Cyber Security

Cyber Security Products and Implementation Services

ONGSEC addresses corporate cyber security needs end to end. This section details, by product family, which security technologies we can deploy, integrate and operate. Under every heading we provide not only product installation bu…

EDR / XDRNGFW / WAFPAM / IGADLPE-mail securityCloud security
01

Endpoint Security

  • Endpoint Detection & Response (EDR) deployment, policy design and detection rule tuning
  • Endpoint Protection Platform (EPP) / antivirus migration and central management
  • Extended detection and response (XDR) architecture and data source integration
  • Applying server and workstation hardening templates
  • Application allow-listing and execution control
  • Disk encryption (BitLocker, LUKS) and central key management
  • Mobile device and endpoint management (MDM / UEM), corporate profiles and remote wipe
  • Removable media control and USB policy management
  • Ransomware-specific protection layers and rollback capabilities
  • Principal solutions used: SentinelOne, Palo Alto Cortex, Microsoft Defender, ESET, SOTI
02

Network, Perimeter and E-mail Security

  • Next-generation firewall (NGFW) design, deployment, migration and rule optimisation
  • Web application firewall (WAF) deployment, signature and learning mode management
  • API security: discovery, schema validation, rate limiting and abuse detection
  • DDoS protection solutions and carrier-level scrubbing integration
  • DNS security and malicious domain blocking
  • Secure web gateway (SWG) and URL filtering
  • E-mail security: phishing protection, sandbox analysis, SPF/DKIM/DMARC implementation
  • Anomaly detection in encrypted traffic with network detection and response (NDR)
  • Secure browser and isolated desktop solutions
  • Principal solutions used: Fortinet, Cisco, Check Point, Palo Alto, WatchGuard, SonicWall, Huawei, Wallarm, HYAS, Surf
03

Identity and Access Management

Most attacks begin not with exploitation of a vulnerability but with valid credentials. The identity layer is therefore placed at the centre of the security architecture.

  • Privileged access management (PAM): vaulting, session recording, just-in-time privilege and password rotation
  • Identity governance and administration (IGA): role-based access, entitlement review campaigns
  • Multi-factor authentication (MFA) rollout and exception management
  • Single sign-on (SSO), SAML/OIDC federation and application integrations
  • Enterprise PKI deployment, certificate lifecycle and code signing infrastructure
  • Inventorying and bringing service accounts and machine identities under control
  • Active Directory security assessment and attack path analysis
  • Principal solutions used: Delinea, Segura
04

Data Security and Leakage Prevention

  • Data discovery and classification: mapping structured and unstructured data
  • Labelling policy design and rollout on the user side
  • Data loss prevention (DLP): policy deployment across endpoint, network and e-mail channels
  • False positive tuning and phased enforcement (monitor → warn → block)
  • Encryption and data masking solutions, key management
  • Database activity monitoring (DAM) and sensitive query auditing
  • File-level persistent protection with digital rights management (DRM)
  • Secure file transfer and control of sharing channels with external parties
  • Principal solutions used: Safetica, GTB Technologies, Geodi
05

Cloud Security

  • Misconfiguration detection with cloud security posture management (CSPM)
  • Cloud workload protection (CWPP) and virtual machine/container security
  • Cloud access security broker (CASB) and shadow IT visibility
  • Transition planning to SASE / ZTNA architecture
  • Identity and entitlement management (CIEM), excessive privilege detection
  • Integration of cloud log sources into the SIEM
  • Consistent policy management across multi-cloud and hybrid environments
06

Application and Software Supply Chain Security

  • Establishing a secure software development lifecycle (SSDLC) and threat modelling
  • Integrating static code analysis (SAST) and dynamic application testing (DAST) into CI/CD
  • Software composition analysis (SCA) and open source library risk management
  • Software bill of materials (SBOM) generation and version-level tracking
  • Secret scanning in code repositories and leakage prevention
  • Container image security, registry scanning and signing
  • Build pipeline security and detection of unauthorised change
  • Security assessment of supplier and subcontractor software
07

