Cyber Security Operations · AI-first Automation

One more productwill not make you secure.

Security is not a product, it is one concept carried through.

  • IT and OT
  • Mid-market to large enterprise
  • Models: EU · DE · on-premise
Patch Tuesday · Cycle 2026-Q1 Audited example · in your instance
14:00 Inventory pulled
14:02 Risk classified
14:05 Staging approved
1:58 hDuration
3Human decisions
69 / 70Hosts patched
1Rollbacks

Workflow ID: WF-PATCH-042 · Audited in your instance · more steps ↓

Where we are at home

Six sectors we hold mandates in.

Regulation lands differently in every sector — and the stack behind it looks different every time. We know these six from operating them, not from a brochure.

Not one of them? Operations differ less than the regulation suggests. Just ask.

dynexo has been building and operating large security and network environments for two decades — from mid-market to critical platforms of national reach, on Cisco, Check Point, Palo Alto Networks and Fortinet. We have always run them automated; for the past two years, AI-first: business playbooks supported by language models, controlled and steered by our agent harness. People make the decisions — in day-to-day operations, not on a roadmap.

What we keep hearing

Four assumptions that cost money.

They come up in almost every first conversation. None of them survives a closer look — and each one sends budget to the wrong place.

Security costs a lot of money. Operations from EUR 199 a month. Not a toolbox nobody ends up operating. The effort sits in running it, not in buying it.
New hardware makes you secure. The old server was rarely the problem. Configuration and operations were — in practically every mandate we have taken over.
More tools mean more protection. Past a point it reverses. Every additional tool produces alerts somebody has to review. We operate fewer of them, completely — what nobody operates protects nobody.
Certificates prove security. A certificate shows that measures were applied. Not how well. Certificates make vendors comparable and satisfy requirements — as evidence of security actually lived, they are worth little.
What we operate today

The stack we know — layer by layer.

We don't recommend a component we haven't solved tickets with. We know the strengths, quirks and failure modes of the leading vendors — because we run them in production.

Firewalls & NGFWConfiguration, hardening, audit. Operated in large mandates for more than two decades.
  • Cisco
  • Check Point
  • Palo Alto Networks
  • Fortinet
  • Cisco Secure Firewall (SourceFire)
SASE / SSEEdge security, zero-trust access, inspection for hybrid workforces.
  • Palo Alto Prisma
  • Netskope
  • CATO Networks
  • Zscaler
  • Cisco Umbrella
  • Fortinet
SD-WANSite interconnect, app-aware routing, integrated with security policy.
  • Palo Alto Prisma SD-WAN
  • CATO Networks
  • Fortinet
  • Versa Networks
  • Cisco Viptela
Data centre SDNCisco ACI as the single source of truth for data-centre segmentation — large mandates, 100% automated.
  • Cisco ACI
  • VMware NSX
  • Arista CloudVision
  • HPE Aruba CX
Web & e-mail proxiesContent filtering, SSL inspection, DLP pre-hooks, e-mail security (DMARC enforce).
  • Zscaler
  • Cloudflare
  • Cisco WSA
Load balancers & ADCHigh-availability publishing, TLS offload, WAF integration, application delivery.
  • F5
  • HAProxy
  • Citrix NetScaler
  • Cloudflare
Identity managementLifecycle, federation, conditional access, sign-in risk, service accounts.
  • Microsoft Entra
  • Okta
  • Auth0
Privileged access managementJust-in-time, session audit, four-eyes for admin access.
  • CyberArk
  • Teleport
  • BeyondTrust
SIEM & detectionSplunk operations in large estates. Correlation, detection engineering, runbooks.
  • Splunk
  • IBM QRadar
  • FortiSIEM
OT gateways & segmentationSafe bridges between IT and OT. Detection rather than blind blocking.
  • Fortinet
  • Cisco IE
  • Claroty
  • Nozomi Networks
  • Dragos
Assessments & pentestsArchitecture reviews, pentests and red-team exercises — Burp, Metasploit and Nmap, paired with LLM-driven recon and reporting where customers allow.
  • Burp Suite Pro
  • Metasploit
  • Nmap
  • PentestGPT

We have our favourites per layer — and still operate what you already run.

How we work

One source of truth. Everything else follows from it.

