What is cybersecurity management?
Cybersecurity management is the continuous cycle of identifying an organisation's technology risks, protecting systems, detecting threats and responding to incidents, with clear ownership and evidence. Ontech ICTM brings that cycle into one platform: vulnerability scanning and penetration testing, flow-based network detection, log collection, CVE and CISA KEV intelligence, MITRE ATT&CK mapping and access reviews.
Security teams are rarely short of tools; they are short of a joined-up view. Scan results sit in one report, access reviews in a spreadsheet, network alerts in a console and incidents in email, which makes it hard to prioritise and harder to prove to auditors what was fixed.
ICTM brings testing, detection, intelligence and access control together and ties findings to the assets they affect. Vulnerabilities are matched against the CISA Known Exploited Vulnerabilities catalogue on a schedule, findings carry remediation deadlines by severity, and detections and findings are mapped to MITRE ATT&CK so coverage gaps are visible.
Security work also feeds the rest of the platform: findings contribute to the unified risk score, provide evidence for compliance controls and inform business continuity planning. AI assistance for remediation and patch suggestions can run on a locally hosted model and is advisory.
What ICTM does for cybersecurity management
Vulnerability scanning
Run nmap port, service-version and SSL/header scans, match detected service versions to known CVEs, schedule recurring scans and track each finding against a remediation deadline set by severity.
Web application testing
Built-in probes check web applications for issues such as SQL and command injection, cross-site scripting, file inclusion, SSRF, XXE, JWT weaknesses, CORS and open redirects, and secrets or vulnerable libraries exposed in JavaScript.
Authenticated, role-by-role testing
Log in as each role you supply and test for broken access control, insecure direct object references and privilege escalation — the flaws unauthenticated scans cannot see.
Network detection and response
Analyse NetFlow v5/v9, IPFIX and sFlow records for port scans, command-and-control beaconing, lateral movement, DNS tunnelling, data exfiltration and brute-force behaviour.
Security log collection
Receive syslog (RFC 3164 and 5424), pull Windows event logs over WinRM and Linux authentication logs over SSH, and turn matching events into security events with configurable threshold rules.
Threat intelligence
Look up CVEs through the NVD API, refresh the CISA KEV catalogue and match it against your vulnerabilities on a schedule, and enrich IPs and domains from Shodan InternetDB, AbuseIPDB, VirusTotal, GreyNoise and AlienVault OTX.
MITRE ATT&CK mapping
Map findings, security events and audit actions onto a built-in ATT&CK matrix and view a coverage heat map showing which tactics and techniques you can and cannot see.
Identity and access management
Enforce password and lockout policy, find dormant and orphaned accounts with scheduled auto-disable, grant time-limited privilege elevation with approval, and review access from Active Directory data synchronised over LDAP.
Configuration hygiene
List pending Linux updates over SSH, audit firewall rule sets from five vendors, run SSH-based Linux hardening audits and check email domains for SPF and DMARC records.
Incidents and security awareness
Record incidents with severity and SLA-breach flags and export them, and run awareness courses with quizzes, mandatory-course enrolment and certificate tracking in the built-in learning module.
ICTM modules: Security Dashboard · Penetration Testing · Authenticated Pentest · Network Detection & Response · Log Aggregation · Threat Intelligence · CVE Database · KEV Catalog · MITRE ATT&CK · ATT&CK Coverage · OSINT · Patch Management · Firewall · Identity & Access (IAM) · Active Directory · Training
Use cases
Pre-audit vulnerability assessment
Scan internal and external systems ahead of an ISO 27001 or PCI DSS assessment and track fixes to closure.
Testing a new web application
Probe a release for common web flaws and test each user role for access-control weaknesses before go-live.
Prioritising patching
Focus effort on vulnerabilities that appear in the CISA KEV catalogue because they are known to be exploited.
Quarterly access reviews
Identify dormant, orphaned and over-privileged accounts from directory data and remove access with a record of the decision.
Investigating suspicious traffic
Use flow detections and IP reputation lookups to decide whether a host needs isolating.
Benefits
Prioritised effort
Severity, exploit status and asset context help teams fix what matters first.
Evidence for auditors
Scan history, remediation deadlines, access reviews and exportable reports show controls operating over time.
Visibility of coverage
ATT&CK mapping shows which attacker behaviours you can detect and where the blind spots are.
Less tool sprawl
Testing, detection, intelligence and access control share one platform and one set of asset records.
Frequently asked questions
How does ICTM prioritise vulnerabilities?
Each finding has a severity and a remediation deadline set by that severity. ICTM also uses the CISA Known Exploited Vulnerabilities catalogue (cached for up to six hours) and matches it against your vulnerabilities on a schedule, so issues known to be exploited in the wild stand out from the long tail of theoretical risks.
Can ICTM test web applications that sit behind a login?
Yes. Authenticated testing logs in with the credentials you supply for each role and checks whether one role can reach another's data or functions — broken access control, insecure direct object references and privilege escalation. Supplied credentials are encrypted at rest.
Does ICTM collect security logs?
ICTM receives syslog, pulls Windows security event logs over WinRM and Linux authentication logs over SSH, and applies threshold rules you configure to raise security events. It is a focused collector for security-relevant events rather than a general-purpose log search platform.
Which threat intelligence sources does ICTM use?
ICTM queries the NVD API for CVE details, uses the CISA Known Exploited Vulnerabilities catalogue, maps activity to MITRE ATT&CK, and enriches IP addresses and domains from Shodan InternetDB, AbuseIPDB, VirusTotal, GreyNoise and AlienVault OTX. AbuseIPDB and VirusTotal need your own API keys.
How is AI used in ICTM's security modules?
A language model, which can run locally alongside ICTM, drafts remediation and patch suggestions for pentest findings, summarises threat intelligence and adds commentary to firewall audits. Its output is advisory: security staff decide what to act on, and findings are based on the scans and data ICTM collected.
Do Zambian laws affect security testing?
Zambia's Cyber Security Act No. 3 of 2025 lists penetration testing and vulnerability assessment among cyber security services (s.41), and s.42 prohibits providing such services without a licence. Organisations testing their own systems, or engaging a provider to do so, should confirm their position with the Zambia Cyber Security Agency or a legal adviser.