National-Level Cybersecurity
SOC autonomy, national CERT tooling, sovereign detection and response — Arabic-first.
The region's cybersecurity posture is a sovereign posture. We build the detection, triage and response systems that the region's national authorities, national CERTs and CNI operators need — inside their own perimeters, in Arabic and English, cleared to their standard, transferred with full IP.
Our cybersecurity practice is led by senior engineers with backgrounds in national-CERT operations, sovereign-cloud SOC leadership and defense-industrial cyber engineering. Every senior on the practice is personally cleared before mobilisation.
We do not resell foreign SIEM or SOAR products. We build the sovereign layer that sits above them — the triage copilots, the fusion agents, the OT / ICS anomaly baselines, the case-management stack — and we build it inside the customer's own tenancy.
Every production system ships with an incident-response runbook signed in Arabic, a red-team report cleared by the customer's authority, and a handover to the customer's own cleared engineers.
Autonomous SOC copilots for triage, containment and post-incident narrative
Threat-intelligence fusion agents across OSINT, dark-web, sensor and CERT feeds
OT/ICS anomaly detection for grid, water, downstream and transport operators
Cleared, air-gapped Arabic-first phishing, disinformation and influence-operations detection
National-CERT case-management and incident-coordination platforms
SOC mean-time-to-triage reduced from 47 minutes to under 4 minutes at a CNI operator.
First fully sovereign, Arabic-first phishing-and-influence-operations engine deployed at a national CERT.
OT / ICS anomaly baseline established across an entire national grid inside one operating year.
CNI operator · autonomous SOC copilot
A cleared six-person pod delivered an autonomous SOC triage copilot inside a Tier-1 CNI operator's on-prem SOC. Mean-time-to-triage reduced from 47 minutes to under 4 minutes; false-positive rate reduced 71%.
National CERT · phishing and influence-operations engine
First sovereign, Arabic-first phishing-and-influence-operations detection engine deployed at a national CERT. Fully air-gapped delivery, IP transferred, operated today by the CERT's own engineers.
National grid · OT/ICS anomaly baseline
Twelve-month programme to establish an OT/ICS anomaly baseline across the entire national grid of a GCC state. Fifteen critical substations instrumented; the reference baseline now feeds the national CERT.
Cleared nationals only. On-prem or air-gapped by construction. NCA / NESA / NCSA reference architectures respected and extended, never bypassed. Every playbook and runbook signed in the customer's language.
- Air-gapped / on-prem SOC integration
- Arabic-first NLU · dialect-aware
- Threat-intel fusion pipelines
- OT/ICS anomaly detection