Four security services.
Your data and your control stay inside your organisation.
Public institutions and large corporates in South Africa run into the same two constraints. Cover is needed around the clock, but the skills to staff it are scarce and expensive to hold. At the same time, handing the whole security function, and the data that comes with it, to an outside party is not acceptable. These four services answer both. Each works as an extension of your team, on your infrastructure, under your rules. Hayshack installs, integrates, operates and answers for all four in-country.
- 01Detection and response 24/7
- 02Preemptive protection
- 03Continuous defence testing
- 04Incident response team
The order follows the path of an attack: stop it before it arrives, see it once it is in, prove the defence actually works, and have someone to call when none of that was enough. This is not a proposal and not part of any procurement process. It only asks which of the four is worth a conversation. The last page has a one-click answer.
AI SOC: detection and response around the clock, without adding people to your team
Our AI security system takes over collection, correlation and analysis of events, and discards false alarms on its own. We cover the shifts, you keep the decision on every action.
Your data never leaves your network
The system runs on your side. No cloud, no external log storage, no cross-border transfer. Analysts work through access you grant and revoke, with a full audit trail.Relevant to POPIA section 19 on security safeguards and section 72, which restricts transborder flows of personal information.
The attacker who is already inside
Lateral movement with legitimate credentials, and misuse of privileged access from inside: bulk queries against customer or citizen records, files opened outside an assigned case, activity at odd hours. To signature-based detection it all looks normal.
Cost does not scale with data volume
No charging per GB or per EPS. The figure holds across the budget year, so sources switched off today because of licence cost can be turned back on without going back for funding.
No change to your infrastructure
We connect to your existing SIEM and log sources. No migration, no tool replacement, no implementation project. If there is no SIEM, or it is near end of life, we supply one.
Triage instead of an alert storm
Correlation and false positive elimination happen automatically, before anything reaches a person. The aim is less noise, not another console to watch.
Co-managed, not outsourced
Platform, rules and data are yours. We cover shifts and expertise and train your people to take over any part of it. Hayshack operates and answers for the service in-country, and the specialist team behind it works within an hour of your day, so nothing waits for an overnight handover.
How it starts
We connect to your existing sources, then run 30 days alongside your team. The measure is how many manual alerts have disappeared, and what we saw that you did not.
What we do not ask of you
To change existing tools, to open an outbound channel to a cloud service, to hire anyone, or to hand us control of your security function.
*In preparation, as an optional add-on: monitoring of AI use through the same system, recording what employees and internal systems send to AI services and what comes back. Useful on security, because you see where confidential data and code go, and on governance, because a record of how an automated decision was reached cannot be rebuilt after the fact. POPIA section 71 already limits decisions based solely on automated processing.
Preemptive protection: a signal about an attack before the attack reaches you
This is why the detection on the previous page sees earlier. Instead of data about attacks that already happened somewhere and were written up afterwards, we watch attackers live, on a network of decoys that look like your real systems.
Decoys an attacker cannot tell from production
Clones of your portals, VPN endpoints, administrative interfaces and network devices, protected by patent and built so that neither automated scanners nor attacking AI agents recognise them as a trap.
No false positives by definition
A decoy has no legitimate function, so every interaction with it is hostile. Nothing to tune, no sensitivity threshold, and no alerts burning someone’s shift.
A signal before public disclosure
The technique is recognised while it is being used, before the vendor confirms the flaw. In the documented case of the Microsoft SharePoint zero-day, that was 45 days ahead of the official patch.
Early warning for your sector, and a sovereign option
A campaign forming against government bodies or against your industry appears on other participants’ sensors before it reaches you. If your data may not leave the country, the service runs as a closed set of sensors for you alone.
IOFA feeds instead of lists of known attacks
A classic feed ships indicators of compromise, traces of attacks that already happened and were published afterwards. We ship indicators of future attack: addresses, domains, tool signatures and behaviour taken from attackers active at that moment, so they do not go stale when the attacker moves infrastructure.
A feed that blocks, not one that reports
Indicators are pushed automatically into enforcement, to the firewall, WAF and DNS layer for preventive blocking, and into the SIEM as context, with no rule to approve by hand. If you run a mature SOC, the same feed comes as a raw stream with ready detection rules and hunting queries.Delivered over REST API and the STIX/TAXII standard, mapped to MITRE ATT&CK.
Not a separate subscription
This layer is included in the AI SOC price. It is contracted on its own only when the SOC part is not on the table, or when you want the feed alone for your own team.
