Nestack Agent Care
Industries / Telecom / Security duty agent

Telecom AI agent · security duty

Telecom Security-Duty AI Agent

Run one discovery into two notifications — the UK three-hour Ofcom expectation and the EU twenty-four-hour early warning — and leave every notification to a named person.

4–6 weeksTypical delivery
Your stackDeployment
Two clocksPerson notifies
Agent CareAfter launch

What this agent does

Drafts both notifications, sends neither

In
01

A compromise is discovered, and one moment of awareness starts both clocks, in the UK and in the EU.

02

An effect is weighed against the s.105K(2) matters: period, persons, geography, extent of activities.

Reason
03

An urgent UK case runs on Ofcom policy of 15 September 2023: initial notification usually within 3 hours.

04

An EU incident crosses the significance line, and Article 23(4) opens at 24 hours and closes at 72.

05

A final EU report falls one month after the notification is submitted, not one month after awareness.

Decide
06

A review falls due, and UK regulation 11 wants a written assessment of the next 12 months of risk.

07

A supplier contract is in force, and the UK Code reaches all contracts by 31 March 2027.

Out
08

A Member State has not transposed, and the old EECC security articles went on 18 October 2024.

09

Execute write actions only inside the approval boundaries agreed during implementation.

Product statement

The agent drafts and keeps the record; a board-level person or committee holds the responsibility, a named person notifies, and the provider answers for it.

Example workflow

One compromise, discovery to notification

AgentHuman
1Compromise discoveredMonitoring tools, incident tickets, supplier advisories or a CSIRT contact
2Effect assessed against the limbsPeriod, persons, geographical area and extent of activities, and the near-miss limb with them
3Notifications draftedThe UK notification and the EU early warning, drafted from one set of facts
4Controls appliedClock checks, jurisdiction checks, evidence-sufficiency checks and completeness confidence
No human action required

Stages 1 to 4 run unaided, and nothing is notified at any of them — the agent is drafting, and the security lane opens at the completeness gate.

5DecisionBranches at the completeness gate
Evidence sufficient

Goes to the named notifier to send.

Anything thin

Adds a regulatory counsel read first.

Security review

The draft is held with its clocks, its evidence and the jurisdiction each one belongs to.

Notify the regulator · Append evidence · Send to counsel
Notified — by a named person
6Incident and assessment records updatedOnly where write access and security policy allow it
7Outcome evaluatedClock margin, effect evidence, counsel corrections and what the post-incident review found
Corrections

Each counsel correction is counted in the evaluation.

What should not run autonomously

Human approval stays in control

Outside the boundary — human approval required8 items
Deciding the UK significance test is not met.
Notifying Ofcom or any EU national authority.
Sending an EU early warning under Art. 23(4).
Approving EU risk-management measures under Art. 20.
Automation boundaryAgent acts unaided
Start both clocks from the one moment the provider became aware.
Weigh the effect against each s.105K(2) matter and record the answer.
Draft the UK and EU notifications from one assembled set of facts.
Hold the twelve-month written assessment current against what changed.
Nothing reaches a regulator except by a named person, inside the agreed boundaries.
Judging that the near-miss limb has not been reached.
Telling a customer their service went unaffected.
Concluding the overall forward risk is low.
Changes to clocks, significance rules or templates.

Example output

One compromise, annotated

Our NOC copilot declares the cause; this record is what two regulators are notified from.

Notification draft · single compromiseIllustrative example
Compromise
Drafted as
Clock
Evidence of record
Confidence
Held for
Core signalling node failure
UK initial notification, urgent, effect assessed
Hour 2 · UK 3-hour clock
Monitoring and incident record, 12 August 2026
Held unsent
The named notifier, in person
As receivedTaken from the monitoring tools and the incident record — it reaches as far as the logging does.
What the record holds Awareness time-stamp Effect-limb evidence Assessment extract
Why no significance call hereSignificance is the s.105K test for a person, not a model output.
ActionNotify the regulatorAppend evidenceSend to counsel
What the score decidesBelow the configured threshold the draft picks up a counsel read before it moves.

Value

Where AI adds value

The same four claims, placed at the point in the workflow where each one applies.

Where the value landsValue 01 – 04
Every compromiseFrom the monitoring tools that saw it
03Evidence

Where the notification goes

Our outage and disaster reporting agent files the US reports from this same discovery — three regulators there, three clocks, another signer. Financial-sector resilience sits under DORA, a separate regime with its own register and its own clocks.

