Plaidnox InfoSec
PLX-2025-011  .  Confidential
CSaaSMonthly ReportApril 2025

Cybersecurity-as-a-Service
Monthly Security Report . Heron Logistics

Monthly managed security service state report for [REDACTED]. Coverage summary, alert statistics, incidents resolved, and next-cycle priorities. Service ref. SVC-2025-HLG.

Report IDPLX-2025-011
PeriodApril 2025
Service LevelSLA Achieved
Service byPlaidnox InfoSec
01 . Monthly Summary

April 2025 Security State

Plaidnox CSaaS delivered full SLA compliance for [REDACTED] in April 2025. 2,847 security alerts were processed across all monitoring surfaces. Of these, 2,801 were resolved as benign or low-priority. 46 required analyst triage, of which 3 were elevated to confirmed incidents. All three incidents were contained and remediated within the agreed MTTR SLA of 4 hours.


02 . Coverage Summary

Monitoring coverage

2,847
Alerts Processed
99.8%
SLA Uptime
3
Confirmed Incidents
1.9h
Avg MTTR
Coverage AreaAssets MonitoredAlert VolumeCoverage
Endpoint (EDR)847 endpoints1,204100%
Cloud (AWS / Azure)3 accounts892100%
Email Security1,240 mailboxes543100%
Network (IDS/IPS)12 segments20894% (2 segments pending)

03 . Incident Summary

Confirmed incidents . April 2025

INC IDTypeSeverityDetectedResolvedStatus
INC-042Credential stuffing against VPN portalHighApr 04 08:12Apr 04 10:01Closed
INC-043Lateral movement attempt . compromised service accountCriticalApr 17 14:33Apr 17 16:02Closed
INC-044Phishing email with credential-harvesting link (3 users clicked)HighApr 23 09:44Apr 23 11:15Closed
?INC-043 Post-Incident Note: The compromised service account (used for automated deployment) had excessive permissions inherited from a legacy role. Least-privilege remediation for service accounts is scheduled for May Sprint 1.

04 . Next Cycle Priorities

May 2025 scheduled activities

ActivityTarget DateOwner
Service account least-privilege remediationMay 09Plaidnox / IT
Network IDS extension to remaining 2 segmentsMay 16SecOps
Monthly threat intelligence briefingMay 20Plaidnox
Quarterly vulnerability scan cycleMay 28Plaidnox

Conclusion
SLA achieved . one high-priority remediation outstanding from INC-043
April delivered strong performance with full SLA compliance and all three incidents contained within the MTTR target. The service account permissions gap identified in INC-043 is the primary outstanding action item for May and represents a systemic risk that extends beyond this incident to other deployment-related accounts.
Plaidnox InfoSec . PLX-2025-011
Confidential . Authorised Distribution Only