In-Country Security Operations Architecture & Delivery Model
SOC IN ADDIS ABABA · NBE DIRECTIVE & INSA ALIGNED · ISO 27001:2022 · 24×7×365 · BILLED IN ETB
#1
Most-targeted country in the world for malware detections, 2024
INTERPOL Africa Cyberthreat Assessment, 2025
+115%
Year-on-year rise in attempted attacks reported by INSA
INSA Director-General, 2024
ETB 10.5B
Losses INSA estimates were avoided by blocking those attacks
INSA, 2023/24 fiscal year
220+
Attacks per day on Telebirr alone, rising ~20% a year
Ethio Telecom CISO, 2025
What this document is. The architecture behind the SentinelET service lines — how client telemetry
reaches an Addis-hosted SOC, what detects on it, and who responds. Every component below is deployed in-country:
logs terminate in Ethiopia, analysts sit in Addis, and the contract is invoiced in birr.
1Correlate wallet velocity, SIM-swap and device-change events
2Score agent float movement against baseline behaviour
3Freeze suspect agent tills via channel API
4Package evidence for the bank's fraud & risk committee
5File incident summary in the NBE-required format
Trigger: Privilege Escalation
PB-003 — Privilege Escalation Response
1Query PAM for full session context
2Suspend account in Active Directory
3Collect correlated audit trail from SIEM
4Escalate to Tier 2 analyst for review
⏱️ SLA Commitments
P1 — CRITICAL
Detect: 5 min
Respond: 15 min
Resolve: 4 hr
Ransomware · Breach · APT
P2 — HIGH
Detect: 15 min
Respond: 1 hr
Resolve: 24 hr
Privilege Escalation · Exfil
P3 — MEDIUM
Detect: 1 hr
Respond: 4 hr
Resolve: 72 hr
Malware · Policy Violation
P4 — LOW
Detect: 4 hr
Respond: 24 hr
Resolve: 168 hr
Recon · Low-risk anomalies
Contractual, in birr. These targets are written into the 12-month ETB retainer. P1 and P2 carry
on-site escalation in Addis — the response a remote-only foreign vendor cannot commit to.
💼 Service Lines & Ethiopian Pricing
SOC / MDR
Security Operations & Managed Detection
24/7 monitoring of core banking and channels
SIEM deployment and tuning
Incident response with on-site escalation
Monthly board and NBE-ready reporting
From ETB 180,000 / month
≈ $1,300 — mid-tier bank or MFI
Pen Testing
Penetration Testing & Offensive Security
Mobile money, agent banking and API testing
Network, web app, ATM and POS assessments
Phishing simulation in Amharic and English
Remediation roadmap and retest included
From ETB 450,000 / engagement
≈ $3,200 — scoped per environment
GRC — the wedge
Governance, Risk & Compliance
NBE Cybersecurity Directive readiness
INSA registration and audit preparation
ISO 27001 and PCI-DSS gap assessment
Data Protection Proclamation mapping
From ETB 250,000 / month
≈ $1,800 — or fixed-fee project
Regulation is the entry point. Institutions buy GRC because they must, then keep us for
monitoring because the audit exposed what they cannot see. Retainers are 12-month ETB contracts billed
monthly — roughly 70% of revenue — with pen tests and readiness work as the 30% that opens the door.
📜 Regulatory Mapping
Obligation
What the client must prove
Where it is satisfied here
NBE Cybersecurity Directive
Continuous monitoring of core banking and channels, incident reporting to the regulator, board oversight
Zone 3 SIEM + SOAR case management, monthly board/NBE report pack
Zone 3 Addis SOC, GRC submission pack, SLA-clocked playbooks
Personal Data Protection Proclamation
Personal and transaction data does not leave the country without lawful basis
Zone 2 domestic routing, residency boundary, in-country log storage
ISO 27001:2022
Documented ISMS with evidence per control
Zone 3 control & evidence register — SentinelET certifies itself in Phase 2
PCI-DSS
Card estate segmentation, quarterly scanning, tested response plan
Zone 1 ATM/POS scope, vulnerability management, PB-002 containment
The moat a foreign vendor cannot copy. ETB invoicing removes the forex approval queue,
logs never leave Ethiopia, and reporting is formatted for the directives clients are actually audited
against — not a generic international template.
🚀 How This Platform Scales
PHASE 1 · MONTHS 1–12
Land on Compliance
Single multi-tenant SOC stack, 5-person Addis team
Fixed-fee readiness assessments as the entry product
Convert 3 of 5 assessments into retainers
Publish an Ethiopian threat report
Target: ETB 12M ARR (≈ $86K) · 5 clients
PHASE 2 · MONTHS 13–24
Expand & Certify
Same stack, more tenants — margin improves as clients share it
ISO 27001 achieved in-house: proof, not promise
Government and critical-infrastructure accounts added
Djibouti, Somalia and Kenya served from the same SOC
Productised compliance portal for smaller MFIs
USD-earning export work via the US entity
Addis team past 25 people
Target: ETB 107M ARR (≈ $765K) · 32 clients
Why the economics work. Tooling — not people — is the dominant cost line, and it is the only
material USD exposure. A five-person Addis SOC runs at roughly ETB 4.4M/year fully loaded, less than a single
commercial SIEM licence. Gross margin moves 58% → 70% as clients are added to shared infrastructure.
👥 Team, Roles & Compensation
CEO & Co-Founder
[Founder Name]
Security leader with working relationships across Ethiopian banking and the regulator
community, plus international enterprise experience. Understands both the NBE audit cycle and how a modern
SOC is run.
