Cybersecurity • • 8 min read

From alert queues to agentic defense: how CDP-MapSync's monitoring evolved

How a practical continuous-monitoring partnership grew from endpoint telemetry and engineer-led investigation into a human-governed Agentic SecOps architecture.

Edwin Kairu

Edwin Kairu

Co-Founder and CEO, Tabiri Analytics

Agentic security operations protecting connected municipal geospatial infrastructure

Continuous monitoring is easy to describe and difficult to operate. Collecting logs is only the first step. Someone still has to separate routine noise from evidence of compromise, understand what happened across multiple systems, decide what deserves escalation and give the customer a practical next action.

Our work with CDP-MapSync taught me that lesson in the most useful way: over time, on real systems, alongside a customer willing to improve with us. What began as a 30-day sensor trial in 2019 became a renewed endpoint-monitoring deployment in 2023 and an ongoing security relationship. Today, the same operational foundation is evolving again, this time around Agentic SecOps.

The relationship started with visibility

CDP-MapSync supports engineering and utility-infrastructure work, including proprietary GPS and GIS systems. In 2019, after discussing how our teams could collaborate, we offered a continuous-monitoring trial. We completed a pre-engagement review, documented the technical architecture and brought a preconfigured network sensor to CDP's office.

That early deployment established the pattern we still value: understand the environment first, deploy with the customer rather than around them and turn observations into specific remediation. It also gave both teams a shared operating history before continuous monitoring was expanded in 2023.

The original operating loop

Endpoint agents collected system activity and forwarded it to Tabiri's cloud security stack. Detection rules generated alerts. Our cybersecurity engineers investigated the underlying logs, documented findings and worked directly with CDP-MapSync on remediation.

In 2023, monitoring moved onto the endpoints

The 2023 rollout began system by system. We helped install and register lightweight agents, confirmed that each endpoint was reporting and troubleshot the inevitable deployment issues. The agents consumed few local resources because their role was focused: forward telemetry to our cloud sensor, where indexing, analytics and alert generation took place.

The first assessment quickly produced useful work. We grouped issues by severity, identified a high-severity PostgreSQL exposure on two systems and tracked the customer's corrective action in a remediation plan. As coverage expanded, we also advised CDP to include systems hosting shared data because mounted shares can become a path for malware to move between machines.

sensors

Collect

Lightweight endpoint agents continuously forwarded security telemetry without moving the analysis burden onto CDP's systems.

manage_search

Investigate

Tabiri engineers reviewed alerts and raw activity, correlated evidence and distinguished genuine risk from routine behavior.

fact_check

Improve

Prioritized reports and remediation tracking turned technical findings into concrete changes the customer could verify.

The service proved itself between reports

A monitoring service earns trust in the moments between scheduled reviews. We watched for endpoints that stopped reporting, contacted CDP when an agent needed to be restarted and followed anomalous activity far enough to recommend proactive action even when we had not observed a breach.

CDP's own account of the engagement captured what mattered: setup was straightforward, the assessment produced practical recommendations, critical items were corrected quickly and ongoing reports were easy to interpret. The team also credited the monitoring process with detecting anomalous activity and intercepting potentially harmful software. That feedback mattered because it measured the service by outcomes, not alert volume.

"The continuous monitoring of our systems has been seamless with easy to interpret reporting."

David Carter, President, CDP-MapSync

The limit was never collection. It was human attention.

The original architecture did what it was designed to do, but every alert still entered a human queue. An engineer opened the event, gathered context, checked the endpoint, formed a hypothesis and wrote the result. False positives consumed the same scarce attention before they could be dismissed. Good analysts could work methodically, but they could not investigate thousands of events at machine speed.

That became the design question behind our next phase: could we preserve the telemetry, controls and accountability we had built while giving each monitored system an investigative capability of its own?

Agentic SecOps changes who does the first investigation

In the evolved architecture, the security information and event management platform still provides centralized detection and visibility. An orchestrator can turn a health-check requirement or a specific alert into a bounded investigative task. An agent on the monitored endpoint receives that task, inspects the local evidence, uses approved tools and reports its findings back in structured natural language.

The difference is operational. A listening-services audit can be delegated and returned without an analyst manually stepping through every command. A suspicious web request can trigger focused review of thousands of related records in minutes. Multiple endpoint investigations can proceed in parallel, while the orchestrator maintains the task history and the human team supervises the system.

What remains human

Autonomy has a boundary. Agents can gather evidence, reason over context, test hypotheses and recommend action. Potentially destructive remediation remains behind explicit human authorization. Engineers define scope, monitor the agents, review material findings and retain the final say.

Scale comes from hierarchy, not unchecked autonomy

I do not see Agentic SecOps as removing security engineers. I see it changing their unit of work. Instead of spending most of a shift opening alerts and assembling context, engineers manage investigative agents, improve detection logic, authorize sensitive actions and focus on incidents where judgment has the highest value.

The architecture can also be adapted to the customer's data requirements. Reasoning may use a governed cloud model, or it can run on local infrastructure for sensitive or disconnected environments. Local memory allows an agent to retain task state and build on previous work. In either model, telemetry, guardrails, auditability and a clear chain of command remain essential.

What years of monitoring taught me

The most important part of this evolution is not the language model. It is the operational foundation underneath it. We already knew how CDP's endpoints reported, how to notice gaps in coverage, how to communicate a finding and how to move from evidence to remediation. Agentic capabilities make that loop faster and more parallel; they do not replace the need to engineer it carefully.

CDP-MapSync's journey shows what responsible adoption looks like to me. Start with visibility. Build trust through useful findings and consistent follow-through. Automate the repetitive investigation only after the controls are understood. Then keep people at the points where authority, business context and accountability matter most. That is how continuous monitoring becomes agentic defense without becoming uncontrolled defense.

Continuous Visibility. Agent-Accelerated Investigation.

Evolve your monitoring into Agentic SecOps

Combine endpoint telemetry, autonomous investigation and human-controlled response in one accountable security operation.