEM)
- Deception Technology
Typical deliverables
- Requirements analysis
- PoC report
- Architecture design
- Deployment and policy document
- Handover training
Let us define the scope together
A short discovery call is enough to identify the slice of this portfolio you actually need.
Request a quoteRelated services
What usually runs alongside this
Penetration Testing, Red Teaming and Digital Forensics
Methodology-driven penetration testing, red team operations, digital forensics and incident response.
EXPLORE Cyber SecurityOT / ICS and Industrial System Security
Passive visibility, segmentation and IEC 62443 compliance work in industrial control system environments.
EXPLORE Cyber SecurityManaged Security Services (MSSP / SOC)
Managed security services: SIEM deployment and operation, 24/7 monitoring, incident response and automation.
EXPLOREGet started
Let us talk about your project.
The first meeting is a discovery session, not a sales pitch. You are also welcome to evaluate our capability directly through a short pilot or proof of concept (PoC) in your own environment.