[ Investor Briefing — Technical Annex ]
S E N T I N E L E T

In-Country Security Operations
Architecture & Delivery Model

SOC IN ADDIS ABABA  ·  NBE DIRECTIVE & INSA ALIGNED  ·  ISO 27001:2022  ·  24×7×365  ·  BILLED IN ETB

#1
Most-targeted country in the world for malware detections, 2024
INTERPOL Africa Cyberthreat Assessment, 2025
+115%
Year-on-year rise in attempted attacks reported by INSA
INSA Director-General, 2024
ETB 10.5B
Losses INSA estimates were avoided by blocking those attacks
INSA, 2023/24 fiscal year
220+
Attacks per day on Telebirr alone, rising ~20% a year
Ethio Telecom CISO, 2025
What this document is. The architecture behind the SentinelET service lines — how client telemetry reaches an Addis-hosted SOC, what detects on it, and who responds. Every component below is deployed in-country: logs terminate in Ethiopia, analysts sit in Addis, and the contract is invoiced in birr.
🏢
Zone 1 — Client Environment (Bank · MFI · Payment Operator)
TRUST: INTERNAL
▸ Banking & Channel Layer
🏦
Core Banking Platform
Temenos / Oracle Flexcube / Fusion
Txn-LogsDB-AuditNBE-Scope
📲
Mobile Money & Agent Banking
Wallet · USSD · Agent app · API gateway
FraudSIM-SwapVelocity
🏧
ATM & POS Estate
Switch · HSM · Card management
PCI-DSSJackpotting
🌍
Internet & Mobile Banking
Web / app front ends · Open APIs
WAFBot-DefenseATO
▸ Endpoint Layer
💻
Employee Workstations
Windows 11 / macOS
EDRDLPSyslog
🖥️
On-Premise Servers
Windows Server / RHEL 9
HIDSFIMAV
📱
Mobile Devices (MDM)
iOS 17+ / Android 14+
MDMMTD
▸ Network Layer
🔥
NGFW / Perimeter
Palo Alto / Fortinet
IPSSSL-InspectApp-ID
🔀
Core Switches
Cisco Catalyst / Juniper EX
NetFlowNAC802.1X
🌐
Secure Web Gateway
Zscaler ZIA / Umbrella
DNS-SecCASBZTNA
🔍
NDR Sensor
Darktrace / ExtraHop
E-W TrafficMLETA
▸ Identity & Access Layer
🗂️
Active Directory / Entra ID
AD DS / Azure AD
Auth-LogsAudit
🔐
MFA Platform
Duo / MS Authenticator
TOTPPush
🛡️
PAM (Privileged Access)
CyberArk / BeyondTrust
VaultSession-Rec
🚧
Network Access Control
Cisco ISE / ClearPass
PostureRADIUS
▸ Cloud Workload Layer
☁️
Cloud IaaS
AWS / Azure / GCP
CloudTrailGuardDutyDefender
📦
SaaS Applications
M365 / Salesforce / Slack
UALCASBDLP
📤
Log Aggregator
Elastic / Filebeat / UF
NormalizemTLSBuffer
🔒
Zone 2 — Secure Transmission (Domestic Routing Only)
AES-256 / mTLS · NO CROSS-BORDER EGRESS
🚇
IPSec VPN / SD-WAN Tunnel
IKEv2 · AES-256-GCM · Certificate Auth
Tenant IsolationmTLSTraffic Shaping
📡
Protocols in Transit
Syslog-TLS :6514 · Beats :5044 · REST/443 · UF :9997
CEFLEEFECS
🧾
Data in Transit Controls
TLS 1.3 minimum · FIPS 140-2 modules
Cert-PinningDLP-in-Transit
🇪🇹
Data Residency Boundary
Links terminate in Addis · no offshore forwarding
PDP ProclamationINSAAudit-Evidence
🛡️
Zone 3 — SentinelET SOC, Addis Ababa (In-Country)
MANAGED · 24×7×365 · INVOICED IN ETB
▸ Ingestion & Normalization Layer
⚙️
Data Ingestion Pipeline
Kafka / Logstash / Apache NiFi
Multi-TenantEnrichDedupRoute
▸ Detection & Analytics Layer
🔬
SIEM Platform
Commercial (Splunk ES / Sentinel) or open-core (Wazuh + Elastic)
SIGMAMITRE ATT&CKUEBACompliance
🌍
Threat Intelligence (TIP)
MISP / Anomali · Ethiopian threat feed
STIX/TAXIIIOCRegional TTPs
🩺
Vulnerability Management
Tenable.io / Qualys / Rapid7
CVERisk-ScorePatch-Track
▸ Orchestration & Response Layer
🤖
SOAR Platform
Palo Alto XSOAR / Splunk SOAR
PlaybooksCase MgmtSLA Track
▸ Analyst Operations
👁️
Tier 1 — Alert Triage ×3
24×7 monitoring · Playbook execution
P1: 15minP2: 1hrETB 25–60K/mo
🕵️
Tier 2 — Security Engineer ×1
Deep investigation · Hunting · On-site response
ForensicsDFIRETB 40–80K/mo
🧠
Tier 3 — SOC Team Lead ×1
Rule authoring · Escalation owner · Client briefings
Purple TeamTTP DevETB 50–100K+/mo
▸ Governance, Risk & Compliance Layer
📋
Control & Evidence Register
NBE Directive · ISO 27001:2022 · PCI-DSS mapping
Gap-AssessEvidenceRetest
🗳️
Regulator Submission Pack
INSA registration · NBE audit responses
TemplatesDeadlines
🎯
Offensive Testing
Mobile money · API · ATM/POS · Phishing (አማርኛ/EN)
Pen TestRemediation
▸ Reporting & Client Portal
📊
Client SOC Portal
Grafana / Power BI / Custom Web
Real-TimeBoard PackNBE-Ready
🗣️
Reporting in Amharic & English
Monthly board report · Directive-mapped format
አማርኛEnglish

