Skip to main content

Defensive cybersecurity: use cases

Critical systems have to be watched around the clock, because an adversary does not keep office hours. The Cybersecurity Group runs security operations, threat detection and incident response that block over 100,000 threats a day across fleets, power grids and financial platforms, with AI-assisted operations shipped alongside defence-in-depth and human oversight. The goal is not zero intrusions; it is intrusions that never matter. A managed operation watches the estate around the clock, decides which alerts are real, and acts before an intruder moves beyond the first host, and the difference between providers is rarely the tooling and usually the analyst: whether the person on shift has seen that kind of system break before. This one is live in power grids, regulated finance and more than 1,500 vessels at sea, and it answers to the buyer with no obligation to report what it discovers to anyone else.

Where it is used

01
Analysts who know the estate

For a corporate IT estate the leading endpoint platforms are hard to beat, and this is worth saying plainly. For grids, ships and payment systems the shortlist changes, because endpoint telemetry does not parse a substation protocol and an agent has never seen a maritime control network. Grid monitoring needs analysts who understand what cannot be rebooted and protocols an enterprise stack never modelled; ships break the assumptions most tooling is built on, with intermittent links and equipment nobody will restart. This is a staffed defence already running inside those environments rather than a capability statement, which is the distinction that matters when a real incident starts.

02
Two clocks: detection and recovery

Detection and recovery are separate measures that are often confused. Detection races the intruder, whose breakout time past the first host is measured in a couple of minutes, so the watch has to be fast and continuous. Recovery is a different clock: the published example here is a fleet-wide ransomware event contained and fully recovered within a week with all data restored, on systems in service. That is an outcome rather than a percentage, and the honest ask of any supplier is for both numbers and the commitment behind each, because a fast detector with no recovery plan and a strong restore with slow detection are both incomplete answers.

03
Sensors and the people who watch them

Passive OT sensors and a staffed operation solve different problems and a serious estate usually needs both. Sensors give visibility into control and device networks that endpoint agents cannot see, scaling across a wide range of sites and rated for harsh environments; they are what a defender sees with. A staffed operation is who watches, and sensors without a watch produce a dashboard nobody is reading during the incident. AI assists the operations, but it is shipped with defence in depth and human oversight, because an automated action taken on a bad inference is still an outage, and the automation is tuned against real alert volume rather than a lab feed.

04
Proven incident response

Good recovery is containment that stops the spread without stopping operations, then a restoration plan that proves data integrity rather than assuming it. The published example is a fleet-wide ransomware event contained and fully recovered within one week with all data restored, on running systems, which is the kind of evidence worth asking every provider to produce rather than a headline percentage. The way to know a provider has defended an estate like the buyer's is to ask which sectors its analysts run today and what they had to do differently in each, then weigh that against a precise description of a different estate rather than a claim of universal coverage.

05
Defence hardened by its own red team

The honest problem with defensive security is that a quiet estate may be safe or merely unwatched, and a defence never tested by an attacker cannot be graded. This layered defence is continuously hardened by the maker's own red-team findings, including maximum-severity discoveries in production fleets, so coverage is measured rather than assumed. That feedback loop is not something every provider runs, and its absence is worth noticing. What response commitments a contract carries matters as much: time to first human contact and time to containment by severity, written separately, are the numbers to demand from every bidder rather than accepting a marketing reduction figure with a footnote instead of a service level.

06
Who sees the data, and a path to ownership

A defence supplier accumulates a running record of what is inside a nation's grid, banks and ships, so the questions of whether it shares what it sees with a home government and whether monitoring data can stay inside the country belong in the contract, asked early and in writing. This capability has no reporting line to a foreign government and no obligation to share what it finds, with residency terms set per engagement, which for a ministry or national operator is frequently the deciding term. Defensive operations can be delivered as a service, built as a national security-operations capability, or staged from one to the other, with training that builds the national team rather than perpetual outsourcing.

Defensive cybersecurity
Contact us

Tell us the requirement. Specifications and the export position are confirmed in briefing, not published here.