How it starts
The first decoys go up in one working day from ready templates, and clones of your specific internal applications in three to seven days. No changes in production.
*Preemptive security is a Gartner category in its own right. On their estimate, by 2030 it will take half of all IT security spending, up from under 5 percent in 2024. gartner.com, Preemptive Cybersecurity Solutions. Gartner does not endorse any vendor or product depicted in its publications; GARTNER is a registered trademark of Gartner, Inc.
Continuous defence testing, from five countries at once
An annual penetration test tells you what the state was on that day. Between two tests a configuration changes, a new service goes live, and a vulnerability that was closed comes back. This service tests continuously and in parallel from several countries.
A test that also checks your SIEM, step by step
For every attack we run, we follow the whole chain: whether data about the attempt reached the SIEM, whether correlation tied it into a single event, whether an alert fired, and whether it was then quietly closed as a false positive. The output is a measured finding about where the chain breaks, not an assumption that it holds.
The same test from three to five countries
Run side by side, including an origin inside Africa, this shows how your WAF, geo-rules, anti-DDoS and CDN layer behave depending on where traffic comes from. Differences are common and usually unintentional. A single-location test cannot show them.
Catching a vulnerability that came back
A flaw that was closed and then reintroduced through a later configuration change or a new release is found in days rather than at the next annual test.Supports the regular testing of controls required by Joint Standard 2 of 2024 for financial institutions, and the board oversight of technology expected under King IV principle 12.
Fake domains and applications impersonating you
Domains and mobile applications that pass themselves off as yours are found while the campaign is still being prepared, before your customers or the public start reporting losses, with support in getting them taken down.
Employee and customer credentials on the dark web
Continuous tracking of leaked accounts, access being sold, and mentions of your organisation on closed forums, with a check on whether the credential still works.
A live picture of what you expose
An inventory of everything reachable from the internet, including subsidiaries, APIs, test environments and supplier infrastructure, kept current as the environment changes.
How it starts
The first cycle from all locations gives a baseline in two weeks, including the list of differences in how the defence behaves by country of origin, and the measurement of what detection actually saw. After that it repeats at an agreed rhythm.
Output for audit and oversight
The report goes straight into internal and external audit and, for public institutions, into the IT control findings the Auditor-General works from. It evidences testing across the whole year rather than on a single date.
An incident response team, contracted before you need it
A serious incident is not a ticket. Hayshack fields this with the specialist team behind the platform, which has led the response on several of the largest national-scale incidents in its home market, every one resolved. The technical sequence of each, and the decisions taken under pressure, we can walk through in a meeting.
Activation within two hours
A contracted guarantee, 24 hours a day. Without an agreement already in place, work can only start once contracting or procurement is done, and those are hours an incident never gives back.
Forensics on day one
Attack timeline, first point of entry, the lateral movement path and evidence of data leaving, using our own tooling and independent of whether your logging covers the period of the attack.
Evidence that holds up afterwards
Collection and handling under an unbroken chain of custody, with documentation that survives scrutiny at SAPS, in a disciplinary process, or at the Information Regulator.
Containment without shutting the business down
Layered control of outbound traffic and targeted isolation of individual hosts and segments, so the attacker’s channel is cut with the smallest possible interruption to service.
Breach notification and crisis communication
Support in preparing the required notifications and in communicating to the board, to customers or the public, and to the media.POPIA section 22 requires notification to the Information Regulator and to affected data subjects as soon as reasonably possible. Financial institutions must also report a material incident under Joint Standard 2 of 2024.
Why it is stronger with AI SOC
If we are already connected to your sources, the team enters the incident with history and a known environment. Without that, the first 24 hours go to collection and learning the network, at the moment they are most expensive.
Recommended form
As an add-on to AI SOC, one line in the budget covers both detection and a proven ability to respond. It is also available as a standalone retainer if the SOC part is not current.
Plan testing and how it is charged
One incident simulation a year with your team and executive, turning the procedure into a tested capability. The retainer covers readiness and guaranteed activation; work on an actual incident is charged by the day.
Just tell us what makes sense
Tick the services worth a conversation. An answer of “none of these” is just as useful and saves us both time.
The next step is 45 minutes
For whichever services you tick, we set up a single 45 minute technical conversation with no preparation needed on your side. We go through what the service looks like in your specific environment and, if you want, the technical sequence of the incidents we have worked on.
A demonstration in your own environment is possible before any procurement. This document is not a proposal, binds neither party, and is not participation in preparing procurement documentation.
