ContiSX
ContiSX iDefence · Cyber Monitoring

The exchange is watched.So nothing else is.

iDefence is ContiSX's always-on cyber monitoring and threat-defence layer — continuous surveillance of the trading engine, the CSD, and every member connection against intrusion, fraud, and market abuse. One correlation plane, watched around the clock, with containment that moves before a signal becomes a breach.

24/7

Continuous monitoring, every surface

< 60 s

Signal → correlated alert, P95

99.9%

Detection-path availability

100%

Actions replayable from the audit log

Monitoring is not enough. Defence is the point.

A dashboard that lights up after the fact is a post-mortem, not a defence. iDefence watches, decides, and acts — three layers on one plane, so the gap between detection and containment is measured in seconds.

Layer 01

Continuous Monitoring

Always-on telemetry across the trading engine, CSD, APIs, and member connections — every login, order, transfer, and privileged action streamed into one correlation plane, watched 24/7.

Layer 02

Threat Detection

Behavioural and signature analytics flag intrusion, credential abuse, and market-manipulation patterns the moment they surface — not in the next-day report. Anomalies are scored, not just logged.

Layer 03

Incident Response

Confirmed threats trigger containment playbooks, analyst alerting, and an immutable forensic trail — so the exchange isolates, investigates, and reports before an incident becomes a breach.

Three surfaces, one defence

The core

Exchange & Trading Infrastructure

The systems that must never blink: matching engine, market data, and the gateways members trade through. iDefence watches the perimeter and the hot path at once.

  • Intrusion and lateral-movement detection across gateways, APIs, and internal services
  • Order-flow surveillance for spoofing, layering, wash trades, and abnormal message rates
  • DDoS and abuse mitigation on the public edge, with rate anomalies escalated in seconds

The assets

Custody & CSD

Where securities and settlement live. Every privileged action against custody and the central depository is monitored, correlated, and replayable — no silent movement.

  • Privileged-access monitoring with two-person-control and out-of-band approval on sensitive operations
  • Settlement and transfer anomaly detection against learned baselines per account and instrument
  • Immutable audit log — every custody state replayable end to end for regulators and forensics

The people

Members & Accounts

Brokers, issuers, and investors are the most-attacked surface. iDefence extends account-takeover and fraud defence to every member connected to ContiSX.

  • Account-takeover detection: impossible travel, device change, credential-stuffing, and session hijack signals
  • Fraud analytics on funding, withdrawal, and beneficiary changes before value leaves the platform
  • Member alerting and step-up verification when a session's risk score crosses the line

If it can be attacked, it is watched

Every surface feeds the same correlation plane — filtered by severity, joined to identity and asset, and escalated the instant a pattern crosses from noise into threat.

Perimeter

Edge, gateways, APIs

Intrusion, scanning, and abuse signals on everything facing the public internet

Trading plane

Matching engine, market data

Latency, message-rate, and manipulation anomalies on the live order path

Privileged actions

Custody, CSD, admin

Every high-value operation, gated by approval and written to the audit log

Member sessions

Brokers, issuers, investors

Account-takeover and device-risk signals per session, with step-up on doubt

Data & secrets

Databases, keys, config

Exfiltration, unusual access, and secret-sprawl detection across data stores

A threat, end to end

Alerts are actionable or silent — no dashboard noise. Every one carries what happened, what it touched, and what iDefence already did about it.

01

Detect

Telemetry and analytics surface a signal — intrusion, anomaly, or abuse pattern — across any monitored surface.

02

Correlate

The signal is joined to identity, asset, and history. One alert, not a hundred fragments. Nothing escalates on noise alone.

03

Triage

Severity is scored: impact × confidence × exposure. Low is queued; Critical jumps straight to an on-call analyst.

04

Contain

Playbooks isolate the session, key, or service — revoke, quarantine, or step-up — to stop the bleed before investigation.

05

Resolve

Root cause, forensic report, and a signed record. Every incident feeds the baselines that catch the next one faster.

The watcher must be trustworthy

A monitoring layer sees everything — so it is held to the strictest standard on the platform. iDefence is built on least privilege, immutability, and zero blind trust.

Least privilege, always

iDefence watches everything but touches nothing it doesn't need. Access to raw telemetry is scoped, logged, and reviewed — the watcher is watched.

Immutable by design

Every detection, decision, and containment action is written to an append-only audit log. Nothing an attacker — or an insider — does escapes the record.

Regulator-ready

Monitoring, retention, and reporting align to SEC Nigeria market-infrastructure expectations and NDPR/NDPA data-protection requirements out of the box.

No blind trust

Internal traffic is not assumed safe. Zero-trust segmentation means a compromised service can't quietly become a compromised exchange.

Service-level objectives

Security is a promise, not a poster. iDefence runs to measured objectives — and reports against them.

Coverage

24 / 7 / 365

continuous monitoring across every core surface

Mean time to detect

< 60 s

signal surfaced → correlated alert, P95

Critical triage

< 5 min

Critical alert → on-call analyst engaged

Monitoring availability

99.9%

detection path, with redundant alerting

Audit retention

Immutable

append-only forensic trail, regulator-grade

Licensable

Global

available to monitor and protect your assets

Watch. Detect. Contain. Stay trusted.

Trust is the exchange's only real asset. iDefence protects it — putting continuous cyber monitoring under every trade, every settlement, and every member session, and closing the gap between when something happens and when the people who can respond find out.