Automate |
73+ integrated modules that give every department head the tools to automate their operations — while giving the CEO and Board a single, real-time source of truth.
ICTM automates each department's operations while giving the CEO and Board a unified source of truth — regardless of your sector.
Centralise 1,000+ tower sites, automate regulatory compliance (ZICTA, DPA, Cyber Security Act), and monitor multi-province infrastructure from one dashboard.
Unify branch infrastructure, automate BOZ and PCI DSS compliance, and give the board real-time visibility across core banking, ATM networks, and digital channels.
Secure policyholder data, automate PIA and data protection compliance, and unify branch and claims infrastructure under one governance platform.
Govern lean IT infrastructure, meet BOZ MFI regulations, and give leadership visibility across branches, mobile money integrations, and agent networks.
Govern OT/IT convergence, track plant-floor assets alongside enterprise IT, and ensure ISO compliance across factories, warehouses, and offices.
Centralise ICT assets across ministries, automate Cyber Security Act compliance, and provide transparent audit-ready governance reporting.
Answer 6 quick questions to gauge your ICT compliance and automation maturity
Everything your IT department needs, seamlessly integrated into one platform
Complete hardware & software tracking with lifecycle management
Track software licenses, expiration dates, and compliance status
Assign assets to users, departments, and locations
Utilization reports and depreciation tracking
Unified view of every asset across security, compliance, monitoring, and ITSM
Service dependency graph with upstream/downstream impact analysis
Tier-based license activation with feature flags and entitlement management
Ticket management with SLA tracking and auto-routing
IT projects with timeline, budget, and resource tracking
Multi-level approval chains with delegation
Project, task, deliverable, and field-inspection tracking for ICT service delivery teams
Track vendors, contracts, SLAs, and performance ratings
Define SLA policies, track MTTR/MTBF, and breach alerts
Self-service request catalog with category-driven workflows and approvals
Synthetic checks across endpoints with response-time graphs and downtime alerts
Device inventory, status monitoring, and topology mapping
CPU, memory, disk, and uptime monitoring with alerts
Multi-cloud resource management compatible with AWS, Azure, and GCP
Compatible with Kubernetes, Docker, and OpenShift
Rule management and traffic policy control
AD sync, user & group management
VPN server config and user access provisioning
24/7 infrastructure monitoring with alerting
Automated server/peer management with QR configs and tunnel health monitoring
Server health monitoring, active alarms dashboard, and configurable alarm rules with escalation
Complete device inventory with real-time status, health checks, and lifecycle tracking
Data classification, retention policies, encryption tracking, and storage alerts
Software inventory, patch management, device groups, and threat event tracking
SSH-based patch scanning across Linux servers — surfaces missing updates and security patches with severity reporting
Enroll, track, and report compliance for Android and iOS fleet devices with policy-based encryption and passcode requirements
SSH-based collection of CPU, memory, disk, network, and Docker stats — no agent install required
Discover, document, and audit Active Directory GPOs with linked-OU mapping
Versioned running-config backups for switches, routers, and firewalls with diff history
Real-time security posture and threat overview
Scan, prioritize, and remediate vulnerabilities
LLM-assisted analysis of pentest findings with MITRE ATT&CK mapping and remediation guidance
Multi-framework compliance tracking and scoring
Automated compliance gap detection
Conversational AI for compliance guidance
Policy creation, approval, and enforcement
External vs internal security assessment comparison
Automated pen tests with scheduling, Big 4-style professional PDF audit reports
Security audit for 12+ firewall vendors with rule analysis and firmware checks
Multi-factor authentication (TOTP, SMS, Email)
Role-based access control with granular permissions
Near real-time NetFlow v5/v9, IPFIX, and sFlow ingestion with 21 seeded detection rules across 17 categories (port scan, C2, lateral movement, DNS tunnelling, exfiltration, brute force, …) and MITRE ATT&CK mapping
Multi-protocol flow ingestion (NetFlow v5/v9, IPFIX, sFlow) with configurable UDP listeners and 1-minute aggregation windows
Query and filter network flows by source/destination IP, port, protocol, and time range with paginated results and byte formatting
Port scan, C2 beaconing, lateral movement, DNS tunnelling, data exfiltration, and brute force detection with severity-based triage
