Platform capability

Operational

Incident response and containment support

A defined path from alert to containment to closure, with analysts who investigate before they escalate.

Overview

The measure of a security operation is not how many alerts it generates. It is what happens in the twenty minutes after a real one.

Vanguard incidents follow a defined lifecycle: alert, triage, investigation, evidence, containment, resolution, report. Analysts investigate before escalating, so what reaches you is a substantiated finding with the evidence attached - not a forwarded alert asking you to work out whether it matters.

Escalation contacts, severity thresholds and out-of-hours procedures are agreed per organisation during onboarding and recorded in the platform, not held in an analyst memory. When a critical incident occurs at 02:00, the procedure is already written down.

What this identifies

  • Confirmed compromise requiring immediate containment
  • Ransomware activity in its early stages
  • Business email compromise and account takeover
  • Data exfiltration attempts
  • Insider incidents requiring evidence preservation

Delivery status: Operational - deployed and in production service.

Capabilities

What incident response does

  • Triage and investigation

    Analysts establish what actually happened before anyone is contacted.

  • Agreed escalation paths

    Per-organisation contacts, thresholds and out-of-hours procedures, configured in the platform.

  • Containment guidance

    Clear recommended actions, with destructive steps requiring your explicit authorisation.

  • Evidence preservation

    Artefacts and timelines are collected and retained so an incident can withstand later scrutiny.

  • Post-incident reporting

    A written account of what happened, what was done, and what should change to prevent recurrence.

Under the hood

The engineering underneath

How this capability is actually engineered and operated. The specific detection tooling behind the security operations centre is shared with customers under agreement rather than published, for the same reason you would not publish yours.

  • Case management is the analyst system of record: every escalation becomes a case and every case receives a documented outcome.
  • Automated containment actions require human approval. An automated block that takes your office offline is a worse outcome than a slower response.
  • Monthly reporting is generated from case records rather than assembled by hand.

The full platform architecture is documented on the architecture page.

Services

Services delivered on this capability

The platform provides the capability. These are the engagements in which Tech49Originals operates it on your behalf.

  • Operational

    Managed SOC

    A staffed security operations centre in Windhoek monitoring your endpoints, servers and network around the clock, so you do not have to build one.

    Explore
  • Operational

    Incident Response

    Structured response to confirmed security incidents for Namibian organisations: investigation, scope, containment guidance and a written post-incident account.

    Explore

Related

  • In deployment

    Threat Hunting

    Analyst-led search for activity that did not trigger an alert, supported by fleet-wide query and remote forensic collection.

    Explore
  • In deployment

    Security Automation

    Automates the repetitive analyst work - enrichment, correlation, case creation - while keeping humans in control of anything destructive.

    Explore
  • Operational

    Security Reporting

    Monthly reporting generated from case records, written for both the technical team and the people who approve the budget.

    Explore

Get started

Find out what is actually happening on your network

A short conversation is usually enough to establish whether monitoring would tell you something you do not already know. There is no obligation and no sales script.