AI DEFENCEBY ALTARI SYSTEMS
Menu

The operating model

From first inspection to continuous defence.

AI Defence is designed around a governed sequence: discover, audit, understand, correlate, explain, recommend, authorise, remediate, verify, baseline and continuously defend. The initial assessment gathers evidence; customer authorisation determines which changes may follow.

IN DEVELOPMENTExplore the specified scope. See capability availability.

01 / Discover and audit

Agree the authorised environment, access and assessment methods. Inventory hosts, workloads, services, identities and network paths, then inspect the applicable controls from the full assessment catalogue. The first-entry assessment is read-only by default.

Document inaccessible assets, unavailable checks and telemetry gaps alongside collected evidence. Comprehensive scope does not mean pretending that one collector can see every device, application or cloud account.

02 / Understand and correlate

Connect individual findings to system roles, dependencies and trust boundaries. Vulnerability severity, exploitability, exposure, privilege, business importance and compensating controls help determine priority.

An internet-facing vulnerable service running with elevated privilege may need urgent attention. The same advisory in an isolated test environment may call for a different response. Evidence quality and uncertainty remain part of that judgement.

03 / Explain and recommend

Produce the client report with an executive explanation, technical evidence and a prioritised work plan. Explain what was examined, what is secure or insecure, why each finding matters and the likely consequences of remediation.

Record expected downtime or dependency effects. A useful recommendation gives the customer enough information to decide what should change and what should wait.

04 / Authorise and remediate

The customer may approve the recommended bundle, selected actions, individual findings or no changes. Material operations need current-state checks, dependency and impact analysis, rollback preparation and preserved administrator connectivity.

Only supported, explicitly permitted actions may proceed. A recommendation outside the available capability set remains work for an authorised operator or a separately governed workflow.

05 / Verify and establish the baseline

Retest the original vulnerability or exposure and the relevant security configuration, service health, application health and network accessibility. Record whether the result is verified, failed or inconclusive. An attempted fix is not a verified fix.

The accepted state then records expected hosts, ports, services, users, packages, workloads, network paths and approved exceptions. That state becomes the reference for subsequent monitoring.

06 / Continuously defend

Monitor for new vulnerabilities, devices, ports, services, identity changes, configuration drift and suspicious activity. Correlate those changes with authorised work and available threat evidence.

New findings return to the same controlled lifecycle. Detection does not erase the approval boundary. Changes need authority and outcomes need verification, even after the initial assessment is complete.

Start with understanding

What does your environment need to defend?

Discuss the assessment scope, current capabilities and the control you need with Altari Systems.

Talk to Altari