Network, firewalls, servers, endpoints, services — one connected estate, not five islands with five user databases.

One source of truthIdentities, rules and state live in one place, versioned, and everything is steered from there. The alternative is a separate user database per tool — and after six months nobody reconciles them.
Architecture before toolingThe concept first: zones, separation, which protocol layer the separation happens on, who may talk to whom. Then the question of which product implements it. Not the other way round.
One estate, not five islandsNetwork, firewalls, servers, endpoints and services are operated together. Run them separately and you find the gap between them only after somebody else has found it first.
AI-first automationRepeating work runs through playbooks, executed by agents under our agent harness. What executes is what was defined beforehand as a rule; the decisions are made by people. That is why a small team can carry a large estate.
How much automation you want

Three levels. You choose, area by area.

Nobody has to hand their operation to agents to get something out of us. The levels are not exclusive — in most mandates they run side by side.

01 Manual

Our people work in your environment, following your processes. No agent touches anything. For the areas where you want it that way, and as a starting point while trust is still being built.

02 Automated

Repeating work runs as code — reviewed, versioned, repeatable. No language model involved, and the result is the same every time. We have done this for two decades.

03 Agents with playbooks

Business playbooks supported by language models, controlled by our agent harness. The agent moves only inside the rule, every action lands in the audit log, and people make the decisions.

Behind all three are our own teams — no subcontractors, one line of authority. You set which level applies where, and you can change it at any time. Your data stays in your environment either way, whoever does the work: person or agent.

Standardisation

Business rules in code. Everything else around them.

We learned it on large Cisco ACI mandates: 100% automation and AI only hold up when a single, versioned source of truth lies beneath them. We encode security and business rules as code — one source. Processes, automation and agents move inside those rules.

One sourceSecurity and business rules live in code, versioned. No Excel exports, no shadow configurations, no drift. Diffable, auditable, traceable.
Cites the ruleEvery workflow references the policy it checks against. We always know why a decision went one way and not the other.
Stays insideAI can act, but never past policy. Vendor changes cost time, not control. The rules outlive the tooling.
Traces to the ruleEvery agent action traces back to the rule that authorised it. No black-box behaviour, no scrambling for an explanation in front of an auditor.
Field record

Two mandates where it held.

Security vendors are not allowed to name clients. What we can name are the patterns — and the outcomes. Two examples from our practice.

DACH industrial group · multi-site environment · migration to a modern security standard for industrial environments

Active ransomware against the group. Where the overlay had landed, nothing broke.

We designed the security overlay and implemented a modern security standard for industrial environments. The standard has held under active attack across multiple mandates — industrial and critical power-supply infrastructures. The most prominent: a DACH industrial group hit several times during the migration. Everything already migrated stayed available.

Availability of migrated sites100%
Encrypted systems in scope0
Ransom discussionnone
Utility · critical platform with national reach

Platform built, secured, operated — and handed over clean.

WAN and security platform migrated and automated. Operations ran on machine learning for logs and events, combined with deterministic agents — no language models, which did not exist for this yet. Two years of operations by dynexo. Clean hand-over in 2022 — the customer has run it independently since.

Platform livesince 2020
Operational ownership2 years
Hand-over without incident2022
Customer operatingself-sufficient

Both mandates are built into what we run today. Nova9 is the continuation of an approach that has been proven in production: business playbooks supported by language models, controlled and steered by the Nova9 Agent OS — our agent harness. More detailed reports from our mandates are on the »About« page.

On certificates

Comparable is not the same as secure.

A certificate shows that a management system was audited. It does not show that an environment holds when it matters — that is decided by the operations behind it.

We look after clients with a valid ISO 27001 certificate whose implementation does not reach the minimum. Hence our plain position: certificates make vendors comparable and satisfy requirements. They do not prove security.

If your tender requires one, we will say so openly instead of pretending the question is answered. And if you want to know how your environment actually stands, we will look at it.

Sovereignty, built in

The big AI vendors want your data. We build the opposite.

Sovereignty here isn't marketing — it's architecture. Every layer is designed so you stay in control, including over us.

OUTSIDE · PUBLIC

PUBLIC

Public models

Useful, but outside your environment. Reachable through the gateway and nowhere else.