⚡ Security Operations Pipeline

S1
📡
Data Collection
  • Core banking & switch
  • Mobile money & agents
  • Endpoints, network, IAM
  • Cloud & SaaS
S2
🔒
Secure Transmission
  • AES-256-GCM encrypt
  • IKEv2 / mTLS auth
  • Tenant isolation
  • Stays inside Ethiopia
S3
⚙️
Ingestion & Normalization
  • Schema normalization
  • GeoIP enrichment
  • Threat intel lookup
  • Asset resolution
S4
🔬
Detection & Correlation
  • SIEM rule engine
  • UEBA / ML anomaly
  • MITRE ATT&CK map
  • TIP IOC matching
S5
🤖
Triage & Orchestration
  • Auto-enrichment
  • Playbook execution
  • Analyst assignment
  • SLA clock start
S6
🚨
Investigation & Response
  • Deep-dive forensics
  • Network isolation
  • On-site response (Addis)
  • Client notification
S7
📊
Reporting & Improvement
  • Board & NBE reporting
  • Rule tuning (FP/FN)
  • Playbook optimize
  • Quarterly briefings

🤖 Automated SOAR Playbooks

Trigger: Phishing Alert
PB-001 — Phishing Response
  1. 1Extract IOCs from email headers & body
  2. 2Query TIP for malicious indicators
  3. 3Determine campaign scope via email gateway
  4. 4Quarantine confirmed mailboxes
  5. 5Block sender domains on NGFW & SWG
  6. 6Create incident ticket → notify client
Trigger: Ransomware Behavior
PB-002 — Ransomware Containment
  1. 1Correlate EDR telemetry for blast radius
  2. 2Network-isolate affected endpoints via EDR API
  3. 3Block C2 IPs on NGFW
  4. 4Initiate forensic memory capture
  5. 5Page on-call IR team (P1)
  6. 6Initiate client crisis communication
Trigger: Mobile Money Anomaly
PB-004 — Agent / Wallet Fraud Response
  1. 1Correlate wallet velocity, SIM-swap and device-change events
  2. 2Score agent float movement against baseline behaviour
  3. 3Freeze suspect agent tills via channel API
  4. 4Package evidence for the bank's fraud & risk committee
  5. 5File incident summary in the NBE-required format
Trigger: Privilege Escalation
PB-003 — Privilege Escalation Response
  1. 1Query PAM for full session context
  2. 2Suspend account in Active Directory
  3. 3Collect correlated audit trail from SIEM
  4. 4Escalate to Tier 2 analyst for review

⏱️ SLA Commitments

P1 — CRITICAL
Detect: 5 min
Respond: 15 min
Resolve: 4 hr
Ransomware · Breach · APT
P2 — HIGH
Detect: 15 min
Respond: 1 hr
Resolve: 24 hr
Privilege Escalation · Exfil
P3 — MEDIUM
Detect: 1 hr
Respond: 4 hr
Resolve: 72 hr
Malware · Policy Violation
P4 — LOW
Detect: 4 hr
Respond: 24 hr
Resolve: 168 hr
Recon · Low-risk anomalies
Contractual, in birr. These targets are written into the 12-month ETB retainer. P1 and P2 carry on-site escalation in Addis — the response a remote-only foreign vendor cannot commit to.

