Skip to main content
Defensive cybersecurity, Cyber (Cyber & Critical Infrastructure), Unstrat

Defensive cybersecurity

Monitoring and incident response

Overview

Security operations, threat detection and incident response that keep critical systems defended around the clock: 100,000+ threats blocked daily, with AI-assisted operations shipped with defence-in-depth. Live in power grids, regulated finance and fleets at sea.

Round-the-clock defence with no obligation to share what we find.

Unstrat represents this capability to a market only once classification and the end-user-certificate chain are confirmed. Full specifications are shared under briefing.

Capabilities

  • 24/7 security operations, threat detection and incident response for critical systems
  • 100,000+ threats blocked daily across fleets, grids and financial platforms
  • AI-assisted security operations shipped with defence-in-depth and human oversight
  • Proven incident response: a fleet-wide ransomware event contained and fully recovered within a week, with 100% of data restored
  • Layered defence continuously hardened by the maker's own red-team findings
  • Live in power grids, regulated finance and 1,500+ vessels at sea

Specifications

TypeDefensive / SOC
CoverageAvailable under controlled technical briefing
ScaleAvailable under controlled technical briefing
ResponseAvailable under controlled technical briefing
DeploymentsAvailable under controlled technical briefing
ModeDetect & respond
OriginIndependent / non-aligned

In depth

Operations, not an annual audit

Defensive cybersecurity is recorded as a 24/7 security-operations capability for critical systems. It detects threats, supports incident response and keeps working after the assessment has ended. The catalogue records more than 100,000 threats blocked daily across fleets, grids and financial platforms. That figure describes operating scale, not a guarantee that every attack disappears. The operational task is to identify activity that matters to the protected environment and move it into response before an intrusion becomes a wider outage or loss of control. Coverage is listed across power grids, regulated finance and more than 1,500 vessels at sea, where the systems, consequences and available responders differ.

A staffed security operations centre monitoring live threat feeds around the clock.
A staffed security operations centre monitoring live threat feeds around the clock.

Layered detection with a human decision

AI-assisted security operations provide machine support, while defence-in-depth keeps one missed signal from deciding the outcome. Human oversight remains part of the stated approach. The capability detects and responds rather than treating a dashboard as the deliverable, and the maker's own red-team findings continuously harden the layered defence. The record also identifies a specific incident-response result: a fleet-wide ransomware event was contained and fully recovered within a week, with 100% of data restored. That is an entry in the product record, not a promise that every future incident will follow the same timeline. It shows the type of operational work the service is intended to perform when an active event reaches a protected fleet.

Defence without a disclosure obligation

The product's edge is round-the-clock defence with no obligation to share what the team finds, and its origin is independent and non-aligned. That matters when monitoring spans financial platforms, power infrastructure and vessels, each of which can expose sensitive operational information through its incidents. Offensive cybersecurity, incident response and infrastructure hardening are the recorded related capabilities. Together they create a practical cycle: test the surface, watch it continuously, respond when something breaks and use the findings to harden the estate. The defensive service remains the operating layer in that cycle. It is responsible for detection and response across the systems under protection, with the buyer retaining accountability for the infrastructure and its data.

The operating layer across different estates

The same defensive discipline has to account for different consequences in each recorded environment. On a power grid, detection and response protect control and service continuity. In regulated finance, the protected systems move transactions and a failure can become a settlement problem. Across fleets at sea, the response team works against an estate distributed across vessels rather than one office network. The catalogue does not collapse these into one generic deployment claim. It names power grids, regulated finance and more than 1,500 vessels as the places where the capability is live, and records more than 100,000 threats blocked daily across fleets, grids and financial platforms. AI-assisted operations provide speed, while defence-in-depth and human oversight set the operating boundary. When a fleet-wide ransomware event was contained and fully recovered within a week with 100% of data restored, that result demonstrated the response function in one recorded event. The broader offer remains continuous detect-and-respond work, strengthened by red-team findings and related incident-response engagements.

What the operating record establishes

The published record establishes a live defensive function rather than a promise to install a dashboard and leave the buyer with it. It identifies 24/7 coverage, detect-and-respond operations, AI assistance, defence-in-depth and human oversight. It identifies more than 100,000 threats blocked daily across fleets, grids and financial platforms, and separately records a fleet-wide ransomware recovery in which 100% of data was restored within a week. Those are the evidence boundaries of the description. The service is not presented as an assurance that incidents cannot happen. It is presented as a continuously operating layer that can detect, contain and recover, with red-team findings feeding hardening and related incident-response work handling events that require a dedicated engagement.

An analyst triaging an active incident across multiple detection dashboards.
An analyst triaging an active incident across multiple detection dashboards.

