Our offerings

02 / AXENTYR Security

Protect and respond.

Make assets, dependencies and coverage visible, then qualify alerts and coordinate the investigation of a cyber or operational incident.

Conceptual illustration · Security

Who it is for

Cybersecurity, site security and operations managers in institutions, banks and businesses that need a defined protection scope and clear incident responsibilities.

Development status

In development. The detailed service perimeter, integrations, equipment and support arrangements are being defined for each security scope.

The proposition

See the perimeter. Organise the response.

Build a view of assets and their dependencies, connect relevant authorised records, and assist teams in qualifying alerts with context. Track the evidence, investigation steps and handovers in one agreed workflow. People remain responsible for escalation, intervention and validation.

Cybersecurity and operational or site security are distinct scopes. Start from the systems, facilities and activities concerned, the monitoring already in place and the gaps in coverage. Define how an alert becomes an investigation and who coordinates the response.

Scope

A focused scope.

01

Cyber assets and dependencies

Identify critical systems, identities and data flows. Examine which dependencies matter to the service and where the existing monitoring provides or lacks coverage.

02

Operational and site coverage

Study facilities, access points, sensors and operational dependencies as a separate perimeter, with the people and procedures needed to check a physical or activity-related alert.

03

Qualification, investigation and coordination

Link alerts to their context, record the evidence and investigation steps, and organise handovers. Define who validates findings and who may authorise an intervention.

How the work is structured

From the task
to a reviewed result.

An engagement starts from your objective and defines the inputs, work and validation needed to address it.

  1. 01

    Define the perimeter and coverage

    Select cyber, operational/site security or both. Identify assets, dependencies, existing controls and the areas where observation or ownership is missing.

  2. 02

    Connect authorised operational evidence

    Agree which inventories, event logs, access records or sensor alerts may be used. Preserve their context, time window and access restrictions.

  3. 03

    Qualify and investigate

    Relate an alert to the affected asset and activity. Assist reviewers with relevant context, distinguish evidence from hypotheses and record the checks still required.

  4. 04

    Coordinate action and validate the record

    Assign ownership, escalation and intervention authority. Track handovers and decisions, then have the responsible people validate the investigation and response report.

Questions in context

See how a project
could be scoped.

Illustrative situations. These examples describe a question, the inputs and a result to review; they are not accounts of delivered work.

Cybersecurity

Investigate an unusual access alert

Question
Does an access alert reflect expected activity, a configuration issue or an incident that needs escalation?
Inputs
Authorised identity and access logs, asset ownership, expected access policies and relevant change records. The scope specifies which records and time window can be examined.
Output
An alert record linking the observed access to systems and dependencies, evidence supporting each hypothesis, the checks to perform and a proposed escalation route.
Human review
The responsible security analyst confirms the context with the system owner and validates the classification. Any access restriction or intervention requires the authorised team’s decision.

Cybersecurity

Find gaps around a critical service

Question
Which assets and dependencies would affect a critical digital service, and where is its monitoring incomplete?
Inputs
Client-authorised asset inventories, dependency maps, control records, monitoring configuration and existing assessment reports. This scenario does not presume unrestricted scanning rights.
Output
A view of the service’s dependencies, ownership and coverage gaps, with a prioritised list of checks and protection options for review.
Human review
Technology and security owners validate the asset map and the practical effect of each gap. Changes enter their normal approval process; the analysis does not automatically modify systems.

Operational and site security

Qualify a site access anomaly

Question
What should a site team check when an access event or sensor alert differs from the expected operation?
Inputs
Authorised access records, relevant sensor events, site zones, planned activity and the people responsible for those areas, within agreed privacy and retention rules.
Output
A contextual alert linking the event to the site zone and affected activity, missing checks, the responsible operator and the escalation steps to consider.
Human review
A designated site operator checks the physical situation and confirms the event’s significance. Existing access, emergency and safety procedures govern any action.

Operational and site security

Coordinate an interruption across teams

Question
Who needs to act when an operational interruption affects several assets or site activities?
Inputs
Approved incident reports, facility and service dependencies, contact roles, continuity procedures and the updates supplied by the teams concerned.
Output
A shared incident timeline, affected activities, unresolved information and a coordination record with owners, handovers and response updates.
Human review
The incident coordinator verifies updates with each responsible team and approves the report. Contracted coverage and available staff determine who can respond and when.

Deliverables

A defined scope.
Useful deliverables.

A worked example

Two incident contexts. One accountable review.

Separate cyber and site scenarios show how assets, evidence and coverage gaps shape a proposed response that still requires human approval.

Incident review / Cyber and site scenarios Mock-up — fictional data

Synthetic data. Every source, asset, state and decision below belongs to this example.

Cyber security A sign-in followed by an access change.
Review question

Does this activity fit an authorised change?

Assets & dependencies

What does the signal affect?

Staff portal
Identity gateway and assigned access roles
Change workflow
Service owner and approved maintenance record

Synthetic coverage in this scenario

What is available — and unknown.

