Four security services.
Your data and your control stay inside your organisation.

Public institutions and large corporates in South Africa run into the same two constraints. Cover is needed around the clock, but the skills to staff it are scarce and expensive to hold. At the same time, handing the whole security function, and the data that comes with it, to an outside party is not acceptable. These four services answer both. Each works as an extension of your team, on your infrastructure, under your rules. Hayshack installs, integrates, operates and answers for all four in-country.

  • 01Detection and response 24/7
  • 02Preemptive protection
  • 03Continuous defence testing
  • 04Incident response team

The order follows the path of an attack: stop it before it arrives, see it once it is in, prove the defence actually works, and have someone to call when none of that was enough. This is not a proposal and not part of any procurement process. It only asks which of the four is worth a conversation. The last page has a one-click answer.

Jump to the reply deck ↓

Service 01

AI SOC: detection and response around the clock, without adding people to your team

Our AI security system takes over collection, correlation and analysis of events, and discards false alarms on its own. We cover the shifts, you keep the decision on every action.

Your network System logs Network telemetry Endpoints and applications AI SIEM correlation and elimination of false positives Confirmed finding with context and a recommended action Hayshack analyst 24 hours a day access you grant and revoke, with a full audit trail of every action no data sent to the cloud
All data stays inside your network. The analyst works from outside, through a channel you open and close.

Your data never leaves your network

The system runs on your side. No cloud, no external log storage, no cross-border transfer. Analysts work through access you grant and revoke, with a full audit trail.Relevant to POPIA section 19 on security safeguards and section 72, which restricts transborder flows of personal information.

The attacker who is already inside

Lateral movement with legitimate credentials, and misuse of privileged access from inside: bulk queries against customer or citizen records, files opened outside an assigned case, activity at odd hours. To signature-based detection it all looks normal.

Cost does not scale with data volume

No charging per GB or per EPS. The figure holds across the budget year, so sources switched off today because of licence cost can be turned back on without going back for funding.

No change to your infrastructure

We connect to your existing SIEM and log sources. No migration, no tool replacement, no implementation project. If there is no SIEM, or it is near end of life, we supply one.

Triage instead of an alert storm

Correlation and false positive elimination happen automatically, before anything reaches a person. The aim is less noise, not another console to watch.

Co-managed, not outsourced

Platform, rules and data are yours. We cover shifts and expertise and train your people to take over any part of it. Hayshack operates and answers for the service in-country, and the specialist team behind it works within an hour of your day, so nothing waits for an overnight handover.

How it starts

We connect to your existing sources, then run 30 days alongside your team. The measure is how many manual alerts have disappeared, and what we saw that you did not.

What we do not ask of you

To change existing tools, to open an outbound channel to a cloud service, to hire anyone, or to hand us control of your security function.

*In preparation, as an optional add-on: monitoring of AI use through the same system, recording what employees and internal systems send to AI services and what comes back. Useful on security, because you see where confidential data and code go, and on governance, because a record of how an automated decision was reached cannot be rebuilt after the fact. POPIA section 71 already limits decisions based solely on automated processing.

Service 02 · included in AI SOC

Preemptive protection: a signal about an attack before the attack reaches you

This is why the detection on the previous page sees earlier. Instead of data about attacks that already happened somewhere and were written up afterwards, we watch attackers live, on a network of decoys that look like your real systems.

the classic IOC feed sees nothing here, up to 45 days in the documented case Attacker first uses the technique our signal, the same day Vulnerability disclosed Patch IOC feed preventive blocking starts here everyone else only here
One technique, two points on the timeline. The distance between them is the whole window in which the attack can still be stopped.

Decoys an attacker cannot tell from production

Clones of your portals, VPN endpoints, administrative interfaces and network devices, protected by patent and built so that neither automated scanners nor attacking AI agents recognise them as a trap.

No false positives by definition

A decoy has no legitimate function, so every interaction with it is hostile. Nothing to tune, no sensitivity threshold, and no alerts burning someone’s shift.

A signal before public disclosure

The technique is recognised while it is being used, before the vendor confirms the flaw. In the documented case of the Microsoft SharePoint zero-day, that was 45 days ahead of the official patch.

Early warning for your sector, and a sovereign option

A campaign forming against government bodies or against your industry appears on other participants’ sensors before it reaches you. If your data may not leave the country, the service runs as a closed set of sensors for you alone.

IOFA feeds instead of lists of known attacks

A classic feed ships indicators of compromise, traces of attacks that already happened and were published afterwards. We ship indicators of future attack: addresses, domains, tool signatures and behaviour taken from attackers active at that moment, so they do not go stale when the attacker moves infrastructure.

A feed that blocks, not one that reports

Indicators are pushed automatically into enforcement, to the firewall, WAF and DNS layer for preventive blocking, and into the SIEM as context, with no rule to approve by hand. If you run a mature SOC, the same feed comes as a raw stream with ready detection rules and hunting queries.Delivered over REST API and the STIX/TAXII standard, mapped to MITRE ATT&CK.

Not a separate subscription

This layer is included in the AI SOC price. It is contracted on its own only when the SOC part is not on the table, or when you want the feed alone for your own team.

