Platform · The handful of events that deserve a human

Detection & response

Exposure state feeds detection, so an alert on an asset that sits on a live path to regulated data is not treated like an alert on a static marketing page.

93%

of pages in the demo tenant tied to a live path

Capabilities

What detection & response actually does

01

Path-weighted alerting

Alert priority inherits the asset's path position and destination value.

02

Case timeline

Detection, asset context, recent changes and related findings assembled in one place.

03

Response runbooks

Containment steps written against your own architecture, versioned alongside it.

04

SIEM handoff

Structured events to Splunk, Sentinel, Elastic or Chronicle with stable entity identifiers.

In the console

See it working on demo data

  • Alert priority inherits the asset's path position and the value of what that path reaches.
  • Case timelines assemble detection, asset context, recent changes and related findings in one place.
  • Structured events stream to Splunk, Sentinel, Elastic or Chronicle with stable entity identifiers.
LodemarkDemo tenantNorthfleet Group · 4 cloud accounts · 11 regions · 3 subsidiariesHead of Security OperationsSigned in as Asha Rehman
Security overviewAssessed 16 Sep 2026, 08:40 UTC · Rolling 90 days
Exposure score34-24%vs. 58 at programme start
Live attack paths7-19%reaching a Core asset
Critical findings12-41%open past 7 days
Median remediation4.2d-6.1d%critical severity

Exposure trend

Weekly score across the selected range. Lower is better.

Below 4040–65Above 65

Band: Moderate · method published in the assurance pack.

Coverage

What discovery can currently see.

  • Cloud accounts connected4/4
  • Domains under continuous discovery118/124
  • Workloads with agent or API coverage4,512/4,870
  • Identity providers federated3/3

Strata

Assets by depth, and how many are currently exposed.

  • S1 Edge1,28437 exposed
  • S2 Gateway31214 exposed
  • S3 Workload4,87061 exposed
  • S4 Identity9,61528 exposed
  • S5 Core4866 exposed

Needs a decision today

4 critical findings and 4 live paths reaching Core.

  • Unauthenticated file listing on the partner document exchangeFND-8841 · supplier-docs.northfleet.io · 7d oldin progress
  • EDI gateway runs an end-of-life TLS stackFND-8836 · legacy-edi.northfleet.io · 19d oldopen
  • Machine identity holds write access across three accountsFND-8829 · svc-datalake-ingest · 14d oldtriaged
  • Invoice archive readable by the analytics lake roleFND-8824 · nfg-invoice-archive · 12d oldin progress

Activity

Discovery, intelligence and posture changes in one record.

08:41 UTCLook-alike domain registered

northfleet-invoices[.]co resolved for the first time. Certificate transparency match on the supplier portal name.

07:58 UTCNew edge asset discovered

supplier-docs.northfleet.io began answering on a second origin pool in eu-west-2.

06:12 UTCPath AP-01 re-scored

Blast radius widened after the analytics role gained read on a fourth prefix.

YesterdayChoke point applied on AP-05

Enforcement point deployed between the campus range and the depot gateway.

YesterdayFND-8749 verified remediated

Deploy identity subject claim narrowed to 13 active repositories.

2 days agoHalverstone infrastructure expanded

Three new hosts in 185.214.44.0/24 matched the remote-access scanning pattern.

3 days agoCloud account connected

Subsidiary account nfg-baltics-prod onboarded; 412 assets discovered in the first sweep.

Questions

About detection & response

Everything else is in the documentation.

No. It enriches it. Exposure context is streamed as structured events so your existing analytics rules can weigh it.

Next step

Put detection & response against your own estate

A four-week proof of value connects one cloud account, your DNS and your identity provider, and ends with a written readout. Lodemark stays read-only throughout.

Book a walkthroughOpen the console demo

Illustrative product data. Nothing on this site performs a live scan.