01Approved path

Three hours is not twenty-four

Ofcom policy of 15 September 2023 expects an urgent UK initial notification usually within 3 hours; EU Article 23(4) allows 24 hours for the early warning.

02Human review

What was checked, and what was not

No Ofcom penalty specifically for the s.105K or s.105N reporting duties was found, and no tier-by-tier compliance assessment is published.

04Build an evidence trail

The compromise, the effect assessed against it and the person who notified stay on the record.

Integrations

Typical integrations

Five system groups connect to the same agent. Which of them are in scope is decided in discovery.

Notification channelsOfcom incident reporting
National CSIRT contacts
Security monitoringSIEM · network monitoring
Vulnerability and patch records
Governance recordsPolicy · board oversight
Supplier and contract register

Agent

Security duty evidence

Reads the compromise
Drafts both notifications
Holds for the notifier

Incident and case systemsServiceNow · Jira
Post-incident review files
Observability & evaluationOpenTelemetry · Langfuse
Supported monitoring/evaluation sources

Integration availability depends on the client's existing systems and API access.

Agent controls

Six passes between the model and the notification

Six passes, every one narrower than the pass before it. What is still there at the end is mapped below.

L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modePull the agent back to assessment work when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt and rule changes; the revised UK Code is not yet laid in Parliament.Track
L4TraceabilityRecord the compromise, the clocks, the evidence and every read of each draft.Record
L3Notifier releaseHold each draft for a named person; it governs sending, not whether an effect is significant.Gate
L2Policy guardrailsTest each draft against the UK policy clock and the EU Article 23(4) cascade separately.Restrict
L1Confidence thresholdsRoute a thin draft to a counsel read before the named notifier sees it.Require review
Model coreDrafts assembled — the compromise, the effect, the clocks and completeness
L1 – L2Test whether a draft may stand
L3Puts the notification in a person's hands
L4 – L5Keep the compromise and the assessment behind it
L6Holds the notification undrafted when signals degrade

How Nestack evaluates it

Evaluate the whole assembly — not only the notification that comes out.

Coverage runs the whole depth of the workflow, and every layer is cut by slice.

Surface — the notification a regulator reads
Depth of coverage ▼
E1Final-output evaluationDid the draft record the awareness moment that started the clocks?
E2Step-level evaluationDid the agent use the right jurisdiction, the right clock and the current assessment?
E3Tool evaluationDid it read and write the correct incident record and the correct assessment?
E4Confidence calibrationDo low-confidence drafts actually attract more counsel corrections?
E5Slice evaluationHow does performance change across specific jurisdictions?
E6Business outcomeHow many drafts needed a correction before a person notified?
Floor — the outcome the provider answers for

Failure modes

Where each failure originates in the agent

Seven failure modes, each placed where it first starts in the agent.

Agent lifecycleDirection of processing →
01 · Retrieval1 mode
IW-03

Stale assessment read

The assessment read is not the one now current.

Stage gathersThe compromise, the effect, the clocks and the evidence
02 · Reasoning2 modes
IW-04

Effect judged insignificant

A significant effect is reasoned away by the model.

IW-06

Wrong jurisdiction applied

An EU clock is run against a UK compromise.

Stage proposesThe effect assessed, the clocks and completeness
03 · Tool / write2 modes
IW-02

Thin draft moved on

A draft advances with the counsel read skipped.

IW-05

Clock started at escalation

The clock is anchored to escalation, not awareness.

Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
IW-01

Notified, evidence unrecorded

The record shows a notification but not what drove it.

Stage returnsThe notifications a person sends and the record
05 · Change / Version1 mode
IW-07

Silent clock regression

A rule change moves a clock without moving the record.

Stage tracksModel, prompt, clock rules and notification fields
Sev-1 · a notification leaves without a person Sev-2 · a wrong clock reaches the record Sev-3 · source degrades, draft holds unsent

Affected slices

One jurisdiction absorbs the corrections

A jurisdiction-level assessment-currency figure can read clean while one jurisdiction carries most of the corrections. Nestack reports the counsel-correction rate by jurisdiction, not only in total.

