Ontech ICTM by industry

ICT Management for Telecoms Operators in Zambia

Server hardware alarms, traffic-flow threat detection, IP address management and firewall audits for the IT and security teams behind the network.

How can telecoms operators in Zambia manage enterprise ICT and security?

Telecoms operators manage their enterprise ICT by monitoring data-centre server hardware, analysing traffic flows for threats, keeping IP address plans and device configurations under control and auditing firewall rules. ICT is a critical sector under Zambia's Cyber Security Act, 2025. Ontech ICTM supports the IT and security teams behind this work; it does not replace a network management or OSS platform.

Operators run large data centres, carry subscriber data and are a constant target for attackers. The Cyber Security Act, 2025 lists information and communications technology as a critical sector, the Data Protection Act, 2021 applies to subscriber personal data, and ZICTA regulates the sector under the Information and Communication Technologies Act, 2009.

Ontech ICTM covers the enterprise IT and security side of an operator: the servers in the data centre, the traffic crossing corporate networks, address plans, device configurations and firewall rule sets. Radio access and core network elements stay with your network management systems.

ICT challenges in telecommunications

Hardware faults found late

Overheating, failing fans or power supplies in data-centre servers go unnoticed until a service degrades.

Threats hidden in traffic volume

Scanning, beaconing and data exfiltration are hard to spot in the sheer volume of corporate network traffic.

Address and configuration drift

IP plans live in spreadsheets, conflicts appear, and nobody has a current backup of a device configuration when it is needed.

Firewall rule sprawl

Rule sets across several firewall vendors accumulate overly permissive rules that nobody reviews.

Subscriber privacy

Security monitoring must not become an uncontrolled store of subscriber personal data.

How telecommunications organisations use ICTM

Data-centre server hardware alarms

Server management controllers are polled over Redfish or IPMI with threshold rules; alarms can be acknowledged, suppressed, escalated and auto-resolved, in the style of a network operations centre.

Flow-based threat detection

NetFlow, IPFIX and sFlow records are analysed for port scans, command-and-control beaconing, lateral movement, DNS tunnelling, exfiltration and brute-force attempts.

Privacy controls for monitoring data

IP addresses in flow records can be pseudonymised, a person's flow records can be purged on request, and data is deleted on a category-based retention schedule.

IP address management

Subnets and allocations are tracked with conflict detection, and ping sweeps record the hosts found with their MAC addresses and hostnames.

Device configuration backups

Running configurations are pulled over SSH and stored, so a known-good configuration is available after a failure or a bad change.

Multi-vendor firewall audits

FortiGate, Palo Alto, Cisco ASA, pfSense and iptables rule sets are checked, scored and reported with AI commentary.

Threat intelligence enrichment

Suspicious addresses and domains are enriched from Shodan InternetDB, AbuseIPDB, VirusTotal, GreyNoise and AlienVault OTX, and vulnerabilities are matched against the CISA Known Exploited Vulnerabilities catalog.

Regulation that applies

Summaries based on the primary legislation and regulator publications. See the linked Zambia pages for detail and sources — this is general information, not legal advice.

Cyber Security Act No. 3 of 2025

Lists information and communications technology as a critical sector (s.8). The Zambia Cyber Security Agency designates critical information infrastructure by Gazette notice (s.9); a controller of designated infrastructure must file a preliminary cyber incident report within twelve hours (s.17). Providing cyber security services requires a licence (s.42). The Act repealed the Cyber Security and Cyber Crimes Act, 2021 (s.73).

Information and Communication Technologies Act No. 15 of 2009

Continues the Communications Authority as the Zambia Information and Communications Technology Authority (ZICTA), the sector regulator (s.4).

Data Protection Act No. 3 of 2021

Data controllers and processors must register with the Data Protection Commissioner (s.19), appoint a data protection officer (s.48), notify the Commissioner within twenty-four hours of a security breach (s.49), and process and store personal data on a server or data centre in Zambia unless an exception applies (s.70).

What ICTM covers — and what it doesn't

ICTM's hardware alarms come from server baseboard management controllers, not from radio-access or other network elements. ICTM is not an OSS or network management system and does not collect interface counters from network elements; it covers the enterprise IT and security operations around the network.

Benefits

Earlier hardware warnings

Server faults raise alarms from the hardware itself, before a service degrades.

Threats surfaced from flows

Known attack patterns are detected from flow data without full packet capture.

Controlled address space

Subnet allocations and conflicts are tracked in one place.

Configurations you can restore

Device configurations are backed up over SSH.

Privacy by design

Flow data can be pseudonymised and deleted on a retention schedule.

Rolling out ICTM

  1. Scope modules and roles

    Run ICTM as a hosted service or on servers you control, then set up role-based access so each team sees only the modules it needs.

  2. Connect data-centre hardware

    Add the Redfish or IPMI management interfaces of your servers and set alarm thresholds and escalation.

  3. Send flow data

    Point NetFlow, IPFIX or sFlow exporters at ICTM's collector and enable the detection rules you need.

  4. Record address space and devices

    Add subnets and allocations, run ping sweeps and add SSH credentials for configuration backups.

  5. Audit and review

    Upload firewall configurations for rule audits and map controls to the ISO/IEC 27001 or NIST CSF 2.0 control sets.

Frequently asked questions

Can ICTM receive alarms from base stations or other network elements?

No. ICTM's hardware alarms come from the baseboard management controllers of servers, polled over Redfish or IPMI, covering Dell iDRAC, HPE iLO, Lenovo XCC, Cisco CIMC and Supermicro. Radio-access and core network element alarms stay in your network management systems; ICTM covers the data-centre servers and enterprise IT around them.

Which flow formats does ICTM's network detection accept?

ICTM's network detection and response collector accepts NetFlow v5 and v9, IPFIX and sFlow v5. Detection rules look for port scans, command-and-control beaconing, lateral movement, DNS tunnelling, data exfiltration and brute-force attempts, and findings can be enriched with threat-intelligence sources and mapped to MITRE ATT&CK techniques.

How does ICTM handle subscriber privacy in flow data?

IP addresses in flow records can be pseudonymised with a keyed hash, subject access and erasure requests can purge a person's flow records, and a scheduled job deletes data by category: flows after 30 days, alerts after 180 days and baselines after 365 days. This supports the Data Protection Act's principles for security monitoring data.

Is ICT a critical sector under Zambia's Cyber Security Act, 2025?

Yes. Section 8 lists information and communications technology among the critical sectors. The Zambia Cyber Security Agency designates specific critical information infrastructure by Gazette notice (section 9), and a controller of designated infrastructure must file a preliminary cyber incident report within twelve hours (section 17). The Act repealed the 2021 Cyber Security and Cyber Crimes Act.

Can ICTM audit firewall configurations from different vendors?

Yes. ICTM parses rule sets from FortiGate, Palo Alto, Cisco ASA, pfSense and iptables, runs a fixed set of twelve rule checks, such as overly permissive rules, scores the result and produces a PDF report with AI commentary. For FortiGate it can also read live resource statistics and traffic logs.

See how telecommunications teams use Ontech ICTM

Book a walkthrough with the Ontech team, or start a free trial and explore the platform yourself.