Alberta · Identity Threat Detection & Response (ITDR)
Identity Security for Alberta Businesses
"ITDR" just means watching for someone using a real employee login in a way that isn't actually that employee — and shutting it down before it goes further. No jargon required to understand why that matters, and it's included in every LogosCyber plan.
What It Actually Is
Think of it as a bodyguard for your logins, not your computers.
Most security tools watch your devices — is there a virus, is a file behaving strangely. Identity threat detection watches something different: how your employees actually log in, day to day. What time they usually sign in, what device, roughly where from.
When a login shows up that breaks that pattern — the right password, but from a country your business has never touched, at 3am, on a device nobody recognizes — that's flagged immediately. Not because anything was "hacked" in the traditional sense. Because someone is using real, correct credentials in a way that doesn't look like the real employee.
Sources: eSentire 2026 Cyberthreat Landscape Report; FBI Internet Crime Complaint Center (IC3) 2025 Report.
Why This Actually Matters
A stolen password doesn't look stolen to most security tools.
Here's the part that surprises people: a stolen login usually doesn't come from your business getting hacked directly. It comes from an employee's password showing up somewhere else — a breach at a retailer, a reused password, a convincing phishing email. If you want the fuller picture of how that actually happens, that's exactly what dark web monitoring is built to catch before it's ever used.
Once a criminal has that password, they don't need to "hack" anything — they just log in like anyone else would. Antivirus doesn't flag a correct password. A firewall doesn't block a real login. The only thing that catches it is something watching for behaviour that doesn't match the person the credentials belong to. That's the specific job identity threat detection does.
The Jargon, Decoded
Terms you might see, translated.
How It Actually Runs
The process, start to finish.
Normal behaviour gets learned
The system builds a picture of how each employee actually logs in — typical hours, typical devices, typical locations — so it knows what "normal" looks like for them specifically.
A break in the pattern gets flagged
An unusual location, an impossible travel gap, or a device that's never been seen before triggers an immediate alert — in real time, not the next morning.
The account gets locked, a human confirms
Access is suspended and the active session is killed automatically, then a real analyst reviews it — so a legitimate login from a hotel on a work trip doesn't lock someone out for good.
Included, Not Upsold
Identity threat detection is in every LogosCyber plan.
This isn't a feature you have to upgrade to get. It's part of the baseline 24/7 protection.
Common Questions
What business owners ask before signing up.
It helps, but it isn't the whole picture.
MFA stops a lot of attacks, but not session hijacking or MFA fatigue attacks that trick someone into approving a login themselves. This catches what MFA alone lets through.
A strong password can still be stolen.
Password policy reduces guessing. It does nothing once a password is already stolen and being used correctly — which is exactly the situation this is built to catch.
That's expected, and handled.
Unusual-but-legitimate logins get a quick human review rather than a permanent lockout — the goal is catching real threats, not punishing business travel.
No, not in normal day-to-day use.
It runs silently unless something looks wrong. Nobody has to do anything differently to be protected by it.
Get Started
Find out if your logins are actually being watched.
A free, no-obligation security assessment tells you exactly where things stand — no jargon, no pressure.
See Your Risk Score → Pricing→