Wethaq ICT | وثاق
Get a Quote
HomeServices
Service catalogue

The Wethaq service catalogue

Twelve integrated service areas — from security consulting and testing to managed operations, infrastructure, cloud, digital transformation and training. Every engagement is scoped to your environment and quoted through a tailored proposal.

Integrated packages

Commercial Cyber packages

Four ready packages covering the range from first assessment to critical infrastructure. Tailored to your environment and delivered with a detailed proposal.

01

Cyber START

  • Vulnerability Assessment
  • External Security Review
  • Basic Web Security Assessment
  • Security Report
  • Management Meeting
02

Cyber BUSINESS

  • Vulnerability Assessment
  • External Pentest
  • Web Application Test
  • Firewall Review
  • Network Security Review
  • Executive Report
  • Technical Report
  • Remediation Workshop
  • Retest
03

Cyber ENTERPRISE

  • External Pentest
  • Internal Pentest
  • Web, API & Network testing
  • Active Directory review
  • Firewall review
  • Vulnerability Assessment
  • Security Architecture Review
  • Risk Assessment
  • Executive Board Report
  • Retest
04

Cyber CRITICAL

  • External, Internal, Web, API & Mobile testing
  • Active Directory, Network & Cloud testing
  • Red Team
  • Threat Hunting
  • Security Architecture
  • SOC Assessment
  • Incident Response Readiness
  • Executive Risk Report
01 / 12

Cybersecurity Consulting & GRC

Policies, governance programmes, risk registers, BCP/DRP and ISO 27001 implementation — the management layer of security.

Governance, Risk & Compliance (GRC)11
  • GRC-001Cybersecurity Policy Package
  • GRC-002Information Security Policy
  • GRC-003Incident Response Policy
  • GRC-004Access Control Policy
  • GRC-005Backup Policy
  • GRC-006BCP (Business Continuity Plan)
  • GRC-007DRP (Disaster Recovery Plan)
  • GRC-008Incident Response Plan
  • GRC-009Risk Register Development
  • GRC-010Cybersecurity Governance Program
  • GRC-011ISO 27001 Implementation
02 / 12

Cybersecurity Assessment & Compliance

NIST CSF 2.0, ISO 27001 gap and readiness, maturity, risk, cloud, data and third-party assessments, plus security audits.

Cybersecurity Assessment15
  • AS-001Cybersecurity Quick AssessmentNIST CSF 2.0
  • AS-002Cybersecurity Baseline AssessmentNIST CSF 2.0
  • AS-003Full Cybersecurity AssessmentNIST CSF 2.0
  • AS-004Enterprise Cybersecurity AssessmentNIST CSF 2.0
  • AS-005NIST CSF 2.0 AssessmentNIST CSF 2.0
  • AS-006ISO 27001 Gap AssessmentISO/IEC 27001
  • AS-007ISO 27001 Readiness AssessmentISO/IEC 27001
  • AS-008Cybersecurity Maturity AssessmentCMMI / NIST
  • AS-009Cyber Risk AssessmentISO 27005
  • AS-010IT Risk AssessmentISO 27005
  • AS-011Third-Party Security AssessmentISO 27001
  • AS-012Critical Infrastructure AssessmentNIST CSF / IEC 62443
  • AS-013Security Architecture AssessmentSABSA / TOGAF
  • AS-014Cloud Security AssessmentCSA CCM
  • AS-015Data Security AssessmentISO 27001
Security Audit9
  • AU-001IT Security Audit
  • AU-002Network Security Audit
  • AU-003Firewall Audit
  • AU-004Active Directory Audit
  • AU-005Microsoft 365 Security Audit
  • AU-006Cloud Security Audit
  • AU-007Backup Security Audit
  • AU-008DR Security Assessment
  • AU-009Security Policy Audit
03 / 12

Penetration Testing & Red Team

Web, API, mobile and network penetration testing, Red Team operations and vulnerability assessment — think like the attacker first.

Web Application Penetration Testing4
  • PT-W01Small Web ApplicationOWASP WSTG
  • PT-W02Medium Web ApplicationOWASP WSTG
  • PT-W03Enterprise Web ApplicationOWASP WSTG
  • PT-W04Complex / Critical Web PlatformOWASP WSTG
API Penetration Testing6
  • PT-A01Basic API
  • PT-A02Standard API
  • PT-A03Complex API
  • PT-A04Enterprise API Platform
  • PT-A05API Gateway Assessment
  • PT-A06Microservices Security Assessment
Mobile Application Security Testing4
  • PT-M01Android
  • PT-M02iOS
  • PT-M03Android + iOS
  • PT-M04Mobile Backend + API
Network Penetration Testing11
  • PT-N01Small Network
  • PT-N02Medium Network
  • PT-N03Enterprise Network
  • PT-N04Large Government Network
  • PT-N05External Network Pentest
  • PT-N06Internal Network Pentest
  • PT-N07External + Internal
  • PT-N08Active Directory Security Assessment
  • PT-N09Firewall Assessment
  • PT-N10Wireless Security Assessment
  • PT-N11VPN Security Assessment
Red Team Operations5
  • RT-001Red Team Mini Engagement
  • RT-002Standard Red Team
  • RT-003Enterprise Red Team
  • RT-004Critical Infrastructure Red Team
  • RT-005Purple Team Exercise
Vulnerability Assessment5
  • VA-001Up to 25 Assets
  • VA-00226–100 Assets
  • VA-003101–250 Assets
  • VA-004251–500 Assets
  • VA-005500+ Assets
$ nmap -sV target22/tcp open ssh443/tcp open https[!] finding: HIGH▍
04 / 12