Statistical baseline computation over 14-day windows for anomaly detection with automatic deviation scoring
Deep-dive IP analysis with classification (internal/external), traffic summary, peer communication mapping, and port risk profiling
MITRE ATT&CK matrix with 14 tactics and 51 pre-loaded techniques, coverage heatmap, and recommended detections per technique
Automatic correlation of related alerts by IP, time window, and attack pattern with confidence scoring and escalation to Security Events
Track audits, reviews, and compliance deadlines
Compatible with major ERM platforms including SAP GRC, ServiceNow, RSA Archer, MetricStream, and Galvanize
Centralized IAM with user provisioning, group policies, access reviews, and privilege management
Live CVE lookup against the NIST NVD API and on-demand CISA Known Exploited Vulnerabilities catalog
Unified threat-intel dashboard: live NVD CVE search, MITRE ATT&CK matrix (60+ pre-mapped techniques), and ATT&CK coverage heatmap
Centralised syslog collection plus scheduled WinRM/SSH event-log ingestion — with full-text search, per-source tracking, and configurable retention for compliance and forensic review
Configurable detection-rule engine over your AD event logs and syslog stream — define thresholds, time windows and severities; matches raise security events and notify admins automatically
Define physical zones with clearance levels, access methods, and occupancy limits
Badge-based access logging with entry/exit tracking and denial alerts
Temperature, humidity, and environmental monitoring with threshold alerts
Camera inventory with health monitoring, recording modes, and storage tracking
UPS, generators, and PDU monitoring with battery health and load tracking
Pre-registration, badge issuance, check-in/out, NDA tracking, and host notification
Report, investigate, and resolve physical security incidents with evidence tracking
Automated threshold breach detection with acknowledge/resolve workflows
RTO/RPO assessment, critical process identification, and dependency mapping
Disaster recovery plan creation, versioning, and activation workflows
Schedule and track tabletop, walkthrough, and full-scale DR exercises
Track database and system replication status with lag alerts
Backup verification, RTO/RPO compliance scoring, and gap analysis
Third-party vendor risk assessment and continuity dependency tracking
Primary and alternate site management with failover readiness tracking
Emergency contact lists, succession planning, and communication trees
Track, investigate, and resolve incidents
Change requests with approval workflows
Backup scheduling, status, and RTO/RPO tracking
Preventive maintenance scheduling and tracking
Automated onboarding/offboarding workflows
Multi-channel alerts (email, SMS, in-app)
Monitor SLA compliance and MTTR metrics
SMS/USSD integration for mobile alerts
Invoice generation, cost tracking, budget management, and vendor billing reconciliation
Guided setup wizard for new tenants with step-by-step system configuration
Cross-module risk aggregation from security, compliance, BC, and vendor assessments
Software catalog, license compliance, vulnerability tracking, and application change history
Per-endpoint latency, throughput, peak times, slowest endpoints, with CSV/PDF export
Drag-and-drop custom dashboards with widget library and role-scoped sharing
Cross-module omnibox: assets, tickets, users, policies, incidents, vendors — all in one query
Searchable documentation with versioning
Custom reports with PDF/Excel export
Immutable audit trail for all actions
Courses, quizzes, and certificates
Auto-generated documentation for 1,263 endpoints across 78 feature areas
Flutter-based mobile app (Android APK shipping, iOS build in progress) for tickets, alerts, monitoring, and notifications on the go
Visual workflow builder with triggers and actions
5-Why, Fishbone, and Fault Tree analysis
Rule-based failure-risk scoring across systems and assets with cross-module risk factor aggregation
Flags traffic and metric values that fall outside learned hourly/weekday baselines
On-prem Retrieval-Augmented Generation over your policies, powered by a self-hosted Llama 3.1 model — no data leaves your environment
Elasticsearch-powered vector search with 384-dim embeddings for policies and documents
ClickHouse-powered analytics for policies, audit logs, and compliance metrics
Prometheus metrics with 4 dashboards, 10+ business KPI gauges, and embedded monitoring
Self-hosted LLM generates phased plans for ISO 27001, GDPR, SOC 2, NIST, PCI DSS with milestones and tasks — on-prem, zero data egress
Natural-language Q&A over your indexed policies with cited sources, powered by a locally-hosted Llama 3.1 model
Production-ready infrastructure with the operational guarantees enterprise IT departments expect
Machine-readable logs with request correlation IDs propagated across async boundaries
X-Request-ID header propagation through every service call for end-to-end observability
