Critical Infrastructure

Some intruders wait years before they act.

Schedule a meeting

Essential entities under NIS2, SOCI and the CER Directive

Security for the systems everyone depends on

Keep a signed copy of every log and see when an account stops acting like itself.

Guidance

GuidanceWhat it asksARRTECH
Living off the land guide, 2024Baselines of tools, accounts and traffic.Detection baselines every user, host and application. →
Living off the land guide, 2024UEBA across multiple data sources.SIEM UEBA and cross-source correlation. →
Event logging guide, 2024Protect logs from modification and deletion.Signed, chained logs; a change is detected. →
NCSC CAF C1.bAnalysis on copies, master unaltered.Detection reads a copy of the SIEM export. →
NIS2Evidence on request.Case timelines and signed exports. →

Volt Typhoon

Find attackers living off the land

Volt Typhoon hid in US infrastructure networks for years by using the admin tools already installed. Cyberdroid AI Detection compares every account and host with its own normal behavior, so familiar tools used in an unusual way stand out.

NCSC CAF C1.b

Keep logs attackers cannot quietly erase

The NCSC Cyber Assessment Framework asks you to protect logs from change and to analyze copies, not the originals. ARRTECH signs every log and copies it centrally, so a deleted or changed entry shows up.

NIS2 Article 23

Report on time under NIS2

NIS2 Article 23 requires an early warning within 24 hours of a significant incident, a notification within 72 hours and a final report within one month. Each ARRTECH SIEM case keeps the full timeline from the first alert, so every report draws on the same record.

Telemetry health

Know when your evidence has gaps

An empty week of alerts can mean a quiet week or a broken data feed. Cyberdroid AI Detection reports the health of its data next to every result, and ARRTECH SIEM alerts when a log source goes silent.

By rule

Living off the land guide, 2024

Baselines of tools, accounts and traffic. ARRTECH: Detection baselines every user, host and application.

Living off the land guide, 2024

UEBA across multiple data sources. ARRTECH: SIEM UEBA and cross-source correlation.

Event logging guide, 2024

Protect logs from modification and deletion. ARRTECH: Signed, chained logs; a change is detected.

NIS2

Evidence on request. ARRTECH: Case timelines and signed exports.

Questions

Would we know if evidence were missing?

Yes. Cyberdroid AI Detection reports the health of its data next to every result, so you can tell a quiet week from a gap in the data. ARRTECH SIEM also alerts when a log source goes silent.

Can we show the regulator a timeline in time?

Each SIEM case keeps its full history and the stage of the attack, and downloads as a report.

Who acts?

A person. ARRTECH SOAR emails the approver up to five options and waits. The history shows who chose what and when.

What stays with you?

Reporting to your authority, and anything at the level of the control systems themselves. ARRTECH cannot promise when an attack will be detected or reported.

Sources

Guide

What is NIS2 and who must comply?

NIS2 is the EU directive for essential and important entities in energy, transport, health, water and digital infrastructure. It requires a 24-hour early warning and 72-hour notification.

How do you detect living off the land attacks?

Attackers like Volt Typhoon use your own admin tools. Detection depends on knowing each account’s normal behavior and flagging what changes.

What logging does critical infrastructure need?

Central, protected logs that show any modification, as the NCSC CAF and joint government guidance recommend.

Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Available now

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Early access

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

See every system. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.