Skip to main content

SERVICE LINE

Cybersecurity & Compliance

A 24/7 security operations centre in Kano, staffed by Nigerian analysts watching Nigerian threats. Monitoring, testing, incident response and the compliance evidence your regulator and your board will both ask for.

Defence that is watched, tested and evidenced

Zainab Idris Kabo, Director of Cybersecurity & Compliance, leads a practice of twenty-nine analysts, testers and compliance specialists built around a security operations centre that runs from our Kano headquarters every hour of every day. The SOC exists because detection cannot be outsourced to a time zone that is asleep when Nigerian business hours begin, and because the threats our clients face are specific: business email compromise aimed at procurement departments, credential theft against bank staff, ransomware delivered through unpatched remote access, insider misuse of citizen records, and payment fraud that exploits the gap between a collection system and a reconciliation process.

The technical service is built on a security information and event management platform ingesting logs from endpoints, servers, firewalls, network devices, identity providers and business applications, correlated against threat intelligence and tuned continuously to the client environment. Endpoint detection and response agents give analysts the ability to isolate a compromised machine within minutes rather than dispatching an engineer. Vulnerability management runs on a scheduled cycle with risk-ranked remediation tracked to closure, not merely reported. Penetration testing and phishing simulation tell you what an attacker would actually achieve, rather than what a scanner thinks is theoretically possible.

Compliance work sits in the same practice deliberately, because a control that is not operating is not a control. We take organisations through ISO/IEC 27001:2022 implementation and certification, readiness for the Nigeria Data Protection Act and the NDPR framework, alignment with Central Bank of Nigeria risk-based cybersecurity guidelines for banks and other financial institutions, and NITDA guidance for public bodies. We hold ISO/IEC 27001:2022 certification ourselves, which means the evidence we ask clients to produce is evidence we produce for our own auditors first.

Security services

Buy the whole programme or the single capability you are missing. Every service produces evidence you can put in front of an auditor.

24/7 SOC and SIEM

Kano, round the clock

Continuous log collection, correlation and triage by named analysts, with tuned detection rules, threat intelligence enrichment and a monthly detection-coverage report.

Endpoint detection and response

Contain in minutes

Behavioural detection on servers, laptops and virtual desktops, with remote isolation, process termination, forensic capture and rollback of ransomware encryption where supported.

Vulnerability management

Tracked to closure

Authenticated scanning of internal and internet-facing assets, risk-ranked findings by exploitability and business impact, remediation SLAs and verification rescans.

Penetration testing

CREST-aligned method

External, internal, web application, mobile application, API and wireless testing, with proof-of-exploit evidence, a prioritised remediation plan and a free retest within 90 days.

Phishing simulation and awareness

Behaviour, not slideware

Realistic simulated campaigns in English and Hausa, click and report metrics by department, and targeted micro-training for the people who need it most.

Compliance and certification

ISO 27001, NDPA, CBN, NITDA

Gap assessment, risk treatment plan, policy suite, control implementation, internal audit, management review and support through the certification audit itself.

SOC service tiers and response targets

Response time is measured from alert triage to first analyst contact with the client. Targets are contractual, with service credits where they are missed. Monthly pricing is indicative for a mid-sized estate and excludes VAT.

Tier Coverage Critical alert response High alert response Indicative monthly fee
Watch Business hours, 08:00–18:00 Monday to Friday, log monitoring and monthly reporting 30 minutes 2 hours ₦1,850,000
Guard 24/7 monitoring and triage, endpoint detection, quarterly vulnerability scanning 15 minutes 1 hour ₦4,200,000
Sentinel 24/7 monitoring with active containment, monthly scanning, threat hunting, annual penetration test 10 minutes 30 minutes ₦7,600,000
Sentinel Plus All of Sentinel plus a retained incident response team, forensic readiness and named on-site security manager 5 minutes 20 minutes ₦12,900,000

Incident response, stage by stage

Our process follows NIST SP 800-61 and is rehearsed with clients through tabletop exercises before it is ever needed in earnest.

1

Prepare

Before anything happens: an agreed incident response plan, a contact tree that includes legal and communications, pre-authorised containment actions, forensic tooling staged in the environment, and at least one tabletop exercise a year with the executive team present.