Threat Intelligence and Brand Protection

  • Collection, enrichment and prioritisation of cyber threat intelligence (CTI) feeds
  • Dark web and underground forum monitoring: detection of leaked credentials and corporate data
  • Mapping the corporate digital footprint through open source intelligence (OSINT)
  • Brand protection: detection of look-alike domains, fake mobile apps and social media accounts
  • Managing takedown processes for malicious content and fraudulent sites
  • Sector- and organisation-specific threat actor profiling and reporting
  • Automatic feeding of intelligence output into SIEM and security devices
08

Vulnerability and Configuration Management

  • Establishing continuous vulnerability scanning infrastructure and defining asset scope
  • Prioritising vulnerabilities by business impact and exploitability
  • Integration with the patch management process and closure tracking
  • Applying a secure configuration baseline (CIS Benchmark) and drift monitoring
  • Continuous monitoring of the external attack surface and detection of newly exposed services
  • Reporting vulnerability metrics (mean time to close, ageing) to management
09

Zero Trust Architecture

Implicit trust based on network location is removed; every request is re-evaluated against identity, device posture and context.

  • Identity-centric access policy design
  • Device posture checks and quarantine for non-compliant devices
  • Micro-segmentation and restriction of east-west traffic
  • ZTNA for application-level access instead of VPN
  • Continuous verification and session risk scoring
  • Phased migration plan: pilot scope, measurement, rollout
10

Privileged Access Management (PAM)

Administrator accounts are the attacker’s first target. Privileged sessions are vaulted, recorded and granted for a limited time.

  • Privileged account inventory and ownership assignment
  • Password vault, automatic rotation and removal of shared accounts
  • Session recording, monitoring and termination when required
  • Just-in-time, time-bound elevation
  • Vaulting of service and application account secrets
  • Approval workflow and audit trail for privileged operations
11

WAF, API and Bot Security

Internet-facing applications and API endpoints are protected with signature, behaviour and rate-limiting layers together.

  • Web application firewall deployment and rule tuning
  • API discovery, schema validation and authorisation checks
  • Rate limiting, bot management and credential-stuffing prevention
  • False-positive reduction and rollout in learning mode
  • API gateway authentication and quota management
  • Verification against the OWASP API Top 10
12

DDoS Protection and Mitigation

Multi-layered mitigation for volumetric, protocol and application-layer attacks — designed before the incident, not during it.

  • Traffic profiling and a baseline of normal behaviour
  • Integration with carrier or cloud scrubbing services
  • On-premise protocol and rate-based filtering
  • Load distribution with anycast and CDN
  • Attack-time runbook and carrier escalation chain
  • Annual attack exercise and capacity validation
13

Container, Kubernetes and DevSecOps Security

Security is placed inside the build pipeline; image, cluster and runtime are each assessed separately.

  • Image scanning, signing and trusted registry policy
  • Kubernetes configuration review and CIS Benchmark compliance
  • Network policy, service account and secret management
  • Runtime behaviour monitoring and anomaly detection
  • SAST, SCA and IaC scanning in the CI/CD pipeline
  • Policy gates that stop risky builds from being deployed
14

Mobile Device and Endpoint Management (MDM / UEM)

Corporate data reaches personal devices too. Device management, app separation and remote wipe bring it under control.

  • MDM / UEM deployment and enrolment flow
  • Separation of corporate and personal data through containers
  • Application allow-listing and minimum OS version enforcement
  • Remote lock, wipe and lost-device procedure
  • Conditional access that blocks non-compliant devices
  • Mobile threat defence (MTD) integration
15

Deception Technology

Decoy assets seeded across the network catch a laterally moving attacker early and with very few false positives.

  • Placement of decoy servers, shares and honeytokens
  • A deception layer designed to resemble the production estate
  • High-confidence alert integration with SIEM and SOAR
  • Recording attacker behaviour and turning it into intelligence
  • Periodic decoy refresh and scope expansion

Get started

Let us talk about your project.

The first meeting is a discovery session, not a sales pitch. You are also welcome to evaluate our capability directly through a short pilot or proof of concept (PoC) in your own environment.

Fill in the enquiry form

WhatsApp