  • GPT
  • Claude
  • Gemini
LLM GATEWAY Filter · Redaction · Budgets ↑ the only route out

INSIDE · YOUR INFRASTRUCTURE (EU · DE · ON-PREM)

CUSTOMER

Your own models

Whatever you already run or have licensed, we connect to — instead of replacing it.

  • your licences
  • your hardware

CLOUD

Our models in the EU

Operated by us, in the EU or in a German data centre. You pick the location.

  • EU cloud
  • DE data centre

ON-PREM

Inside your own building

On your hardware, fully disconnected from any network if you want it that way.

  • on-premise
  • air-gapped
DATAstays here Business data, training data, inference✓ You control
LOGSstay here Audit trail, tool calls, model outputs✓ You control
MODELSEU or here EU-cloud, DE-DC, on-premise, air-gapped✓ You control
Models — EU, Germany or on-premiseWe run whatever model is permitted in your environment — EU-cloud through air-gapped on-prem. Your choice, not ours.
Data — never leaves your perimeterTraining and inference data stay in your infrastructure. We don't see business data unless you explicitly approve it.
Logs — stay with youAudit logs, tool calls, model outputs — all in your system, searchable by you. We don't keep shadow copies.
Platform — cloneable at any timeYour Nova9 instance fits in a VM. We deliver the snapshot — you can run the platform yourself whenever you want.
Gateway — safe access to public LLMsWhen you need a public model — GPT, Claude, Gemini — we route it through our gateway with filters, redaction and budgets.
Lock-in — doesn't existNo proprietary format, no hidden binding. What we build is yours — as code, with documentation.
A day of operations

Example: a patch rollout, fully driven by the agent fleet.

A real, anonymised sequence. Three human decisions, the rest by the agent fleet. Every action in the audit log inside your system.

Patch Tuesday · Cycle 2026-Q1 Workflow ID: WF-PATCH-042 · Audited in your instance
AI Human
01 / 11
14:00 Inventory pulledVendor feeds (Microsoft, RedHat, Cisco) consolidated. 47 new CVEs identified.
14:02 Risk classified12 CVEs marked critical. 81 affected assets mapped.
14:05 Staging approvedOps lead confirms staging plan for the test ring (12 hosts).
14:10 Test ring rolled outAnsible playbook applied to 12 hosts. Service health checked.
14:25 Test ring validatedLogs, latency and error rates within thresholds. No regress.
14:30 Production approvedAnalyst reviews validation report, releases waved rollout.
14:32 Wave 1/3 · 24 hostsRolling update, max 8 parallel. Health-check after each batch.
15:04 Wave 2/3 · 24 hostsContinues. One host showed elevated CPU — auto-rolled back.Auto-rollback
15:18 Triage wave-2 anomalyInvestigation of CPU spike on srv-app-17. Patch rescheduled.
15:46 Wave 3/3 · 21 hostsRemaining hosts patched successfully.
15:58 Report generatedPDF + audit log generated, attached to ticket, mailed to CISO.
1:58 hDuration
3Human decisions
69 / 70Hosts patched
1Rollbacks

Anonymised excerpt of a real run — Q1 2026, mid-market mandate. Logged inside the customer instance.

How it starts

Non-binding first format · scope by agreement

Up to two weeks of our work before you commit.

We look at what you run and write down what we find — including when the finding is that you don't need us.

You get

  • A written report, yours to keep
  • Findings sorted by priority
  • A realistic effort estimate per finding
  • A clear statement of what comes first

We need

  • One site, not the whole estate
  • Read access and one contact person
  • Two appointments, one hour each

Afterwards

  • You decide whether anything follows
  • No follow-on commitment
  • The report stays valid without us

Scope, dates and effort are agreed before we start; this does not create a claim to have the assessment carried out. The report we produce is yours to keep — including if you hand the work to someone else afterwards.

The path in

From the first conversation to running operations.

01 Conversation30 minutes. We map your stack, your bottlenecks and your sovereignty requirements.
02 Pilot4–6 weeks. One Nova9 module runs in production on your data. You see real workflows, not demos.
03 HandoverRollout across more modules. Optional: a fully cloned instance you operate yourself.
Next step

Showing is easier than explaining.

45 minutes spent on real operations rather than slides: the playbooks, the log, the crossings. We talk about your environment and which level fits it — manual, automated or by playbook. You decide afterwards whether a pilot makes sense.