CISSP · 10+ yrs InfoSec · Banking network
No cash draw during runway — equity only
CTO & Co-Founder
[Technical Lead]
Senior security engineer with hands-on SIEM, threat hunting and red team experience in
Ethiopian environments — core banking, mobile money and agent networks. AAU graduate.
CEH · OSCP · SIEM architecture
No cash draw during runway — equity only
Head of GRC & Biz Dev
[GRC Lead]
Compliance and audit background inside an Ethiopian financial institution. Has been on the
buyer's side of an NBE directive review — knows what evidence regulators ask for and where institutions
fall short.
ISO 27001 LA · NBE directive experience
No cash draw during runway — equity only
Founders are unpaid through the raise. All ETB 7.5M of budgeted payroll goes to the operating
team. Founder salaries begin only at break-even — targeted within 24 months — at ETB 80,000–120,000/month,
below the market rate for their seniority. Advisory board in formation: former INSA and NBE technical
leadership, and a serving bank CISO.
Salary bands — Addis market, ETB per month
Benchmarked to Ethiopian IT salary survey data · USD at ~140 ETB/USD
SOC Analyst ×3IT Officer band
25,000 – 60,000$179 – $429
Security Engineer ×1InfoSec Officer band
40,000 – 80,000$286 – $571
SOC Team Lead ×1Cyber Specialist band
50,000 – 100,000+$357 – $714+
030K60K90K120K
Band floor — entry offerBand ceiling — certified, retained
Role
Ethiopian IT band
Count
ETB / month
Annual cash (ETB)
Starts
SOC Analyst
IT Officer
3
25,000 – 60,000
1.53M
Month 1
Security Engineer
InfoSec Officer
1
40,000 – 80,000
0.72M
Month 1
SOC Team Lead
Cyber Specialist
1
50,000 – 100,000+
0.90M
Month 1
GRC Analyst
Compliance Officer
1
35,000 – 70,000
0.63M
Phase 2 (mo 13+)
Founders ×3
—
3
No draw
—
From break-even
Phase 1 funded team
Five staff, Addis
5
at midpoint
3.15M
ETB 4.40M loaded
From cash to fully loaded
Basis
ETB / year
Base cash salary
Five staff at band midpoint
3.15M
Employer pension
11% of basic, private organisations scheme
0.35M
Allowances
Transport, comms, night-shift differential for the rota
0.45M
Medical & insurance
Group cover
0.20M
Certification sponsorship
CEH / OSCP / CISSP exams and training
0.25M
Fully loaded
≈ 1.40× base cash
4.40M
Assumptions to confirm before the meeting: founder cash draw held at zero through the 18-month runway ·
band midpoints used for the annual figures · loaded multiplier of 1.40× derived from the ETB 4.4M team cost in
the model · the ETB 7.5M payroll line runs 0.9M above straight-line 18-month cost, covering annual increments
and the mid-runway GRC hire.
Compensation is the talent moat, not an expense line. AAU and AAiT graduate thousands of
engineers a year into a market with almost no security career path. We pay at band midpoint on day one, sponsor
certification, and publish a two-step path from Analyst to Team Lead — so scarce talent concentrates here rather
than leaving for the Gulf. Every certification we fund also raises what we can charge for the analyst who holds it.
Coverage model, stated plainly. Five people cannot staff three shifts. In Phase 1, detection and
automated containment run 24×7×365 through the SIEM and SOAR; analysts are on console 06:00–22:00 EAT with a paid
on-call rota carrying P1 escalation overnight. A full three-shift desk arrives with Phase 2 headcount at
12 staff — which is what the ETB 40M ARR step funds.
📈 Per-Client Unit Economics
ETB 2.9M
Average annual contract value
≈ $21K — retainer plus one project a year
ETB 350K
Customer acquisition cost
≈ $2.5K — founder-led selling
ETB 7.2M
Lifetime value
≈ $51K at 2.5-year average retention
20 : 1
LTV : CAC ratio
Buyer universe is ~100 institutions
~2 months
CAC payback
Assessment fees often cover acquisition outright
115%+
Net revenue retention
Clients expand channel by channel
Smaller contracts, stronger ratios. Contract values are well below Western markets — but so is
every cost line except tooling. One analyst costs ETB 40–80K/month against an ACV of ETB 2.9M, which is why the
ratios improve rather than degrade at Ethiopian price points.
5 signed clientsETB 12M ARRISO 27001 certifiedBreak-even within 24 months
Where the money goes
ETB millions · total 31.0M
Tooling & Cloud
12.0M · 39%
Engineering Team
7.5M · 24%
Compliance & Legal
5.0M · 16%
Working Capital
3.5M · 11%
Sales & Marketing
3.0M · 10%
Tooling — the only significant USD exposureBirr-denominated spend
Line
ETB
What it buys
Tooling & Cloud
12.0M
SIEM, EDR, threat intel and in-country hosting — priced in USD
Engineering Team
7.5M
Five people for 18 months at Addis market rates, fully loaded
Compliance & Legal
5.0M
ISO 27001 certification, INSA registration, US entity upkeep
Working Capital
3.5M
Buffer for the long collection cycles of institutional clients
Sales & Marketing
3.0M
Threat report, industry forums, tender participation
Total raise
31.0M
≈ $220K · 18-month runway
Note the shape of this raise: tooling costs more than people. That inversion is the Ethiopian
opportunity — we can staff a credible SOC for less than the software it runs on, and every client added to the
shared stack lands on margin rather than on cost.