Cybersecurity and MXDR
Identity and access, detection, security operations and compliance reporting on the Microsoft security stack. We put it in place where it is missing, switch on what you already own, then operate it and keep the record — so your posture holds up when a regulator asks.
What the service covers
Identity and access, detection and response, security operations and compliance reporting, on the Microsoft security stack.
- Identity and access
- Entra ID posture review, directory health, privileged accounts, user lifecycle, entitlements.
- Detection and response
- Microsoft Defender XDR deployment, Microsoft Sentinel monitoring and alert review, M365 incident response assistance.
- Operations and compliance
- Microsoft Purview, device management through Intune, vulnerability remediation, Secure Score review and remediation.
- Trajectory
- Zero Trust assessment and the roadmap that follows it.
Your obligations, not ours
A UEMOA financial institution must satisfy BCEAO and Commission Bancaire requirements on outsourcing, control and security — risk management in credit institutions and financial companies of the UMOA is governed by Commission Bancaire circular N°04-2017/CB/C. A data controller in Côte d’Ivoire answers to ARTCI. Those obligations are yours. Our job is to produce the evidence you will have to present, and to keep it current.
Who watches, and from where
Onshore Managed MXDR provides monitoring, detection, investigation and response across the Microsoft security ecosystem — Microsoft Defender, Microsoft Sentinel, identity and cloud security. Coverage, escalation paths, response objectives and operational responsibilities are defined at scoping, against your risk profile, your compliance obligations and your own staffing.
The security operations centre function belongs to the Onshore group and is operated from the United States. Onshore Africa operates no security operations centre in Africa and claims none.
The CISO’s questions, answered in this order
- Where the data sits, and under which legal regime
- Who accesses it, with what rights, and how that access is logged
- Which subcontractors are involved — and they are declared
- What evidence is produced, how often, and in what form
- Who answers during an incident, and through which escalation chain
The boundaries, stated up front
We are neither a certification body nor an auditor: we produce the material an auditor examines. We claim no data sovereignty; we document the applicable regime and leave the decision that follows to you and your advisers.
Tell us where the gap is. A person reads every message and replies.