Strict CSP, HSTS, X-Frame-Options, and Referrer-Policy enforced on every response
Dedicated /health/live and /health/ready probes for orchestrator integration
Sub-millisecond cache for dashboard data, expensive aggregations, and ML embeddings
Redis-backed per-tenant API rate limits with graceful degradation under load
Alembic-managed schema migrations with rollback support and automated baseline creation
pytest + pytest-asyncio with coverage reporting, fixtures, and CI-friendly assertions
10 live business metrics — open tickets, SLA breaches, vulnerabilities, compliance score, incidents
Built on async SQLAlchemy + asyncpg for high-concurrency throughput on commodity hardware
Dense-vector cosine search over policies and documents with all-MiniLM-L6-v2 embeddings
Columnar analytics warehouse for compliance metrics, audit trails, and trend reporting at scale
9 frameworks, AI-powered gap analysis, automated evidence collection, and audit-ready reporting
LLM-driven gap analysis against 9 built-in frameworks (Zambia DPA, ISO 27001, NIST CSF, PCI DSS, SOC 2, GDPR, HIPAA, CIS v8, CIS Critical). Identifies gaps, scores coverage, and produces a prioritised remediation plan — runs entirely on your self-hosted Llama 3.1 model.
AI maps your existing controls to framework requirements with confidence scoring. Review, approve, or adjust mappings with one click.
Pull evidence from cloud providers, repositories, and internal systems. Timeline tracking and automated export for auditors.
AI-scored readiness assessment with checklist, score breakdown by domain, and prioritized remediation plan for each framework.
Ask compliance questions in natural language. RAG-powered responses cite specific policies and controls from your governance documents.
Discover security findings from integrated sources. AI assesses severity, suggests fixes, and tracks resolution progress automatically.
Pre-built controls, automated mapping, and evidence templates for each
AI generates step-by-step compliance roadmaps with timelines and task tracking
Schedule audits, reviews, and deadlines with automated reminders
Works with Azure, AWS, GitHub, and hosting providers for automated discovery
Generate complete audit evidence packages ready for external auditors
End-to-end DPC readiness — registration, processing records, impact assessments, consent, breach notification, data-subject rights, and the ICT-inventory self-assessment — all in one place.
Track your controller/processor registration with the DPC — certificate number, status and renewal deadline — plus your appointed Data Protection Officer, with automatic renewal reminders.
Auto-generate the ICT asset inventory the DPC requires from your live asset register and export it for submission to inventory.dataprotection.gov.zm — no more manual Excel.
Maintain an organization-wide s.45 register of processing activities — purpose, lawful basis, data categories, recipients, retention and safeguards — with one-click CSV export.
Run DPIAs for high-risk processing with risk scoring, mitigations, residual-risk rating and DPO sign-off — the evidence regulators expect.
Capture and withdraw consent with full evidence, and action access / erasure (DSAR) requests with statutory deadline tracking and one-click anonymisation.
Log personal-data breaches with an automatic 72-hour DPC notification deadline, overdue alerts, and a full record of who was notified and when.
Register international transfers with their lawful mechanism and safeguards, and evidence in-Zambia storage of sensitive data (s.70–71).
A consolidated readiness report with a per-obligation checklist and live score — print or export the full evidence pack for management and the DPC.
See how fast your organization can achieve certification with ICTM
Import assets, users, and network inventory. Connect cloud providers and Active Directory. ICTM auto-discovers your infrastructure.
Select target frameworks (ISO 27001, SOC 2, etc.). AI scans your environment and identifies compliance gaps with prioritized remediation plans.
Deploy security controls, configure policies, set up monitoring. ICTM maps your existing controls to framework requirements automatically.
Automated evidence collection from cloud, repositories, and systems. AI generates policies and procedure documents tailored to your organization.
Run automated pen tests, firewall audits, and vulnerability scans. AI prioritizes findings and tracks remediation progress.
Deploy mandatory security awareness courses via built-in LMS. Track completion, issue certificates, and generate training evidence.
Generate audit-ready evidence packages. AI scores readiness across all domains. Export professional reports for external auditors.
A clear, repeatable workflow that takes your organization from initial setup to continuous compliance
Connect your infrastructure and auto-discover all assets, then assess your security posture.
