Alberta · Identity Threat Detection & Response (ITDR)

Identity Security for Alberta Businesses

"ITDR" just means watching for someone using a real employee login in a way that isn't actually that employee — and shutting it down before it goes further. No jargon required to understand why that matters, and it's included in every LogosCyber plan.

What It Actually Is

Think of it as a bodyguard for your logins, not your computers.

Most security tools watch your devices — is there a virus, is a file behaving strangely. Identity threat detection watches something different: how your employees actually log in, day to day. What time they usually sign in, what device, roughly where from.

When a login shows up that breaks that pattern — the right password, but from a country your business has never touched, at 3am, on a device nobody recognizes — that's flagged immediately. Not because anything was "hacked" in the traditional sense. Because someone is using real, correct credentials in a way that doesn't look like the real employee.

389%
Year-Over-Year Surge
in account compromise attacks in 2025, now making up over half of all attacks observed
$360M
Reported Losses
from account takeover fraud in 2025 — the first year the FBI tracked it as its own category
24/7
Continuous Monitoring
every employee login is watched around the clock, on every LogosCyber plan

Sources: eSentire 2026 Cyberthreat Landscape Report; FBI Internet Crime Complaint Center (IC3) 2025 Report.

Why This Actually Matters

A stolen password doesn't look stolen to most security tools.

Here's the part that surprises people: a stolen login usually doesn't come from your business getting hacked directly. It comes from an employee's password showing up somewhere else — a breach at a retailer, a reused password, a convincing phishing email. If you want the fuller picture of how that actually happens, that's exactly what dark web monitoring is built to catch before it's ever used.

Once a criminal has that password, they don't need to "hack" anything — they just log in like anyone else would. Antivirus doesn't flag a correct password. A firewall doesn't block a real login. The only thing that catches it is something watching for behaviour that doesn't match the person the credentials belong to. That's the specific job identity threat detection does.

The Jargon, Decoded

Terms you might see, translated.

What the industry calls itWhat it actually meansWhy it matters to you
ITDRWatching how people log in, not just if they canShort for Identity Threat Detection & Response — the umbrella term for exactly what's on this page.
Impossible TravelLogging in from two places too far apart, too fastIf an employee signs in from Edmonton and then, twenty minutes later, from another country, that's physically impossible — and an instant, reliable red flag.
Session HijackingStealing an already-unlocked loginInstead of stealing a password, an attacker steals the active session token after someone's already logged in — skipping the password and MFA prompt entirely.
MFA FatigueSpamming approval requests until someone taps "yes"An attacker who already has a password triggers repeated login approval pop-ups, hoping a tired employee approves one just to make it stop.

How It Actually Runs

The process, start to finish.

1

Normal behaviour gets learned

The system builds a picture of how each employee actually logs in — typical hours, typical devices, typical locations — so it knows what "normal" looks like for them specifically.

2

A break in the pattern gets flagged

An unusual location, an impossible travel gap, or a device that's never been seen before triggers an immediate alert — in real time, not the next morning.

3

The account gets locked, a human confirms

Access is suspended and the active session is killed automatically, then a real analyst reviews it — so a legitimate login from a hotel on a work trip doesn't lock someone out for good.

Included, Not Upsold

Identity threat detection is in every LogosCyber plan.

This isn't a feature you have to upgrade to get. It's part of the baseline 24/7 protection.

Common Questions

What business owners ask before signing up.

“We already use multi-factor authentication — isn't that enough?”

It helps, but it isn't the whole picture.

MFA stops a lot of attacks, but not session hijacking or MFA fatigue attacks that trick someone into approving a login themselves. This catches what MFA alone lets through.

“How is this different from just having a strong password policy?”

A strong password can still be stolen.

Password policy reduces guessing. It does nothing once a password is already stolen and being used correctly — which is exactly the situation this is built to catch.

“What if it flags a false alarm, like me logging in from a hotel on a trip?”

That's expected, and handled.

Unusual-but-legitimate logins get a quick human review rather than a permanent lockout — the goal is catching real threats, not punishing business travel.

“Do employees notice this running in the background?”

No, not in normal day-to-day use.

It runs silently unless something looks wrong. Nobody has to do anything differently to be protected by it.

Get Started

Find out if your logins are actually being watched.

A free, no-obligation security assessment tells you exactly where things stand — no jargon, no pressure.

See Your Risk Score → Pricing→