The exchange is watched.So nothing else is.
iDefence is ContiSX's always-on cyber monitoring and threat-defence layer — continuous surveillance of the trading engine, the CSD, and every member connection against intrusion, fraud, and market abuse. One correlation plane, watched around the clock, with containment that moves before a signal becomes a breach.
24/7
Continuous monitoring, every surface
< 60 s
Signal → correlated alert, P95
99.9%
Detection-path availability
100%
Actions replayable from the audit log
Monitoring is not enough. Defence is the point.
A dashboard that lights up after the fact is a post-mortem, not a defence. iDefence watches, decides, and acts — three layers on one plane, so the gap between detection and containment is measured in seconds.
Continuous Monitoring
Always-on telemetry across the trading engine, CSD, APIs, and member connections — every login, order, transfer, and privileged action streamed into one correlation plane, watched 24/7.
Threat Detection
Behavioural and signature analytics flag intrusion, credential abuse, and market-manipulation patterns the moment they surface — not in the next-day report. Anomalies are scored, not just logged.
Incident Response
Confirmed threats trigger containment playbooks, analyst alerting, and an immutable forensic trail — so the exchange isolates, investigates, and reports before an incident becomes a breach.
Three surfaces, one defence
The core
Exchange & Trading Infrastructure
The systems that must never blink: matching engine, market data, and the gateways members trade through. iDefence watches the perimeter and the hot path at once.
- Intrusion and lateral-movement detection across gateways, APIs, and internal services
- Order-flow surveillance for spoofing, layering, wash trades, and abnormal message rates
- DDoS and abuse mitigation on the public edge, with rate anomalies escalated in seconds
The assets
Custody & CSD
Where securities and settlement live. Every privileged action against custody and the central depository is monitored, correlated, and replayable — no silent movement.
- Privileged-access monitoring with two-person-control and out-of-band approval on sensitive operations
- Settlement and transfer anomaly detection against learned baselines per account and instrument
- Immutable audit log — every custody state replayable end to end for regulators and forensics
The people
Members & Accounts
Brokers, issuers, and investors are the most-attacked surface. iDefence extends account-takeover and fraud defence to every member connected to ContiSX.
- Account-takeover detection: impossible travel, device change, credential-stuffing, and session hijack signals
- Fraud analytics on funding, withdrawal, and beneficiary changes before value leaves the platform
- Member alerting and step-up verification when a session's risk score crosses the line
If it can be attacked, it is watched
Every surface feeds the same correlation plane — filtered by severity, joined to identity and asset, and escalated the instant a pattern crosses from noise into threat.
Perimeter
Edge, gateways, APIs
Intrusion, scanning, and abuse signals on everything facing the public internet
Trading plane
Matching engine, market data
Latency, message-rate, and manipulation anomalies on the live order path
Privileged actions
Custody, CSD, admin
Every high-value operation, gated by approval and written to the audit log
Member sessions
Brokers, issuers, investors
Account-takeover and device-risk signals per session, with step-up on doubt
Data & secrets
Databases, keys, config
Exfiltration, unusual access, and secret-sprawl detection across data stores
A threat, end to end
Alerts are actionable or silent — no dashboard noise. Every one carries what happened, what it touched, and what iDefence already did about it.
Detect
Telemetry and analytics surface a signal — intrusion, anomaly, or abuse pattern — across any monitored surface.
Correlate
The signal is joined to identity, asset, and history. One alert, not a hundred fragments. Nothing escalates on noise alone.
Triage
Severity is scored: impact × confidence × exposure. Low is queued; Critical jumps straight to an on-call analyst.
Contain
Playbooks isolate the session, key, or service — revoke, quarantine, or step-up — to stop the bleed before investigation.
Resolve
Root cause, forensic report, and a signed record. Every incident feeds the baselines that catch the next one faster.
The watcher must be trustworthy
A monitoring layer sees everything — so it is held to the strictest standard on the platform. iDefence is built on least privilege, immutability, and zero blind trust.
Least privilege, always
iDefence watches everything but touches nothing it doesn't need. Access to raw telemetry is scoped, logged, and reviewed — the watcher is watched.
Immutable by design
Every detection, decision, and containment action is written to an append-only audit log. Nothing an attacker — or an insider — does escapes the record.
Regulator-ready
Monitoring, retention, and reporting align to SEC Nigeria market-infrastructure expectations and NDPR/NDPA data-protection requirements out of the box.
No blind trust
Internal traffic is not assumed safe. Zero-trust segmentation means a compromised service can't quietly become a compromised exchange.
Service-level objectives
Security is a promise, not a poster. iDefence runs to measured objectives — and reports against them.
Coverage
24 / 7 / 365
continuous monitoring across every core surface
Mean time to detect
< 60 s
signal surfaced → correlated alert, P95
Critical triage
< 5 min
Critical alert → on-call analyst engaged
Monitoring availability
99.9%
detection path, with redundant alerting
Audit retention
Immutable
append-only forensic trail, regulator-grade
Licensable
Global
available to monitor and protect your assets
Watch. Detect. Contain. Stay trusted.
Trust is the exchange's only real asset. iDefence protects it — putting continuous cyber monitoring under every trade, every settlement, and every member session, and closing the gap between when something happens and when the people who can respond find out.