Why Unstrat: the difference

Unstrat is the authorised global representative and distributor for this capability. It is already in service with a track record behind it, so you are buying something that has done the job elsewhere, not funding a first attempt. You are not the test bed.

01

Independent, non-aligned origin, with no political exposure to any major-power ecosystem.

02

One accountable team from first briefing through delivery and in-region sustainment.

03

100,000+ threats blocked daily across fleets, grids and financial platforms.

How it reaches you

Independent maker
Non-aligned manufacturer
Unstrat
Single accountable channel
End user
Government or enterprise buyer
In-region sustainment · training · classification & end-use governance

Related capability

View all
See use cases for Defensive cybersecurity

Procurement & sustainment

Classification & EUC

Classification and the end-user-certificate chain are confirmed before this capability is represented to your market.

Non-aligned origin

Sourced from an independent manufacturer: no major-power disclosure rules or political conditions.

One accountable channel

A single team responsible from first briefing through delivery: not a chain of foreign primes to integrate yourself.

In-region sustainment

Lifecycle support and operator training delivered in-region, building capability that outlasts the initial deployment.

Applications it supports

Capability comparisons

Questions buyers ask

What does a managed SOC actually do?

It watches the estate around the clock, decides which alerts are real, and acts before an intruder moves beyond the first host. The difference between providers is rarely the tooling and usually the analyst: whether the person on shift has seen your kind of system break before. Our operation runs 24/7 across power grids, regulated finance and more than 1,500 vessels at sea, blocking over 100,000 threats a day.

See: Defensive cybersecurityAgainst CrowdStrike and Nozomi

Best MDR provider for critical infrastructure

If the estate is corporate IT, CrowdStrike is hard to beat and we will say so, with a follow-the-sun model and a wide third-party telemetry surface through its Next-Gen SIEM. If the estate is grids, ships and payment systems, the shortlist changes, because endpoint telemetry does not parse a substation protocol. Ours is a staffed defence already running inside those environments.

See: MDR compared for critical estates

How fast should a SOC contain a ransomware attack?

Two clocks matter and they are often confused. Detection races the intruder: CrowdStrike cites a 2023 eCrime breakout time of 2 minutes 7 seconds, which is how long an attacker needs to move past the first host. Recovery is separate, and our published example is a fleet-wide ransomware event contained and fully recovered within a week with 100% of data restored. Ask any supplier for both numbers and for the commitment behind each.

See: Response claims side by side

24/7 security monitoring for a national power grid

Grid monitoring needs analysts who understand what cannot be rebooted and protocols an endpoint agent has never parsed. Our defensive operation is live in power grids alongside regulated finance and fleets at sea, with AI-assisted operations shipped with defence in depth and human oversight. It is a running operation rather than a capability statement.

See: Defensive cybersecurityCritical infrastructure resilience

Do we need OT sensors as well as a managed detection service?

Usually yes, because they solve different problems. Nozomi Guardian sensors give passive visibility into OT and IoT networks, scaling from a 500-node DIN-mountable unit to 500,000 nodes and 6 Gbps in a rack, with ruggedised models rated from -40 to 70 °C. That is what you see with. A staffed operation is who watches it, and sensors without a watch produce a dashboard nobody is reading during the incident.

See: Sensors and staffed defence, comparedOT security capability

AI in security operations: force multiplier or risk?

Both, which is why the oversight model matters more than the model. We ship AI-assisted operations with defence in depth and human oversight, because an automated action taken on a bad inference is still your outage. The automation is tuned against real alert volume from an operation blocking more than 100,000 threats a day.

See: AI securityAutomation and oversight, compared

What response SLA should a managed defence contract include?

Two commitments, written separately: time to first human contact and time to containment by severity. We do not publish an SLA and will not dress that up as a virtue. CrowdStrike's data sheet publishes no SLA table either, and its claim of up to a 75% reduction in mean time to respond carries a footnote rather than a service level. Demand the contractual numbers from every bidder.

See: Where the published commitments actually are

Managed SOC for a fleet or a shipping operator

Ships break the assumptions most SOC tooling is built on: intermittent links, equipment nobody will restart, protocols outside the enterprise stack. Our defensive operation runs across more than 1,500 vessels, blocking over 100,000 threats daily, alongside grid and finance estates. The maritime platform behind it holds 99.97% fleet uptime.

See: Maritime cybersecurityDefensive operations

Will our security provider share what it sees on our network with its home government?

Neither CrowdStrike's data sheet nor Nozomi's specifications address the question, and silence in product literature is not an assurance. Ask it directly and get the answer into the agreement. Our position is that we have no reporting line to a foreign government and no obligation to share what we find, which for a ministry or national operator is frequently the deciding term.