Available in this example
A sign-in event and an access-change record.
Unknown
Endpoint state and the person’s current intent.
Outside this example
Network traffic and other systems.

Evidence retained

Keep the original records.

C-A

Sign-in event

A new session appears in the identity record.

C-B

Access-change record

A role change is requested after the session begins.

C-C

Maintenance note

A planned change exists, but the session is not linked to it.

Qualification & investigation

Test the explanation.

  1. Qualify the alert

    A sequence worth reviewing; the event alone does not establish misuse.

  2. Investigate the context

    Compare the session and change record with the authorised maintenance scope. Ask the service owner to verify the link.

Proposed action

Review the affected access with the service owner and consider a temporary restriction if justified.

Human approval required

Security lead and service owner review scope, impact and reversibility before any action.

Await human validation of the change. No restriction is executed by this demonstration.

Simulated response record

Keep evidence references, the reviewer’s reasoning, the approval owner and follow-up together. Status: awaiting human review.

Site & operational security An access event beside a maintenance task.
Review question

Is the door event explained by the scheduled work?

Assets & dependencies

What does the signal affect?

Door checkpoint A
Access reader and site access rules
Maintenance task
Site operator and an approved work scope

Synthetic coverage in this scenario

What is available — and unknown.

Available in this example
A reader event and a maintenance note.
Unknown
The door’s current physical state and who is present.
Outside this example
Video observations and other access points.

Evidence retained

Keep the original records.

S-A

Reader event

Door checkpoint A records an access exception.

S-B

Work note

Maintenance is authorised in the nearby work area.

S-C

Review note

The work note does not confirm that this door was part of the task.

Qualification & investigation

Test the explanation.

  1. Qualify the alert

    An exception with a plausible work context, but no confirmed explanation.

  2. Investigate the context

    Check the reader event against the approved work scope and ask the site operator to verify the checkpoint.

Proposed action

Arrange a bounded site check before changing access rules or escalating the incident.

Human approval required

The site lead authorises the check and confirms who can act within the operating rules.

Await the site lead’s review. No door, access system or equipment is controlled here.

Simulated response record

Keep evidence references, the reviewer’s reasoning, the approval owner and follow-up together. Status: awaiting human review.

These scenarios illustrate a review process. They do not establish deployed coverage or execute autonomous remediation.

Engagement options

A scope of its own.
A contract of its own.

Each offering has its own contract. Select the scope, access model and support arrangements that fit your needs.

Cybersecurity

Systems, identities, data and digital services: define asset visibility, dependencies, monitoring coverage and the path from an alert to an authorised investigation.

Operational and site security

Facilities, access, sensors and essential activities: map the site’s dependencies and coverage, then define alert qualification, operational checks and coordination with the teams responsible.

Pricing structure

  • An initial evaluation and protection plan, followed by separately scoped deployment.
  • Recurring maintenance and supervision priced against the agreed perimeter, responsibilities and service levels.
  • Specialised interventions separately authorised, scoped and priced.

Before an engagement

Conditions to agree.

Prerequisites

  • A selected cyber or operational/site perimeter, with asset and activity owners.
  • Authorised records, interfaces and an agreed view of existing monitoring coverage.
  • Named reviewers, escalation routes and people authorised to intervene.
  • Explicit coverage, response times, responsibilities and service-level terms.

Operating responsibilities

  • No SOC or 24/7 human response service is announced. Continuous coverage requires a capable team or partner and explicit commitments.
  • AI supports qualification and coordination; it does not authorise intervention or automatically remediate systems.
  • No certification or clearance is claimed. Any required credentials and specialised intervention capability must be established for the engagement.

Independent offerings

Explore the other offerings.

AXENTYR Security can be considered on its own. A combination is optional and starts with your needs.

Useful questions

Questions about Security.

Does AXENTYR Security cover digital systems or physical sites?

Cybersecurity and operational/site security are distinct scopes. Cybersecurity concerns systems, identities, data and service dependencies. Operational/site security concerns facilities, access, sensors and essential activities. Each needs its own view of assets, coverage, responsibilities and incident workflow; they can also be coordinated.

What would AI do in security operations?

Assist alert qualification by relating an event to the asset, activity and relevant evidence. Help organise investigation notes and handovers. People validate the findings and authorise action; the workflow does not automatically remediate systems.

Is 24/7 human monitoring available?

No 24/7 human monitoring or response service is announced as available. Continuous coverage would require a capable team or partner, named responsibilities, escalation routes and an agreed service level.

Do we need robots to use AXENTYR Security?

No. Security has its own scope and contract. A robotics component is optional and would only be considered for a defined need, such as incorporating robot observations into a site’s incident workflow.

AXENTYR Security

Define the perimeter. Assign the response.

Identify your priority assets, existing monitoring and incident workflow. Scope cyber or operational/site security around the evidence, coverage and responsibilities you need.

Scope a security engagement