💼 Service Lines & Ethiopian Pricing

SOC / MDR
Security Operations & Managed Detection
  • 24/7 monitoring of core banking and channels
  • SIEM deployment and tuning
  • Incident response with on-site escalation
  • Monthly board and NBE-ready reporting
From ETB 180,000 / month
≈ $1,300 — mid-tier bank or MFI
Pen Testing
Penetration Testing & Offensive Security
  • Mobile money, agent banking and API testing
  • Network, web app, ATM and POS assessments
  • Phishing simulation in Amharic and English
  • Remediation roadmap and retest included
From ETB 450,000 / engagement
≈ $3,200 — scoped per environment
GRC — the wedge
Governance, Risk & Compliance
  • NBE Cybersecurity Directive readiness
  • INSA registration and audit preparation
  • ISO 27001 and PCI-DSS gap assessment
  • Data Protection Proclamation mapping
From ETB 250,000 / month
≈ $1,800 — or fixed-fee project
Regulation is the entry point. Institutions buy GRC because they must, then keep us for monitoring because the audit exposed what they cannot see. Retainers are 12-month ETB contracts billed monthly — roughly 70% of revenue — with pen tests and readiness work as the 30% that opens the door.

📜 Regulatory Mapping

ObligationWhat the client must proveWhere it is satisfied here
NBE Cybersecurity Directive Continuous monitoring of core banking and channels, incident reporting to the regulator, board oversight Zone 3 SIEM + SOAR case management, monthly board/NBE report pack
INSA registration & audit Registered security provider, in-country capability, documented incident handling Zone 3 Addis SOC, GRC submission pack, SLA-clocked playbooks
Personal Data Protection Proclamation Personal and transaction data does not leave the country without lawful basis Zone 2 domestic routing, residency boundary, in-country log storage
ISO 27001:2022 Documented ISMS with evidence per control Zone 3 control & evidence register — SentinelET certifies itself in Phase 2
PCI-DSS Card estate segmentation, quarterly scanning, tested response plan Zone 1 ATM/POS scope, vulnerability management, PB-002 containment
The moat a foreign vendor cannot copy. ETB invoicing removes the forex approval queue, logs never leave Ethiopia, and reporting is formatted for the directives clients are actually audited against — not a generic international template.

🚀 How This Platform Scales

PHASE 1 · MONTHS 1–12
Land on Compliance
  • Single multi-tenant SOC stack, 5-person Addis team
  • Fixed-fee readiness assessments as the entry product
  • Convert 3 of 5 assessments into retainers
  • Publish an Ethiopian threat report
Target: ETB 12M ARR (≈ $86K) · 5 clients
PHASE 2 · MONTHS 13–24
Expand & Certify
  • Same stack, more tenants — margin improves as clients share it
  • ISO 27001 achieved in-house: proof, not promise
  • Government and critical-infrastructure accounts added
  • Integrator partnerships for pipeline
Target: ETB 40M ARR (≈ $285K) · 14 clients · 12 staff
PHASE 3 · MONTHS 25–36
Regionalise & Export
  • Djibouti, Somalia and Kenya served from the same SOC
  • Productised compliance portal for smaller MFIs
  • USD-earning export work via the US entity
  • Addis team past 25 people
Target: ETB 107M ARR (≈ $765K) · 32 clients
Why the economics work. Tooling — not people — is the dominant cost line, and it is the only material USD exposure. A five-person Addis SOC runs at roughly ETB 4.4M/year fully loaded, less than a single commercial SIEM licence. Gross margin moves 58% → 70% as clients are added to shared infrastructure.

