Security Monitoring and Threat Detection

This page sets out what security monitoring the managed platform includes by
default and what it does not. Active cyber-threat detection and anomalous
activity monitoring are not part of the default managed platform. Every
platform we deliver is designed and operated following security best
practices and hardening principles, and we can help you integrate a dedicated
security monitoring solution where you need one.

Included by default

Platform and infrastructure hardening

  • Secure cloud and Kubernetes baseline configurations
  • Least-privilege IAM and access control models
  • Network segmentation and restricted exposure (private by default)
  • Secure ingress and egress patterns and traffic controls

Operational security foundations

  • Centralized logging for infrastructure and workloads
  • Cloud audit logs and access trails
  • Secure secrets and configuration management practices
  • Alignment with cloud provider and Kubernetes security best practices

These controls prevent common misconfigurations and reduce attack surface,
but they are not a replacement for active threat detection.

Not included by default

The following are out of scope unless explicitly agreed otherwise. They
require specialized tooling and a dedicated ownership model beyond standard
platform operations.

  • Real-time cyber-threat detection (IDS/IPS, malware detection)
  • Behavioral or anomaly-based monitoring
  • SIEM or SOC services (24x7 security monitoring)
  • Security event correlation and threat intelligence analysis
  • Incident response for security breaches

Optional: security monitoring & threat detection

If your organization needs deeper security visibility, we can support you
with:

Advisory and recommendations

  • Reviewing your environment and risk profile
  • Recommending tools for cyber-threat detection, anomalous activity
    monitoring, or compliance and regulatory requirements

Enablement and integration support

  • Assisting with tool selection and architecture
  • Helping integrate the selected solution into your platform
  • Supporting alert routing, ownership, and escalation models

Commonly used solutions include cloud-native security services, runtime
protection tools, and SIEM platforms, selected based on your scale, risk, and
compliance needs.

Our approach

Security by design, not security by assumption. Platform operations and
security monitoring are treated as separate concerns, with monitoring enabled
to match your organization's needs and maturity. If strengthening security
monitoring is a priority, contact us and we will define a tailored approach
together.

Related articles


Did this page help you?