Enforce policies, manage changes, and close gaps with guided remediation across all frameworks.
24/7 monitoring, AI-powered analytics, and continuous compliance with automated workflows.
See the real impact of automation on your IT operations
Hear from ICT leaders across Africa who rely on Ontech Solutions
Multi-layered security built into every component, from authentication to encryption, from real-time monitoring to automated compliance enforcement
Near real-time Network Detection & Response with optional OSINT enrichment (bring-your-own API keys).
Automated vulnerability assessment with ZAP-equivalent detection, calibration benchmarking, and formal rectification reporting.
All credentials and sensitive data encrypted at rest. TLS enforced for all communications.
Automatic IP and domain reputation checks against global threat databases for every alert, finding, and investigation.
Monitor servers, networks, devices, cloud resources, and VPN tunnels from a single dashboard -- with alerting built in
CPU, memory, disk, and process monitoring across all servers
Real-TimeTopology mapping, bandwidth, latency, and device health
24/7AWS, Azure, GCP resource inventory, costs, and utilization
Multi-CloudTunnel status, peer monitoring, and tenant-isolated VPN management
EncryptedNatural-language compliance chat, semantic policy search, and statistical analytics — powered by self-hosted models. No prompts or data ever leave your environment.
Vector-powered search across all your governance documents. Find relevant policies by meaning, not just keywords.
Ask questions in plain English and get answers grounded in your actual policies and controls. Self-hosted Llama 3.1 8B model with local MiniLM embeddings — zero data egress, sovereign-cloud ready.
Rule-based failure-risk scoring that aggregates signals across systems, assets, security findings, and compliance gaps into a single risk score per entity.
Learns hourly and weekday traffic-and-metric baselines, then flags values that exceed configurable standard-deviation thresholds. Backed by 21 seeded NDR detection rules out of the box.
Complete BC/DR planning with 9 integrated modules for disaster preparedness, recovery testing, and business impact analysis
Manage primary and disaster recovery sites with automated failover configuration and geographic redundancy mapping
Real-time and scheduled data replication monitoring with RPO/RTO tracking and cross-site sync verification
Create, version, and test recovery plans with automated runbook generation and team assignment workflows
Schedule and execute disaster recovery drills with automated scoring, gap identification, and compliance reporting
Assess criticality of business processes, identify dependencies, and calculate recovery time objectives
Centralized risk register with likelihood/impact scoring, mitigation tracking, and heat map visualization
Built-in LMS for security awareness training, compliance courses, and organizational knowledge sharing
Role-based training modules with phishing simulations, security best practices, and compliance requirements
Track employee certifications, auto-assign required courses, and generate compliance evidence for auditors
Searchable documentation repository with version control, department categorization, and access controls
Guided onboarding workflows with automated account provisioning, training assignment, and equipment requests
Built-in quiz engine with multiple question types, passing scores, and automatic certificate generation
Everything you need to know about ICTM
Enterprise ICT Management is a comprehensive solution for managing all aspects of your organization's ICT infrastructure, including assets, networks, security, compliance, and governance. ICTM provides 50+ integrated modules in a single platform.
Yes, we implement ISO 27001 security standards, with AES-256 encryption at rest and in transit, 6-tier RBAC, MFA, regular security audits, and compliance with international data protection regulations.
ICTM supports ISO 27001, GDPR, SOC 2, HIPAA, PCI DSS, NIST CSF, ISO 27017, and ISO 27018. Our AI-powered engine automates gap analysis, evidence collection, and audit preparation across all frameworks.
Yes! ICTM is available as a cloud-hosted SaaS, on-premises installation, or air-gapped deployment for sensitive environments. Contact us for ISO download and deployment options.
Yes, we provide REST APIs and support integration with Active Directory, ServiceNow, JIRA, SAP GRC, RSA Archer, AWS, Azure, GCP, Prometheus, Grafana, and more.
We provide email and phone support, with priority support for Professional plans. Enterprise customers get a dedicated support manager. Dial *388# or contact info@ontech.co.zm.
Have questions? Our team is ready to help you find the right solution.
Whether you need a product demo, have a technical question, or want to explore enterprise options — we're here to help.
Thank you for reaching out. We'll get back to you within 24 hours.
Start managing your infrastructure with 73+ integrated modules, AI-powered compliance, and enterprise-grade security.