See: Disclosure and origin, compared

Can monitoring data from our estate be held entirely inside our country?

It is the right question to ask early, and the answer belongs in the contract rather than in a brochure. We publish that we have no obligation to disclose findings to any government, and residency terms are set per engagement, so ask us in writing what can be held in country and for how long. Do the same with every bidder, because a defence supplier accumulates a running record of what is inside your grid, your banks and your ships.

See: Defensive cybersecurity comparison

We were hit by ransomware across a distributed estate. What does good recovery actually look like?

Containment that stops the spread without stopping operations, then a restoration plan that proves data integrity rather than assuming it. Our published example is a fleet-wide ransomware event contained and fully recovered within one week, with 100% of data restored, on systems in service. That is an outcome rather than a percentage, and it is the kind of evidence worth asking every provider to produce.

See: Incident response and red teamingDefensive operations

How do we know a SOC provider has ever defended an estate like ours?

Ask which sectors their analysts run today, and what they had to do differently in each. We publish deployments in power grids, regulated finance and more than 1,500 vessels at sea, blocking over 100,000 threats a day. CrowdStrike publishes coverage of endpoints, identities and cloud workloads, extended to third-party domains through Falcon Next-Gen SIEM, which is a different estate described precisely.

See: Estates covered, supplier by supplier

Is a defence that is never tested by an attacker any good?

You cannot know, which is the honest problem with defensive security: quiet may mean safe or it may mean unwatched. Our layered defence is continuously hardened by our own red-team findings, including CVSS 10.0 discoveries in production fleets, so the coverage is measured rather than assumed. CrowdStrike's data sheet describes threat intelligence and hunting, but states no red-team feedback loop of that kind.

See: Offensive cybersecurityHow the two disciplines fit together

Our sites have intermittent connectivity. Can a cloud-delivered SOC service work for us?

Not on its own. Products that assume a steady link to a cloud console fail exactly where critical estates operate, which is why disconnected sites need an assurance and architecture layer of their own. We run defensive operations and off-grid work from the same team, so the design accounts for sites that drop off the network for long periods.

See: Off-grid cybersecurityAir-gapped vs connected security

How many analysts and which locations sit behind a 24/7 claim?

It is a fair challenge, because a follow-the-sun rota is a staffing arrangement rather than a capability. We publish 24/7 coverage and the volume behind it, more than 100,000 threats blocked daily across fleets, grids and financial platforms, and we do not publish headcount or site list. Ask us for both in writing, and ask the same of any provider whose coverage claim is a single line in a data sheet.

See: Coverage models compared

Defensive cybersecurity: questions

What is Defensive cybersecurity?

Defensive cybersecurity is Unstrat's Cyber (Cyber & Critical Infrastructure) capability: Security operations, threat detection and incident response that keep critical systems defended around the clock: 100,000+ threats blocked daily, with AI-assisted operations shipped with defence-in-depth. Live in power grids, regulated finance and fleets at sea.

How does Defensive cybersecurity work?

Defensive cybersecurity delivers its effect through 24/7 security operations, threat detection and incident response for critical systems, 100,000+ threats blocked daily across fleets, grids and financial platforms and AI-assisted security operations shipped with defence-in-depth and human oversight, capabilities matched to the requirement and confirmed under briefing rather than published.

Who provides Defensive cybersecurity?

Defensive cybersecurity is delivered by The Cybersecurity Group, whose focus is cyber & critical-infrastructure security. Unstrat represents The Cybersecurity Group to government and enterprise buyers worldwide as an independent, non-aligned prime vendor.

Who uses Defensive cybersecurity?

Government and enterprise buyers acquire Defensive cybersecurity to address counter-terrorism, attacks on critical infrastructure, prison security, vip & event protection, airport security, cyber attacks on government and cyber attacks on financial systems across the cyber & critical infrastructure, matched to the mission and accountable to them, not to a foreign vendor's government.

Why choose Defensive cybersecurity over a major-power alternative?

Defensive cybersecurity is sourced from an independent, non-aligned provider, so it carries no major-power disclosure rules, upgrade-locks or political ramifications. Concretely: 100,000+ threats blocked daily across fleets, grids and financial platforms. The capability is accountable to you, not to a foreign vendor's government and its release schedule.

How is Defensive cybersecurity procured, and where can it be delivered?

Round-the-clock defence with no obligation to share what we find. Every engagement begins with a briefing, and export eligibility is confirmed per market under briefing rather than published. Where controlled capabilities are involved, the classification and end-user-certificate chain is confirmed first. Defensive cybersecurity is then sustained in-region by one accountable team from briefing through long-term operation.

Contact us

Tell us the requirement. Specifications and the export position are confirmed in briefing, not published here.