Ontech ICTM platform

ICT management software that brings every IT discipline into one platform

Ontech ICTM gives IT, security, compliance and risk teams one system for the assets they run, the risks they carry and the evidence they must produce.

What does an ICT management platform do?

An ICT management platform gives an organisation one system for running and governing its technology. Ontech ICTM, developed by Ontech Solutions Limited in Lusaka, Zambia, combines IT asset management, infrastructure and network monitoring, cybersecurity, IT compliance, IT risk, business continuity and disaster recovery, IT governance and vendor management, so records, monitoring data and audit evidence live in one place.

Most organisations run their technology with a patchwork: an asset spreadsheet, a separate monitoring tool, security reports in email, compliance evidence in shared folders and continuity plans in documents nobody opens. Each works on its own, but none can answer cross-cutting questions such as which critical application depends on a single vendor, or which unpatched server holds personal data.

Enterprise ICT management software closes those gaps by putting the disciplines on a shared foundation. In ICTM the asset register is also a configuration management database, so the same record of a server is used by monitoring, vulnerability scanning, compliance, business impact analysis and change management. Data entered once is reused rather than copied between tools.

ICTM is web-based and role-based: an infrastructure engineer sees alarms and maintenance, a compliance officer sees control mappings and data-protection registers, and executives see a combined risk view. AI features can run on a locally hosted language model, so prompts and data need not leave your environment, and AI output is advisory and reviewed by people.

What Ontech ICTM covers

Each capability area has its own page explaining the discipline, what ICTM does and where it fits.

IT Asset Management

Know what you own, who has it, what it depends on and when it needs attention — in a register every other ICTM module uses.

Infrastructure Management

Watch server health, hardware alarms and service uptime without installing agents — and keep maintenance planned rather than reactive.

Network Monitoring

Know which devices are up, which addresses are in use, how devices are configured and what the traffic is doing.

Cybersecurity Management

Test your systems, watch your network and access, and keep every finding tracked to remediation in one platform.

IT Compliance Management

Map your controls to the frameworks you answer to, see where the gaps are, and keep Data Protection Act records in the same system as your IT estate.

IT Risk Management

Record IT risks once, score them consistently, assign mitigations to named owners, and see how incidents, compliance gaps and supplier dependencies add up.

Business Continuity Management

Work out which services matter most, how long you can be without them, and who does what when they fail — then keep the plans current.

Disaster Recovery & Backup Management

Run and schedule backups, see at a glance whether they are keeping up, and rehearse recovery against the targets your business has set.

IT Governance

Decide who may do what, write it down as policy, route decisions through the right approvers, and keep a record of every change.

IT Vendor Management

Know who supplies your technology, what you have agreed with them, and which services would stop if one of them failed.

How the modules work together

ICTM is one system rather than separate tools, so information recorded in one area is used in others.

Asset register to data-protection inventory

The ICT asset inventory used for a Zambia Data Protection Act self-assessment is built from the live asset register and exported as CSV, instead of being compiled by hand in a spreadsheet.

One risk score from many modules

Open incidents, compliance coverage, business continuity risk, security findings and vendor single points of failure are weighted into a unified risk score calculated from live data in each module.

Asset dependencies drive impact analysis

Dependencies recorded between assets and services let ICTM walk the chain and show what else is affected when a component fails or is scheduled for change.

Change requests through the approval engine

Requests for change carry a risk assessment and rollback plan and are routed through multi-stage approvals — any, all, majority or a set number of approvers — with delegation and escalation.

Vendors linked to the applications they support

In business continuity, each application records the vendors it depends on, flags single points of failure and feeds a concentration-risk analysis across your supplier base.

Network monitoring feeds data-protection records

Records of processing activities can import entries from the network-monitoring module, and flow data is pseudonymised and deleted on a retention schedule to respect data-protection principles.

AI analyses land in the knowledge base

Compliance gap analyses and other AI-assisted reports are published to the internal knowledge base automatically, so findings stay searchable after the meeting where they were discussed.

Who uses ICTM

IT managers and infrastructure teams

One view of assets, server health, hardware alarms, network availability, backups and maintenance windows.

CISOs and security teams

Vulnerability scanning, penetration testing, network detection, threat intelligence and access reviews with remediation tracking.

Compliance and data-protection officers

Framework control mappings, gap analysis, audit readiness and Zambia Data Protection Act registers in one workspace.

Risk and business continuity managers

Risk register, business impact analysis, continuity plans, DR exercises and vendor dependency risk.

Executives and heads of department

A combined picture of risk, compliance posture and infrastructure health without waiting for each team to assemble a report.

Internal and external auditors

Policy history, approval records, audit trails and exportable reports that show what was done, when and by whom.

Deployment, data and access

Web-based, hosted or on your servers

ICTM runs in a web browser. Ontech can host it for you, and it can be licensed for installation on infrastructure you control — confirm the options for your environment with Ontech.

Locally hosted AI

AI features call a language model that can run on the same server as ICTM, so compliance questions, security findings and plans need not be sent to an external AI service.

Role-based access

A six-level role hierarchy from Super Admin to Guest controls what each person can see and change, and individual permissions can be granted with an expiry date.

Multi-factor authentication

Users can protect their accounts with an authenticator app, including hashed backup codes, or with one-time codes sent by email or SMS.

Protected credentials and audit trail

Stored credentials such as SSH and directory passwords are encrypted at rest, and write actions are logged in an audit trail with a SHA-256 hash on each entry.

Frequently asked questions

How is ICT management software different from an ITSM tool?

IT service management (ITSM) tools focus on the service desk: tickets, incidents, requests and changes. ICT management software covers that and more. ICTM includes ticketing, incidents and change management, but also asset and configuration records, infrastructure and network monitoring, security testing, compliance, risk, business continuity and vendor management, so the service desk works from the same data as every other IT discipline.

Can ICTM be installed on-premises?

Yes, subject to licensing. Ontech can host ICTM for you, or ICTM can be licensed for installation on servers you control. Because the AI features can use a locally hosted language model, an on-premises installation can keep monitoring data, findings and compliance evidence inside your own environment. Ontech will confirm the requirements for your infrastructure during scoping.

Which compliance frameworks does ICTM support?

ICTM includes control sets for ISO/IEC 27001:2022, NIST CSF 2.0, PCI DSS 4.0, SOC 2, the HIPAA Security Rule, GDPR and CIS Controls v8, which you can map your own controls against. For Zambia it adds a scored self-assessment against the Data Protection Act No. 3 of 2021 and registers for data-protection work such as breaches, impact assessments and cross-border transfers.

How does ICTM use AI?

ICTM uses a language model for tasks such as compliance gap analysis, suggesting control mappings, drafting compliance roadmaps and business continuity plans, and commenting on firewall audits and hardware alarms. The model can run locally alongside ICTM. AI output is advisory: control mappings are reviewed and approved by a person before they count.

Is ICTM suitable for organisations in Zambia?

ICTM is developed by Ontech Solutions in Lusaka and includes features shaped by Zambian requirements: a Data Protection Act self-assessment referencing the relevant sections of Act No. 3 of 2021, registers for controller and processor registration, breaches and cross-border transfers, and tracking of whether data is stored in Zambia. It is equally usable for organisations working to international frameworks.

How can we evaluate ICTM?

You can start a free trial account from the ICTM website to explore the modules yourself, or request a guided demo where Ontech walks through the areas that matter to your organisation — for example asset management and monitoring for an IT team, or compliance and risk for a governance function.

See Ontech ICTM in action

Book a walkthrough with the Ontech team, or start a free trial and explore the platform yourself.