2

Detect and triage

An alert is validated by a SOC analyst against the client baseline, classified by severity, and either closed as benign with a tuning note or escalated. Escalation starts the response clock and notifies the client contact by telephone as well as by ticket.

3

Contain

Immediate action to stop spread — isolating endpoints, disabling accounts, blocking indicators at the firewall and proxy, revoking sessions and tokens. Where pre-authorisation exists we act first and inform; otherwise we recommend and wait for the client decision, which is why pre-authorisation matters.

4

Eradicate

Identify and remove the root cause: the unpatched service, the exposed credential, the malicious persistence mechanism, the misconfigured rule. Forensic images are preserved before remediation so that later analysis and any legal process remain possible.

5

Recover

Restore systems from known-good backups, rebuild rather than clean where confidence is low, reset credentials at scale, and monitor the recovered environment at heightened sensitivity for a defined period before returning to normal operation.

6

Learn

A written post-incident review within ten working days covering timeline, root cause, what worked, what did not, and dated remediation actions with named owners. Detection rules are updated and the tabletop scenario library is extended with the real event.

The security practice

24/7

SOC coverage

Operated from Kano, all year

29

Security specialists

Analysts, testers and compliance leads

12,000+

Protected endpoints

Under monitoring across clients

10 min

Critical response target

Sentinel tier and above

Frequently asked questions

Where is our data held when you monitor us?
Log and telemetry data for Nigerian clients is stored in our Kano facility with replication to a second Nigerian site. Nothing leaves the country without a written data residency assessment and the client’s explicit instruction. Retention is set contractually, typically twelve months of searchable data with longer cold retention where a regulator requires it, and the client may take a full export at any point during the contract or on exit.
Do we need to replace our existing security tools?
Usually not. The SOC ingests from what you already own — Fortinet, Palo Alto, Cisco, Sophos, Microsoft Defender, Active Directory, your firewalls and your business applications. We will tell you honestly if a product genuinely cannot produce usable telemetry, but the more common finding is that clients own good tools that were never configured to log anything useful. Fixing that is part of onboarding.
How long does ISO 27001 certification take?
For an organisation starting from scratch, expect nine to fourteen months to certification: roughly two months of gap assessment and scoping, four to seven months of control implementation, three months of operating the system to generate audit evidence, then Stage 1 and Stage 2 audits by an accredited certification body. Organisations with mature IT governance sometimes reach certification in seven months. We do not promise faster, because the auditor will want evidence of controls actually operating over time. Our own certifications are listed at /about/certifications.
What is included in a penetration test report?
An executive summary written for a board, a technical findings section with reproduction steps and evidence for every issue, a risk rating using CVSS alongside a business-impact judgement, a prioritised remediation plan with realistic effort estimates, and an appendix listing scope, methodology, tooling and testing windows. One free retest of remediated findings is included within ninety days.
Can you help after a breach has already happened?
Yes. We take emergency incident response engagements from organisations who are not existing clients, subject to capacity. Call +234 803 047 9666 and ask for the SOC duty manager, or write to [email protected]. We will agree scope and mobilise remotely within hours, with an on-site team in Kano, Abuja or Lagos typically the same or next day. Retained clients always take priority, which is an argument for the retainer.
How do you align with CBN and NITDA expectations?
For financial institutions we map controls against the Central Bank of Nigeria risk-based cybersecurity framework, including board reporting, cyber risk assessment, incident reporting timelines and the annual independent review. For public bodies we work to NITDA guidelines and the Nigeria Data Protection Act. Both mappings are delivered as a control mapping table that shows, for each requirement, the implementing control, the evidence and the owner.

Responsible disclosure

If you believe you have found a security vulnerability in a system operated by Brilliant Esystems Limited, or in software we have published, please report it to [email protected]. Include enough detail to reproduce the issue, and please do not access, modify or exfiltrate data belonging to us or to our clients while investigating.

We acknowledge every report within one working day, provide an initial assessment within five working days, and keep the reporter informed until the issue is closed. Researchers who report in good faith and give us reasonable time to remediate will not face legal action from us, and with permission we credit them in our advisory. Encrypted correspondence is welcome; request our PGP key at the same address.

Find out what an attacker would see

Start with an external attack-surface assessment and a compliance gap review. Both take under three weeks and give Zainab Kabo’s team enough to tell you where the genuine risk sits — and what it costs to close it.