👥 Team, Roles & Compensation

CEO & Co-Founder
[Founder Name]
Security leader with working relationships across Ethiopian banking and the regulator community, plus international enterprise experience. Understands both the NBE audit cycle and how a modern SOC is run.
CISSP · 10+ yrs InfoSec · Banking network
No cash draw during runway — equity only
CTO & Co-Founder
[Technical Lead]
Senior security engineer with hands-on SIEM, threat hunting and red team experience in Ethiopian environments — core banking, mobile money and agent networks. AAU graduate.
CEH · OSCP · SIEM architecture
No cash draw during runway — equity only
Head of GRC & Biz Dev
[GRC Lead]
Compliance and audit background inside an Ethiopian financial institution. Has been on the buyer's side of an NBE directive review — knows what evidence regulators ask for and where institutions fall short.
ISO 27001 LA · NBE directive experience
No cash draw during runway — equity only
Founders are unpaid through the raise. All ETB 7.5M of budgeted payroll goes to the operating team. Founder salaries begin only at break-even — targeted within 24 months — at ETB 80,000–120,000/month, below the market rate for their seniority. Advisory board in formation: former INSA and NBE technical leadership, and a serving bank CISO.
Salary bands — Addis market, ETB per month
Benchmarked to Ethiopian IT salary survey data · USD at ~140 ETB/USD
SOC Analyst ×3IT Officer band
25,000 – 60,000$179 – $429
Security Engineer ×1InfoSec Officer band
40,000 – 80,000$286 – $571
SOC Team Lead ×1Cyber Specialist band
50,000 – 100,000+$357 – $714+
030K60K90K120K
Band floor — entry offer Band ceiling — certified, retained
RoleEthiopian IT bandCount ETB / monthAnnual cash (ETB)Starts
SOC AnalystIT Officer325,000 – 60,0001.53MMonth 1
Security EngineerInfoSec Officer140,000 – 80,0000.72MMonth 1
SOC Team LeadCyber Specialist150,000 – 100,000+0.90MMonth 1
GRC AnalystCompliance Officer135,000 – 70,0000.63MPhase 2 (mo 13+)
Founders ×33No drawFrom break-even
Phase 1 funded teamFive staff, Addis5at midpoint3.15METB 4.40M loaded
From cash to fully loadedBasisETB / year
Base cash salaryFive staff at band midpoint3.15M
Employer pension11% of basic, private organisations scheme0.35M
AllowancesTransport, comms, night-shift differential for the rota0.45M
Medical & insuranceGroup cover0.20M
Certification sponsorshipCEH / OSCP / CISSP exams and training0.25M
Fully loaded≈ 1.40× base cash4.40M
Assumptions to confirm before the meeting: founder cash draw held at zero through the 18-month runway · band midpoints used for the annual figures · loaded multiplier of 1.40× derived from the ETB 4.4M team cost in the model · the ETB 7.5M payroll line runs 0.9M above straight-line 18-month cost, covering annual increments and the mid-runway GRC hire.
Compensation is the talent moat, not an expense line. AAU and AAiT graduate thousands of engineers a year into a market with almost no security career path. We pay at band midpoint on day one, sponsor certification, and publish a two-step path from Analyst to Team Lead — so scarce talent concentrates here rather than leaving for the Gulf. Every certification we fund also raises what we can charge for the analyst who holds it.
Coverage model, stated plainly. Five people cannot staff three shifts. In Phase 1, detection and automated containment run 24×7×365 through the SIEM and SOAR; analysts are on console 06:00–22:00 EAT with a paid on-call rota carrying P1 escalation overnight. A full three-shift desk arrives with Phase 2 headcount at 12 staff — which is what the ETB 40M ARR step funds.

📈 Per-Client Unit Economics

ETB 2.9M
Average annual contract value
≈ $21K — retainer plus one project a year
ETB 350K
Customer acquisition cost
≈ $2.5K — founder-led selling
ETB 7.2M
Lifetime value
≈ $51K at 2.5-year average retention
20 : 1
LTV : CAC ratio
Buyer universe is ~100 institutions
~2 months
CAC payback
Assessment fees often cover acquisition outright
115%+
Net revenue retention
Clients expand channel by channel
Smaller contracts, stronger ratios. Contract values are well below Western markets — but so is every cost line except tooling. One analyst costs ETB 40–80K/month against an ACV of ETB 2.9M, which is why the ratios improve rather than degrade at Ethiopian price points.

🎯 The Ask & Use of Funds

ETB 31M ≈ $220,000
SAFE NOTE · 20% DISCOUNT · $2.5M VALUATION CAP · 18-MONTH RUNWAY
5 signed clients ETB 12M ARR ISO 27001 certified Break-even within 24 months
Where the money goes
ETB millions · total 31.0M
Tooling & Cloud
12.0M · 39%
Engineering Team
7.5M · 24%
Compliance & Legal
5.0M · 16%
Working Capital
3.5M · 11%
Sales & Marketing
3.0M · 10%
Tooling — the only significant USD exposure Birr-denominated spend
LineETBWhat it buys
Tooling & Cloud12.0MSIEM, EDR, threat intel and in-country hosting — priced in USD
Engineering Team7.5MFive people for 18 months at Addis market rates, fully loaded
Compliance & Legal5.0MISO 27001 certification, INSA registration, US entity upkeep
Working Capital3.5MBuffer for the long collection cycles of institutional clients
Sales & Marketing3.0MThreat report, industry forums, tender participation
Total raise31.0M≈ $220K · 18-month runway
Note the shape of this raise: tooling costs more than people. That inversion is the Ethiopian opportunity — we can staff a credible SOC for less than the software it runs on, and every client added to the shared stack lands on margin rather than on cost.