How it starts

The first decoys go up in one working day from ready templates, and clones of your specific internal applications in three to seven days. No changes in production.

*Preemptive security is a Gartner category in its own right. On their estimate, by 2030 it will take half of all IT security spending, up from under 5 percent in 2024. gartner.com, Preemptive Cybersecurity Solutions. Gartner does not endorse any vendor or product depicted in its publications; GARTNER is a registered trademark of Gartner, Inc.

Service 03

Continuous defence testing, from five countries at once

An annual penetration test tells you what the state was on that day. Between two tests a configuration changes, a new service goes live, and a vulnerability that was closed comes back. This service tests continuously and in parallel from several countries.

5 attack origins Your system Data reachedthe SIEM Correlated intoone event Alertfired Not closed asa false positive Example finding: data arrived and was correlated, but no alert fired, so step four was never assessed.
The test does not end with whether the attack got through. It ends with where the detection chain broke.

A test that also checks your SIEM, step by step

For every attack we run, we follow the whole chain: whether data about the attempt reached the SIEM, whether correlation tied it into a single event, whether an alert fired, and whether it was then quietly closed as a false positive. The output is a measured finding about where the chain breaks, not an assumption that it holds.

The same test from three to five countries

Run side by side, including an origin inside Africa, this shows how your WAF, geo-rules, anti-DDoS and CDN layer behave depending on where traffic comes from. Differences are common and usually unintentional. A single-location test cannot show them.

Catching a vulnerability that came back

A flaw that was closed and then reintroduced through a later configuration change or a new release is found in days rather than at the next annual test.Supports the regular testing of controls required by Joint Standard 2 of 2024 for financial institutions, and the board oversight of technology expected under King IV principle 12.

Fake domains and applications impersonating you

Domains and mobile applications that pass themselves off as yours are found while the campaign is still being prepared, before your customers or the public start reporting losses, with support in getting them taken down.

Employee and customer credentials on the dark web

Continuous tracking of leaked accounts, access being sold, and mentions of your organisation on closed forums, with a check on whether the credential still works.

A live picture of what you expose

An inventory of everything reachable from the internet, including subsidiaries, APIs, test environments and supplier infrastructure, kept current as the environment changes.

How it starts

The first cycle from all locations gives a baseline in two weeks, including the list of differences in how the defence behaves by country of origin, and the measurement of what detection actually saw. After that it repeats at an agreed rhythm.

Output for audit and oversight

The report goes straight into internal and external audit and, for public institutions, into the IT control findings the Auditor-General works from. It evidences testing across the whole year rather than on a single date.

Service 04 · add-on to AI SOC or a standalone retainer

An incident response team, contracted before you need it

A serious incident is not a ticket. Hayshack fields this with the specialist team behind the platform, which has led the response on several of the largest national-scale incidents in its home market, every one resolved. The technical sequence of each, and the decisions taken under pressure, we can walk through in a meeting.

No retainer in place With AI SOC and a retainer procurement or contracting arrival and access collection and learning your network forensics begins activation, 2 hours containment and forensic work forensics begins difference, about one day Both timelines start at the same moment, when the incident is discovered.
Time lost at the start is never recovered, because the attacker keeps moving through the network during it.

Activation within two hours

A contracted guarantee, 24 hours a day. Without an agreement already in place, work can only start once contracting or procurement is done, and those are hours an incident never gives back.

Forensics on day one

Attack timeline, first point of entry, the lateral movement path and evidence of data leaving, using our own tooling and independent of whether your logging covers the period of the attack.

Evidence that holds up afterwards

Collection and handling under an unbroken chain of custody, with documentation that survives scrutiny at SAPS, in a disciplinary process, or at the Information Regulator.

Containment without shutting the business down

Layered control of outbound traffic and targeted isolation of individual hosts and segments, so the attacker’s channel is cut with the smallest possible interruption to service.

Breach notification and crisis communication

Support in preparing the required notifications and in communicating to the board, to customers or the public, and to the media.POPIA section 22 requires notification to the Information Regulator and to affected data subjects as soon as reasonably possible. Financial institutions must also report a material incident under Joint Standard 2 of 2024.

Why it is stronger with AI SOC

If we are already connected to your sources, the team enters the incident with history and a known environment. Without that, the first 24 hours go to collection and learning the network, at the moment they are most expensive.

Recommended form

As an add-on to AI SOC, one line in the budget covers both detection and a proven ability to respond. It is also available as a standalone retainer if the SOC part is not current.

Plan testing and how it is charged

One incident simulation a year with your team and executive, turning the procedure into a tested capability. The retainer covers readiness and guaranteed activation; work on an actual incident is charged by the day.

Just tell us what makes sense

Tick the services worth a conversation. An answer of “none of these” is just as useful and saves us both time.

Tick at least one service, then send your reply.

The next step is 45 minutes

For whichever services you tick, we set up a single 45 minute technical conversation with no preparation needed on your side. We go through what the service looks like in your specific environment and, if you want, the technical sequence of the incidents we have worked on.

A demonstration in your own environment is possible before any procurement. This document is not a proposal, binds neither party, and is not participation in preparing procurement documentation.