Cyber Security Operations · Gaborone · Southern Africa
[email protected]  ·  Client portal →
01 / Detection

Managed cyber detection & monitoring.

We run a live Cyber Security Operations Centre dedicated to watching your network for anomalies - intrusions, malware, insider misuse - and stepping in the moment something looks wrong.

The centre is split into six specific roles so the right person handles the right job. Only authorised personnel can log into the security dashboard. The team handles the entire lifespan of a threat - from first detection to closure - all under managerial oversight and an independent audit role.

24×7 Tiered SoD enforced AD-bound
Managed CSOC deliverables Active
  • Operating manual
    Documented · versioned v3.2
    Live
  • Role-to-policy map
    Aligned to AD groups · 6 roles
    Live
  • Tiered escalation
    Explicit deny on out-of-scope paths
    Enforced
  • SoD audit & findings report
    Last run 2 d ago · clean
    Weekly
  • Executive summary
    For board / change control
    Quarterly
02 / Automation

Automated sorting of incoming security threats & contextual reporting.

Our system does the repetitive, boring detective work - categorising each problem, judging whether it is a real emergency, and sending it to the right person. That way human analysts engage only with cases that warrant their judgement.

The result: threats are recognised and sized up much faster, analysts stay engaged instead of burning out on repetition, and the business stops paying for work a machine can do reliably.

Bespoke Enrichment Case routing
03 / Identity

Identity detection & access management.

A central gatekeeper that decides who, or what, is allowed to read which password, key or database - and for how long. Every request is tied to a named user or application, every access is short-lived, and no application is ever handed a permanent password in clear text.

Under the hood it is a hardened HashiCorp Vault deployment with full LDAPS validation, dual-tier identity model and dynamic database credentials - but you don’t have to think about that. You just see the audit trail.

LDAPS AppRole Dynamic DB creds PKI
Vault vault.augcyba.com Healthy
Token lease auto-revoke on expiry
s.AbCd1234…XyZ9 47:23 / 1 h · 24 h ceiling
SECRET_ID rotation quarterly · 30‑day notice
fga-app Q3 2026 87 d
sirp-backend Q3 2026 87 d
soc-triage Q3 2026 22 d · alert
Audit stream HMAC‑verified · live
14:32:18 jdoe@augcyba read secret/csoc/ir/INC-2026-0142
14:32:17 fga-app issue auth/approle/login
14:32:15 sirp-backend read database/creds/sirp-postgres
14:32:12 vault.audit1 list sys/audit
Break-glass documented escalation
ROOT TOKEN · sealed
Audit-attributable use only. Quorum approval required.
CSO Vault Admin Platform Ops
04 / Assurance

Automated firewall audit.

A continuous, automated audit of firewall configurations against client baselines and industry standards. Each drift produces a structured finding, an owner and a remediation path.

The output is not a 600‑page PDF that sits unread on a board drive. It is a living register, queryable in the SIEM, with a verifiable history of who changed what, when and why.

Baselines Industry standards Drift detection Continuous
FINDING · SEN-2026-0521-014 High
FortiGate-DMZ-01 · detected 2 m ago
Rule
inbound ANY → 10.10.20.0/24 :: tcp/3389
Baseline · CIS / Client policy
Deny inbound RDP from outside corp-jump segment.
Diff
- set src "any"+ set src "corp-jump"
Owner
Platform / Networks
Remediation
Restrict source; raise CR-2026-0142
05 / Reporting

Regulator‑grade intelligence sharing.

A structured, authenticated channel through which we report incidents to the regulators of the markets we operate in. The platform enforces consistent reporting taxonomy, supports redaction policies, and produces a signed submission envelope that the regulator can verify independently.

Signed envelopes Taxonomy Redaction Regulator-ready
Intel Share 3 peers synced
EVENT · #2026-0142
Credential stuffing · banking sector
TLP:AMBER taxonomy:financial-fraud Threat: High Confidence: 92%
Distribution 3 peers
  • Augmenta CSOC BoB · Regulator
  • Augmenta CSOC National CIRT
  • Augmenta CSOC Banking ISAC
Attributes 5 IOCs
ip-src 185.220.101.42
domain login-bank.tk
md5 8d2c34a1b9…
sha256 a5e4f29c08…
btc-address bc1q4n7k2…
06 / Notification

Instant notification of infrastructure breaches.

When something major breaks, our system automatically sends a WhatsApp message using Meta’s official business tools. These messages use strict, pre-approved templates and are only sent to a specific, hand-picked list of on-call engineers.

To guard against alert fatigue, it only texts when something actively breaks or gets fixed - never on every poll. Optional webhook support unlocks two-way alerting and delivery tracking.

Meta API State-change Approved structure Multi-recipient
At a glance

Service matrix.

Service Coverage Delivery model Status
Managed CSOC monitoring24 × 7Managed serviceLive
Automated triage (Xaelo)ContinuousEmbedded in CSOCLive
Zero‑trust secrets (Vault)Per‑app onboardingManaged + advisoryLive
Automated firewall auditContinuousManaged serviceLive
Regulator intelligence sharingPer‑marketManaged platformLive
Real-Time Infrastructure Events AlertingCritical eventsEmbeddedLive
Internal PKI & mTLS issuancePer‑serviceManagedPhase 2

* Live means the service is in production today and you can be onboarded now. Phase 2 means the service is on our roadmap and not yet available to clients.

Want to scope a service?

Tell us what you are trying to achieve. We will be honest about whether we are the right fit.