SOC-as-a-Service

24/7 security operations in four service tiers, plus SOC design, build and transformation.

SOC-as-a-Service4
  • SOC-001Starter SOC
  • SOC-002Business SOC
  • SOC-003Enterprise SOC
  • SOC-004Critical SOC
SOC Setup & Build5
  • SOC-S01Small SOC Build
  • SOC-S02Medium SOC Build
  • SOC-S03Enterprise SOC Build
  • SOC-S04Government SOC Build
  • SOC-S05SOC Transformation
Hardware and licences are not included in SOC/NOC/network services unless explicitly stated in the proposal.
24/7/365
05 / 12

NOC-as-a-Service

Network operations as a service: monitoring, fault, capacity and availability management under SLA.

NOC-as-a-Service4
  • NOC-001Basic NOC
  • NOC-002Business NOC
  • NOC-003Enterprise NOC
  • NOC-00424/7 Critical NOC
Hardware and licences are not included in SOC/NOC/network services unless explicitly stated in the proposal.
06 / 12

Incident Response & Digital Forensics

Incident response plans and readiness, plus digital forensics for evidence-grade investigations.

Incident Response7
  • IR-001Incident Assessment
  • IR-002Malware Investigation
  • IR-003Compromise Assessment
  • IR-004Digital Forensics
  • IR-005Ransomware Response
  • IR-006Major Cyber Incident
  • IR-007Emergency IR Retainer
Digital Forensics6
  • DF-001Computer Forensics
  • DF-002Mobile Forensics
  • DF-003Server Forensics
  • DF-004Cloud Forensics
  • DF-005Network Forensics
  • DF-006Enterprise Investigation
07 / 12

Network, Infrastructure & Physical Security

Network design and implementation, CCTV and physical security, and structured cabling.

Network Design7
  • ND-001Small Network Design
  • ND-002Medium Enterprise
  • ND-003Large Enterprise
  • ND-004Government Network Design
  • ND-005Data Center Network Design
  • ND-006SD-WAN Design
  • ND-007Network Segmentation
Network Implementation8
  • NI-001Router Configuration
  • NI-002Switch Configuration
  • NI-003Firewall Deployment
  • NI-004VPN Deployment
  • NI-005VLAN Implementation
  • NI-006Network Migration
  • NI-007Firewall Migration
  • NI-008Data Center Network Implementation
CCTV & Physical Security6
  • CCTV-001CCTV Assessment
  • CCTV-002CCTV Design
  • CCTV-003Network + CCTV Design
  • CCTV-004Large CCTV Design
  • CCTV-005Installation Management
  • CCTV-006Security Hardening
Structured Cabling6
  • SC-001Site Survey
  • SC-002Cabling Design
  • SC-003Fiber Design
  • SC-004Full Infrastructure Design
  • SC-005Project Management
  • SC-006Cat6 Point Implementation
Hardware and licences are not included in SOC/NOC/network services unless explicitly stated in the proposal.
08 / 12

Data Center & Cloud

Data-centre design, cloud services and virtualisation — built for availability, control and cost.

Data Center9
  • DC-001Data Center Assessment
  • DC-002Data Center Design
  • DC-003Small DC Implementation
  • DC-004Enterprise DC
  • DC-005Virtualization Design
  • DC-006VMware Implementation
  • DC-007Proxmox Implementation
  • DC-008Backup Infrastructure
  • DC-009Disaster Recovery Design
Cloud Services7
  • CL-001Cloud Readiness Assessment
  • CL-002Cloud Architecture
  • CL-003Cloud Migration Plan
  • CL-004Cloud Migration
  • CL-005Cloud Security
  • CL-006Hybrid Cloud
  • CL-007Cloud DR
Virtualization6
  • VT-001VMware Assessment
  • VT-002VMware Design
  • VT-003VMware Implementation
  • VT-004Proxmox Design
  • VT-005Proxmox Implementation
  • VT-006HA Cluster
Hardware and licences are not included in SOC/NOC/network services unless explicitly stated in the proposal.
09 / 12

Digital Transformation

Roadmaps and platforms that move legacy operations to secure, digital, measurable ones.

