Cyber Security Operations · Gaborone · Southern Africa
info@augcyba.com  ·  Client portal →
01 / Detection

Managed CSOC monitoring.

A fully operational, tiered Cyber Security Operations Centre. Six AD‑backed analyst roles, a documented operating manual, and Segregation‑of‑Duties enforced in policy.

Cover ranges from triage through to incident response, with managerial oversight and an independent audit role.

24×7 Tiered SoD enforced AD-bound
Managed CSOC deliverables Active
  • Operating manual
    Documented · versioned v3.2
    Live
  • Role-to-policy map
    Aligned to AD groups · 6 roles
    Live
  • Tiered escalation
    Explicit deny on out-of-scope paths
    Enforced
  • SoD audit & findings report
    Last run 2 d ago · clean
    Weekly
  • Executive summary
    For board / change control
    Quarterly
02 / Automation

Automated triage & enrichment.

Our in‑house triage engine handles the predictable parts of investigation - enrichment, classification, confidence‑scoring and routing - so that human analysts engage only with cases that warrant their judgement.

The result: faster mean‑time‑to‑triage, lower analyst burnout, and a measurable cap on the cost of repetitive workloads.

Bespoke Enrichment Case routing
03 / Identity

Zero‑trust secrets & identity management.

A hardened HashiCorp Vault deployment with full LDAPS certificate validation, dual‑tier identity model, and dynamic PostgreSQL credentials. Applications authenticate via AppRole with response‑wrapped SECRET_IDs; no application reads a clear‑text credential.

LDAPS AppRole Dynamic DB creds PKI
Vault vault.augcyba.com Healthy
Token lease auto-revoke on expiry
s.AbCd1234…XyZ9 47:23 / 1 h · 24 h ceiling
SECRET_ID rotation quarterly · 30‑day notice
fga-app Q3 2026 87 d
sirp-backend Q3 2026 87 d
soc-triage Q3 2026 22 d · alert
Audit stream HMAC‑verified · live
14:32:18 jdoe@augcyba read secret/csoc/ir/INC-2026-0142
14:32:17 fga-app issue auth/approle/login
14:32:15 sirp-backend read database/creds/sirp-postgres
14:32:12 vault.audit1 list sys/audit
Break-glass documented escalation
ROOT TOKEN · sealed
Audit-attributable use only. Quorum approval required.
CSO Vault Admin Platform Ops
04 / Assurance

Automated firewall audit.

A continuous, automated audit of firewall configurations against client baselines and industry standards. Each drift produces a structured finding, an owner and a remediation path.

The output is not a 600‑page PDF that sits unread on a board drive. It is a living register, queryable in the SIEM, with a verifiable history of who changed what, when and why.

Baselines Industry standards Drift detection Continuous
FINDING · SEN-2026-0521-014 High
FortiGate-DMZ-01 · detected 2 m ago
Rule
inbound ANY → 10.10.20.0/24 :: tcp/3389
Baseline · CIS / Client policy
Deny inbound RDP from outside corp-jump segment.
Diff
- set src "any"+ set src "corp-jump"
Owner
Platform / Networks
Remediation
Restrict source; raise CR-2026-0142
05 / Reporting

Regulator‑grade intelligence sharing.

A structured, authenticated channel through which we report incidents to the regulators of the markets we operate in. The platform enforces consistent reporting taxonomy, supports redaction policies, and produces a signed submission envelope that the regulator can verify independently.

Signed envelopes Taxonomy Redaction Regulator-ready
Intel Share 3 peers synced
EVENT · #2026-0142
Credential stuffing · banking sector
TLP:AMBER taxonomy:financial-fraud Threat: High Confidence: 92%
Distribution 3 peers
  • Augmenta CSOC BoB · Regulator
  • Augmenta CSOC National CIRT
  • Augmenta CSOC Banking ISAC
Attributes 5 IOCs
ip-src 185.220.101.42
domain login-bank.tk
md5 8d2c34a1b9…
sha256 a5e4f29c08…
btc-address bc1q4n7k2…
06 / Notification

Real-Time Infrastructure Events Alerting.

Critical state‑change alerts dispatched over the Meta WhatsApp Business API, against pre‑approved templates, to a curated recipient list. Alerts fire only on state transitions - not on every poll - which keeps the channel meaningful.

Optional webhook support unlocks two‑way alerting and delivery tracking.

Meta API State-change Approved templates Multi-recipient
At a glance

Service matrix.

Service Coverage Delivery model Status
Managed CSOC monitoring24 × 7Managed serviceLive
Automated triage (Xaelo)ContinuousEmbedded in CSOCLive
Zero‑trust secrets (Vault)Per‑app onboardingManaged + advisoryLive
Automated firewall auditContinuousManaged serviceLive
Regulator intelligence sharingPer‑marketManaged platformLive
Real-Time Infrastructure Events AlertingCritical eventsEmbeddedLive
Internal PKI & mTLS issuancePer‑serviceManagedPhase 2

Want to scope a service?

Tell us what you are trying to achieve. We will be honest about whether we are the right fit.