Slice performance — reported separately, not only in aggregateIllustrative example
SliceFailure rateLift Lift vs. thresholdStatus
UK urgent compromises6.7%3.6× Review
EU states not yet transposed4.8%2.6× Review
EU states with NIS2 transposed3.0%1.6× Watch
UK non-urgent compromises1.5%0.8× Normal
Bar: counsel-correction-rate lift vs. UK non-urgent baseline · scale 0–4.0× · tick marks the 2.0× review threshold 2 of 4 slices over threshold

Evidence-linked improvement

What a missed clock costs

A cycle ends when the missed reporting clock is a standing case. That suite is what the next assessment written is measured against.

Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect

Counsel-correction rate rises in one jurisdiction.

02Diagnose

The three-hour expectation that lives nowhere in the Act somebody read is traced back until one cause remains.

03Improve

Every change leaves numbered, with the measures that caused it filed beneath.

04Verify

A single red measure case is enough to keep the release back.

05Learn

The case is permanent, and the reporting rules are rewritten with it.

Learn → DetectThe return edge. The next assessment is measured against a suite one case longer.

Typical build scope

Twelve workstreams across six weeks

The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, notification assembly, evaluation, integration, then production validation and handover.

Workstream Week 1Week 2Week 3Week 4Week 5Week 6
01Security-duty discovery and boundary definition.
02Monitoring and governance sources.
03Significance-limb and reporting-clock mapping work.
04Compromise evidence ingestion.
05Jurisdiction, clock and record binding.
06Completeness scoring and counsel routing.
07Named-notifier release workflow.
08Incident and case-system integration.
09Significance and clock cases.
10Guardrails and board-oversight controls.
11Compromise-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallel Final scope and sequence confirmed in discovery

Engagement tiers

What each tier includes

Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.

Capability✓ in scope · — not at this tier PilotOne jurisdiction, one duty ProductionProduction notification workflow AdvancedMultiple jurisdictions / entities
Introduced at Pilot
Notification drafting to your rules
Named-person notification
Risk-assessment baseline
Introduced at Production
Reporting by jurisdiction
Release workflow in your systems
Approved write-back
Security-monitoring integration
Introduced at Advanced
Multi-jurisdiction security duties
Cross-border evidence packs
High incident volume
Multi-regulator notification controls
Build price From $5,000 From $8,000 Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, transaction volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.

What we need from you

What you bring, and what we build with it

Each input maps to a piece of build scope and a week in the delivery timeline.

You bringWe build with it
01Your security measures as implemented Measure-to-regulation binding and evidence captureWeek 1
02Representative compromises and incident records Effect-limb scoring, clock binding and the draft baselineWeek 2
03Your jurisdictions and notification channels Duty mapping, jurisdiction binding and the automation boundaryWeek 1
04Access to relevant APIs, feeds or exports Monitoring, governance and incident-source assessment, then integration setupWeek 2
05Assessments you would not want relied on Significance cases and the evaluation suiteWeek 4
06What no security assessment may conclude Completeness scoring, counsel routing, guardrails and release controlsWeek 3
07A named person to notify, and the board-level owner Named-notifier release workflow, then pilot and production validationWeeks 5–6
Nothing else is required Deployment, documentation and Agent Care handover are ours.

Delivery timeline

Four phases across six weeks

The widths here are the weeks the work actually takes, and the fifth week is shared for that reason.

Phase W1W2W3W4W5W6
Discovery W1
Build W2 – W3
Evaluate W4 – W5
Pilot & Launch W5 – W6
Week focus W1Security-duty discovery, jurisdiction mapping and the automation boundary W2Source integration and the risk-assessment baseline W3Notification assembly, clock logic and release controls W4Evaluation suite, significance cases and failure-mode testing W5Record integration, pilot compromises and targeted corrections W6One assessment year run under the responsible board member, then Agent Care handover
Reading the bandA band spans only the weeks its own work is named for. The fifth week doubles because two phases run inside it.
At the end of W6When the assessment record validates, Agent Care takes the agent on.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.

Next step · Telecom AI agent

Build a security-duty agent around two clocks that start from one discovery.

Show us how a compromise reaches you today and who notifies. Bring one recent case and we will run it through both clocks with you — the UK 3-hour Ofcom expectation of 15 September 2023 and the EU 24-hour early warning under Article 23(4) — from one moment of awareness.

Nestack Agents · telecom security dutyAGT-TL-24 · Agent Care available after launch