Digital Transformation7
  • DT-001Digital Transformation Assessment
  • DT-002Digital Maturity Assessment
  • DT-003Digital Transformation Strategy
  • DT-004Enterprise Architecture
  • DT-005IT Transformation Roadmap
  • DT-006Government Digital Transformation
  • DT-007Enterprise Digital Transformation
Legacy → Digital
10 / 12

ITSM & IT Operations

IT service management and operations: service desk, processes and continuous improvement.

IT Service Management (ITSM)6
  • ITSM-001ITSM Assessment
  • ITSM-002ITIL Implementation
  • ITSM-003Service Desk Implementation
  • ITSM-004CMDB
  • ITSM-005IT Asset Management
  • ITSM-006ServiceNow/Jira Implementation
11 / 12

Training & Cybersecurity Awareness

Cybersecurity awareness and technical training programmes with measurable outcomes.

Training & Awareness8
  • TR-001Cybersecurity Awareness
  • TR-002Network Security
  • TR-003SOC Analyst
  • TR-004Penetration Testing
  • TR-005Incident Response
  • TR-006Digital Forensics
  • TR-007Secure Coding
  • TR-008CISO Workshop
Training programmes run for 10–20 participants in 3–5 day packages and can be tailored to sector and level.
12 / 12

vCISO & Managed Security Services

Managed cybersecurity packages, vCISO leadership and security retainers.

Managed Cybersecurity Packages4
  • MC-001Cyber Essential
  • MC-002Cyber Business
  • MC-003Cyber Enterprise
  • MC-004Cyber Critical
vCISO & Security Retainer7
  • VC-001vCISO Basic
  • VC-002vCISO Professional
  • VC-003vCISO Enterprise
  • SR-001Bronze Retainer
  • SR-002Silver Retainer
  • SR-003Gold Retainer
  • SR-004Enterprise Retainer
vCISO24/7

Important notes

Every proposal follows a standard structure: scope, methodology, reference frameworks (NIST CSF 2.0, OWASP WSTG/PTES, ISO/IEC 27001, CIS Controls, CVSS), deliverables, timeline, SLA and, for services that include it, a retest with the period and number of rounds stated in the proposal.We sell defined deliverables, not consultant-days: executive and technical reports, remediation plans and retests.
Trusted by leading technology partners
Partner logo
Partner logo
Partner logo
Partner logo
Partner logo
Partner logo
Partner logo
Partner logo
Partner logo
Partner logo
Partner logo
Partner logo
Partner logo
Partner logo
Partner logo
Partner logo
Partner logo
Partner logo
Partner logo
Our partners across critical sectors
Central Bank of Libya
National Oil Corporation
Ministry of Local Government
Ministry of Education – Information & Documentation Center
General Center for Training & Education Development
National Information Security & Safety Authority
ITC – Information Technology Center
Libyan International Telecom Company
AAT – Al Jeel Aljadeed for Technology
Libyan Academy
National Commercial Bank
Libyan Islamic Bank
Nuran Bank
United Bank for Commerce & Investment
Alwaha Bank
Andalus Bank
Yaqeen Bank
ATIB
Akakus Oil Operations
Zueitina Oil Company
Petro Air
FAQ

Questions our partners ask

Answers to the most common questions about our services, methodology and commitment to your business security.

How is SOC-as-a-Service different from traditional monitoring?
Traditional monitoring relies on basic logs and periodic checks. Our SOCaaS provides round-the-clock proactive defence: continuous threat hunting, real-time log correlation with advanced SIEM/SOAR tools, and immediate incident response led by certified analysts — so threats are neutralised before they cause damage.
How do you implement Zero Trust?
We eliminate implicit trust across your network with rigorous Identity and Access Management (IAM), multi-factor authentication, network micro-segmentation, and continuous verification of every user and device — wherever they connect from.
Can you help us meet industry compliance requirements?
Absolutely. Our consultants specialise in industry-specific compliance. We run gap analyses, implement the technical controls, and provide continuous auditing and reporting for local and international standards such as PCI-DSS (finance) and HIPAA (healthcare).
Which cloud platform should we choose?
We are platform-agnostic and certified across AWS, Azure and GCP. Our recommendation rests purely on an assessment of your infrastructure, operational needs, cost structure and compliance mandates.
What are the benefits of managed cloud services?
Optimised performance, significant cost control (FinOps) and 24/7 security monitoring beyond in-house capability — with resources that are always securely configured, efficient and automatically scaling to demand.
How do DevOps and automation accelerate our business?
By building robust CI/CD pipelines, automating routine tasks and integrating technologies such as IIoT and Big Data analytics — particularly for Oil & Gas and Banking.
Do you serve clients outside Libya?
Yes. While our headquarters is in Tripoli, Libya, we deliver remote and on-site managed services and consulting across the region, specialising in critical regional industries.
How do we get started?
It begins with a free consultation. We hold a discovery session on your IT challenges, security posture and business goals, then propose a customised service package for your needs and budget.

Let’s build a secure foundation for your digital future

It starts with a free consultation: we learn your challenges and goals, then propose a service package tailored to your needs and budget.