Open incidents (Sev 1-3)
11
Mapped to CIO comms (County mgmt)
Operational security
Correlate WAF anomalies, IDS heuristics, impossible travel on clinician accounts, API token reuse, ransomware precursors across county VLANs & partner SD-WAN overlays. Investigations chain into immutable audit timelines, trigger identity suspensions, and escalate to MOH cybersecurity desk + NHIF-ISAC cohorts.
Open incidents (Sev 1-3)
11
Mapped to CIO comms (County mgmt)
Mean time to containment
34m
Phishing click rate
3.9%
Pending patching
CVE-2026-0844
| IOC | Class | Source | Actions |
|---|---|---|---|
| 102.xxx.xxx.44 | Inbound scan | WAF edge ELD | Retain |
| sha256:9f83... | Malspam macro | User mailbox | Disable user |
| jwt:sig mismatch | API abuse | SMART launcher | Throttle |