Cybersecurity and IT for Libyan institutions
See your risks clearly. Defend what matters.
Oyoon Altaqnya helps banks, telecom operators and government institutions in Libya design, build, test and govern secure technology — through proven solutions, hands-on engineering services, independent consulting and training that stays with your team.
Coverage across the NIST Cybersecurity Framework
Our offerings map to the six functions of NIST CSF 2.0, the framework many regulators and boards already use. Select a function to see how we help.
Govern (GV)
Govern
- Governance, Risk & Compliance (GRC) Solutions
- Security Assessment Services
- Solution Architecture Services
- Security Strategy and Program Consulting
- Governance, Risk and Compliance Consulting
- Cyber Risk Assessment Consulting
- Compliance Readiness Consulting
- Business Continuity and Resilience Consulting
- IT Strategy and Advisory Consulting
- Executive Cyber Briefings Training
Identify (ID)
Identify
- Unified Endpoint Management (UEM) Solutions
- Mobile Device Management (MDM) Solutions
- Endpoint Compliance Solutions
- Attack Surface Management (ASM) Solutions
- Vulnerability & Exposure Management Solutions
- Cyber Threat Intelligence (CTI) Solutions
- IT Asset Management (ITAM) and CMDB Solutions
- Cyber Asset Attack Surface Management (CAASM) Solutions
- Cloud-Native Application Protection Platform (CNAPP) Solutions
- Penetration Testing Services
- Vulnerability Assessment Services
- Security Assessment Services
- Cyber Risk Assessment Consulting
Protect (PR)
Protect
- Unified Endpoint Management (UEM) Solutions
- Endpoint Compliance Solutions
- Cloud-Native Application Protection Platform (CNAPP) Solutions
- Identity & Access Management (IAM) Solutions
- Privileged Access Management (PAM) Solutions
- Multi-Factor Authentication (MFA) Solutions
- Patch Management Solutions
- Next-Generation Firewall (NGFW) Solutions
- Network Access Control (NAC) Solutions
- SASE / SSE Solutions
- Secure DNS Solutions
- Micro-Segmentation Solutions
- DDoS Protection Solutions
- Email Security Solutions
- Data Loss Prevention (DLP) Solutions
- Encryption Solutions
- Key Management Solutions
- Web Application & API Protection (WAF / WAAP) Solutions
- Ransomware Protection Solutions
- Immutable Backup & Cyber Recovery Solutions
- Penetration Testing Services
- Configuration Review Services
- Solution Architecture Services
- Solution Integration Services
- Security Awareness Training Training
- Product Enablement Training
Detect (DE)
Detect
- Cyber Threat Intelligence (CTI) Solutions
- Email Security Solutions
- Data Loss Prevention (DLP) Solutions
- Web Application & API Protection (WAF / WAAP) Solutions
- Identity Threat Detection & Response (ITDR) Solutions
- EDR / XDR Solutions
- Ransomware Protection Solutions
- Network Detection & Response (NDR) Solutions
- Security Information & Event Management (SIEM) Solutions
- Managed Detection & Response (MDR) Solutions
- Compromise Assessment Services
- Solution Integration Services
- Technical and SOC Training Training
Respond (RS)
Respond
- EDR / XDR Solutions
- Security Information & Event Management (SIEM) Solutions
- Managed Detection & Response (MDR) Solutions
- Ticketing / IT Service Management (ITSM) Solutions
- Compromise Assessment Services
- Technical and SOC Training Training
- Cyber Crisis Tabletop Exercises Training
Recover (RC)
Recover
- Immutable Backup & Cyber Recovery Solutions
- Business Continuity and Resilience Consulting
- Cyber Crisis Tabletop Exercises Training
Four ways we work with you
-
Solutions
Security and IT platforms from leading vendors, selected, sized, deployed and tuned for your environment.
33 offerings
-
Services
Penetration testing, assessments, configuration reviews, architecture and integration carried out by our engineers.
7 offerings
-
Consulting
Independent advice on strategy, risk, governance, compliance and business continuity.
6 offerings
-
Training
Awareness, technical and executive programs that build lasting capability inside your organization.
5 offerings
A clear view across the whole framework
NIST CSF 2.0 organizes cybersecurity into six functions. Here is what each one means, and how many of our offerings support it.
-
Govern
GVSet the strategy, policy and oversight for cybersecurity risk.
10 offerings
See Govern offerings -
Identify
IDUnderstand your assets and the risks they face today.
13 offerings
See Identify offerings -
Protect
PRPut safeguards in place to manage those risks.
26 offerings
See Protect offerings -
Detect
DEFind and analyze possible attacks and compromises.
13 offerings
See Detect offerings -
Respond
RSTake action on a detected incident.
7 offerings
See Respond offerings -
Recover
RCRestore the assets and operations an incident affected.
3 offerings
See Recover offerings
Built for regulated, critical sectors
-
Banking and financial services
Compliance-driven security for payment systems, SWIFT connectivity, digital channels and customer data.
-
Telecommunications
Protecting core networks, subscriber data and critical infrastructure at operator scale.
-
Government and public sector
Risk assessments, governance and secure architecture for ministries, authorities and public institutions.
-
Oil and gas
Protecting production, pipeline and terminal systems and the corporate networks connected to them.
How an engagement runs
-
Discover
We learn your environment, obligations and priorities before proposing anything.
-
Assess
We measure where you stand with evidence — tests, reviews and interviews.
-
Design
We design the target state and a realistic roadmap to reach it.
-
Implement
We deploy and configure the right controls and platforms, integrated with what you already run.
-
Validate
We test that controls work as intended and fix what doesn't.
-
Enable
We hand over documentation and train your team so the capability stays in-house.
What you can expect from us
- Evidence over opinion
- Findings come with proof, severity reasoning and clear remediation steps your teams can act on.
- International standards, local context
- We work to NIST, ISO/IEC, CIS, OWASP and PCI practice while understanding how Libyan institutions operate.
- Arabic and English delivery
- Reports, workshops and training in the language your stakeholders prefer.
- Knowledge transfer built in
- Every engagement ends with documentation and handover, not dependency.
Suspect a compromise?
If you see signs that an attacker may already be inside your environment, a compromise assessment tells you what happened, what is affected and what to do next.
Start with a conversation
Tell us what you need to protect or prove. We'll suggest the smallest useful first step.