Security for the systems everyone depends on
Keep a signed copy of every log and see when an account stops acting like itself.
Guidance
| Guidance | What it asks | ARRTECH |
|---|---|---|
| Living off the land guide, 2024 | Baselines of tools, accounts and traffic. | Detection baselines every user, host and application. → |
| Living off the land guide, 2024 | UEBA across multiple data sources. | SIEM UEBA and cross-source correlation. → |
| Event logging guide, 2024 | Protect logs from modification and deletion. | Signed, chained logs; a change is detected. → |
| NCSC CAF C1.b | Analysis on copies, master unaltered. | Detection reads a copy of the SIEM export. → |
| NIS2 | Evidence on request. | Case timelines and signed exports. → |
Volt Typhoon
Find attackers living off the land
Volt Typhoon hid in US infrastructure networks for years by using the admin tools already installed. Cyberdroid AI Detection compares every account and host with its own normal behavior, so familiar tools used in an unusual way stand out.
NCSC CAF C1.b
Keep logs attackers cannot quietly erase
The NCSC Cyber Assessment Framework asks you to protect logs from change and to analyze copies, not the originals. ARRTECH signs every log and copies it centrally, so a deleted or changed entry shows up.
NIS2 Article 23
Report on time under NIS2
NIS2 Article 23 requires an early warning within 24 hours of a significant incident, a notification within 72 hours and a final report within one month. Each ARRTECH SIEM case keeps the full timeline from the first alert, so every report draws on the same record.
Telemetry health
Know when your evidence has gaps
An empty week of alerts can mean a quiet week or a broken data feed. Cyberdroid AI Detection reports the health of its data next to every result, and ARRTECH SIEM alerts when a log source goes silent.
By rule
Living off the land guide, 2024
Baselines of tools, accounts and traffic. ARRTECH: Detection baselines every user, host and application.
Living off the land guide, 2024
UEBA across multiple data sources. ARRTECH: SIEM UEBA and cross-source correlation.
Event logging guide, 2024
Protect logs from modification and deletion. ARRTECH: Signed, chained logs; a change is detected.
NIS2
Evidence on request. ARRTECH: Case timelines and signed exports.
Questions
Would we know if evidence were missing?
Yes. Cyberdroid AI Detection reports the health of its data next to every result, so you can tell a quiet week from a gap in the data. ARRTECH SIEM also alerts when a log source goes silent.
Can we show the regulator a timeline in time?
Each SIEM case keeps its full history and the stage of the attack, and downloads as a report.
Who acts?
A person. ARRTECH SOAR emails the approver up to five options and waits. The history shows who chose what and when.
What stays with you?
Reporting to your authority, and anything at the level of the control systems themselves. ARRTECH cannot promise when an attack will be detected or reported.
Sources
Guide
What is NIS2 and who must comply?
NIS2 is the EU directive for essential and important entities in energy, transport, health, water and digital infrastructure. It requires a 24-hour early warning and 72-hour notification.
How do you detect living off the land attacks?
Attackers like Volt Typhoon use your own admin tools. Detection depends on knowing each account’s normal behavior and flagging what changes.
What logging does critical infrastructure need?
Central, protected logs that show any modification, as the NCSC CAF and joint government guidance recommend.
Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

See every system. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.