Adversarial Defence Mesh — XDR · SOAR · Identity Graph · AI Red Team
Reseller SOCs sell tickets. We ship a defence mesh that learns: continuous AI red-team agents, identity-graph SOC, posture-as-code in CI, breach-rehearsal drills with measurable MTTR. Security that compounds, not catalogues.
The squads we drop in
Everything that ships
- Identity-graph SOCUnified identity, device and workload graph powering correlation and blast-radius scoring.
- Detection-as-code librarySigma + custom rules under git, CI tests, drift alerts.
- AI red-team agentsContinuous adversarial simulation across email, identity, app and cloud surfaces.
- Posture-as-code controlsTerraform-bound CIS / NCSC controls, drift detection, auto-remediation.
- Regulator dossier (DORA / NIS2)Auto-generated evidence pack: ICT register, incident reporting, third-party risk.
- Security Principal (CISSP / CCSP)
- Detection Engineer
- AI Red-Team Lead
- GRC + Audit Lead
detection: cred_stuffing.spike.v3
trigger: identity_graph.failed_logins
window: 5m
threshold: 40 distinct_users from 1 ASN
enrich:
- geo.ip
- threat_intel.bulk_lists
response:
- sso.lock_session(user)
- mfa.require_step_up
- slack.notify(#sec-ops)
- jira.create(P1, soar_runbook=cs-007)
mttr_target_p95: 6m
last_red_team: 2026-04-21 PASSWeeks 1–8 · first detection-as-code shipped by week 3
- 1Weeks 1–2Identity-graph baseline
Onboard IdPs, EDR, SaaS audit logs into the graph; map crown jewels.
- 2Weeks 3–5Detection-as-code + SOAR
Ship rule library, runbooks, auto-remediation; CI gates on every change.
- 3Weeks 5–8AI red-team continuous
Continuous adversarial drills, MTTR scorecard, regulator dossier signed off.
What buyers actually ask
Usually no — we orchestrate Defender, CrowdStrike, Wiz, Splunk or Sentinel. The mesh is the brain, your tools are the limbs.
We are SLA'd on MTTR and detection coverage, not ticket volume. Detections live in your git repo, not our portal.
Yes — the regulator dossier is shipped on day one and updated continuously, including third-party ICT risk and 24-hour incident reporting.
Prompt-injection, model-exfil and agent-abuse detections ship in the standard library, with red-team coverage on every release.
Stand up Adversarial Defence Mesh in Weeks 1–8.
We'll respond within one business day with a scoping note, a fixed-price outcome contract, and a named principal cleared for your domain. Your details sync straight into our concierge queue.
- • Outcome-priced — no T&M.
- • Sovereign by default — your data, your region, your keys.
- • Refund-backed if the contracted KPI isn't hit.