Wethaq ICT | وثاق
Get a Quote
HomeCase studies
Case studies

Real engagements, confidentially told

Selected work in government and banking cybersecurity. Each case is anonymised to protect the client.

01
Government

External attack-surface assessment & penetration test

Confidential Libyan government entity

75+sub-domains
NISTframework

Challenge

The entity ran several domains and more than 75 sub-domains. Internet-facing systems had no WAF and no DDoS protection, and sat inside an insecure local cloud that offered none of these protections.

Our approach

We mapped the full external attack surface, then ran vulnerability assessment and penetration testing against public web pages, application keys and the online services offered to users. Several other internet-exposed systems were tested the same way, with a rapid-response report for each.

Outcome

Multiple exposed vulnerabilities were identified across pages, application keys and user-facing services. Official reports documented realistic threat and breach scenarios with severity ratings aligned to NIST.

02
Government · Incident response

External intrusion threat: detection, containment and formal reporting

Sensitive Libyan government entity — confidential

NISTanalysis & monitoring framework
2reporting authorities: executive and oversight

Challenge

A threat of intrusion by actors outside the network perimeter was detected against a sensitive government entity.

Our approach

The incident was detected, handled and documented. Analysis and monitoring followed NIST. The work uncovered critical weaknesses in how users and staff sign in to and access their email, and found evidence of leaked information on the dark web that was assessed as near-certain. We also documented deviations from the policies adopted by the legislative authorities, treated as a critical point.

Outcome

Detailed reports covering severity, technical root causes and the impact of non-compliance were sent to the executive and oversight government authorities.

03
Government · Penetration testing

From black-box testing to a white-box scope and rules of engagement

Confidential Libyan government entity

BB → WBtest path
ISO 27001plus NIST reference

Challenge

The entity’s public domain serves citizens and other government bodies. It is connected to many contact points on the same network, which makes the wider sector more exposed to intrusion, malware and email phishing.

Our approach

We ran a black-box penetration test to gather information about the domain, then delivered an integrated report as the basis for a white-box test. The next stage widens the domains and sub-domains in scope, with a clear, organisation-wide rules of engagement (ROE) approved formally and aligned to NIST and ISO 27001.

Outcome

Several vulnerabilities rated critical and high were documented. The detailed report and remediation roadmap aim to prevent a national-scale digital disaster across the connected sector.

04
Government · Threat & vulnerability assessment

Critical local system: 28 days of deep cyber analysis

Confidential critical local service provider

4+ / 10 / 8critical / high / medium
28days of analysis

Challenge

A local system delivering highly important services showed weaknesses and threat sources that had to be confirmed and fixed before an actual compromise.

Our approach

Our assessment and ethical-penetration-testing team confirmed each finding by testing and technical evidence after ruling out false positives. Evidence was backed by IOC feeds and threat-intelligence tooling, all documented formally.

Outcome

More than 4 critical, 10 high and 8 medium vulnerabilities remained confirmed. A detailed report set out the mandatory protective measures, and remediation was completed with the entity’s technical and cyber team over 28 days.

05
Government · SOC platform

A national platform to monitor, analyse and display confirmed attacks

Confidential government entity

AIdaily event analysis
ATT&CKMITRE classification

Challenge

The entity needed one view of all confirmed events and attacks against its entire digital infrastructure, and a way to analyse the very large daily data volume.

Our approach

We built and equipped a platform that monitors, analyses and displays confirmed events and attacks. Artificial intelligence supports the daily analysis of the data volume.

Outcome

Detected events are classified by severity and MITRE ATT&CK, with detection time and speed of handling tracked. Given the sensitivity of the data, these events cannot be published; our information-security approach applies to every task we perform for such entities.

06
Banking · Managed SOC

Exploitation attempts at a local bank, and the move to managed SOC

Confidential Libyan bank

120sites
500endpoints
24/7monitoring

Challenge

Attempts to exploit a critical vulnerability were detected at a local bank. They could have disrupted services and exposed depositor and account-holder data.

Our approach

We met the bank’s team to review the events and the remediation, and rated each vulnerability with CVE and CVSS under international standards. The bank then agreed to SOC-as-a-Service and periodic vulnerability management covering all assets: 120 sites and 500 endpoints on the same infrastructure, prioritised by criticality and the risk of service downtime.

Outcome

An SLA was signed to protect business continuity and avoid sudden service stops. A daily backup and restore point allows recovery after a cyber-attack or ransomware. DDoS and complex intrusions are watched by our UCCC platform 24/7 from the security operations room at Wethaq.

All case studies are anonymised. Client names, systems and technical details are withheld under confidentiality; figures shown are those we can state publicly.

Let’s build a secure foundation for your digital future

It starts with a free consultation: we learn your challenges and goals, then propose a service package tailored to your needs and budget.