Security Platform · U Mobile — 2026
“You cannot segment a network you cannot see.”
Services
Tech
Built by
Full case study →Rahimi Rusyuddin
Designed and built end to end — sole engineer
Industrial placement at U Mobile — Information Services / Information Security, Mar – Jul 2026. Presented to the CIO.
Disclosure
Built inside a telco security division. This case study covers architecture and engineering decisions only — no real hostnames, addresses, topology or asset data appears anywhere on this page.
Documentation
Less manual effort
Hours, down from 93.17
Months, concept to production
Engineer
CYFER ONE — known internally as Tangkap — is a platform built for U Mobile that discovers what is actually running on the network, consolidates months of scan results into one authoritative asset view, and gives the security team the evidence they need to make segmentation decisions.
The Challenge
Server inventory lived in spreadsheets that went stale the moment they were saved. Scans produced raw output nobody had time to reconcile, so the question "what is on this segment, and should it be?" took days to answer and the answer was never quite trusted. Without a dependable inventory, segmentation work stalls — you cannot draw a boundary around assets you have not confidently enumerated.
Our Solution
A Python worker runs Nmap over SSH against defined scopes and streams results back as JSON events; a Node.js orchestration layer supervises those runs with heartbeats and process-liveness checks, so a hung scan surfaces as a failure instead of silence. Results land in a temporal PostgreSQL model that keeps every monthly snapshot while projecting a single current-state view. On top sit division-scoped RBAC, scheduled Excel compliance reports published to SharePoint, and an AI assistant that answers natural-language questions by querying the live database through tool-calling.
The Outcome
The monthly discovery cycle went from 93.17 hours of manual work — SSH sessions, a 90-hour scan, then hours of Excel reconciliation — to 8.9 hours end to end, a 91% reduction. Enrichment, reconciliation, registration and publishing each dropped to under five minutes, and the InfoSec team adopted the system for daily and ad-hoc use. Segmentation discussions now start from evidence rather than recollection. Delivered to production and presented to the CIO at the close of the placement.
Full Tech Stack
← No previous