
Main Sweet Security partner in Poland
Sweet Security
Runtime CNAPP: real-time protection for cloud environments and AI agents
Sweet Security is a Runtime CNAPP that detects and blocks attacks on cloud infrastructure, workloads, applications and AI agents while the attack is still under way. A lightweight eBPF sensor and cloud logs build a behavioral baseline of the environment, and a single detection engine correlates events across every layer to cut MTTR to minutes, according to Sweet Security data.
ICWT is a Poland-based Authorized Sweet Security Partner and the vendor's main partner in the Polish market. We implement and run the platform for organizations in Poland and internationally.
- Authorized Sweet Security Partner
- Main partner in Poland
- Managed services
- Support in Polish and English
What Sweet Security does
Sweet Security watches a cloud environment as it runs, not on a scan schedule. An eBPF sensor on Linux, a Rust sensor on Windows and logs from AWS, Azure and Google Cloud feed one detection engine that ties cloud, workload and application events into a single incident. Sweet Security says it takes about two hours to bring an entire organization under protection, and puts MTTR at five minutes.
The platform covers four areas: runtime detection and response, visibility and risk prioritization, security posture and compliance, and AI security.
Runtime detection and response
CDR, ADR, CWPP and ITDR share one sensor and one behavioral baseline, and AI Storyline turns the events of an incident into an ordered timeline with response actions ready to run.
Visibility and risk prioritization
Sweet Security says the inventory and topology of the environment appear within minutes, and the platform ranks vulnerabilities, packages, APIs and permissions by what actually runs and is exposed to attack.
Posture and compliance
Runtime CSPM catches misconfigurations and drift as they happen, and we treat the CIS, NIST, SOC 2, ISO 27001 and GDPR checks Sweet Security publishes as evidence for the technical requirements of DORA and Poland's amended KSC act implementing NIS2, not as a mapping to those regulations.
AI security
AI-BOM and AI-SPM inventory models and agents, including shadow AI, and AIDR and MCP Gateway block prompt injection, unauthorized tool calls and data leakage as an agent runs.
Sweet Security products and services
19 products and servicesExplore the Sweet Security products ICWT implements and supports across runtime detection and response, visibility and risk prioritization, security posture and compliance, and AI security.
Runtime Detection and Response5
Cloud Detection & Response (CDR)
Real-time detection and blocking of cloud attacks
Application Detection & Response (ADR)
Real-time Layer 7 application protection
Cloud Workload Protection (CWPP)
An eBPF (Linux) and Rust (Windows) sensor for containers, Kubernetes, VMs and serverless
Identity Threat Detection & Response (ITDR)
Detection of human and non-human identity and secret abuse
AI Storyline (investigation)
An AI-generated incident narrative: what happened, what the impact is, who needs to act
Visibility and Risk Prioritization6
Cloud Visibility
Inventory, topology and a connection map of the cloud environment in minutes
Runtime Vulnerability Management
Vulnerability prioritization by what actually runs and is exposed
Runtime SBOM (Supply Chain)
A package inventory with runtime context: what is loaded, executed and vulnerable
API Security
API catalog, posture and a record of real attack attempts
Cloud Infrastructure Entitlement Management (CIEM)
Granted versus exercised permissions across AWS, Azure and Google Cloud
Sweet Attack (AI red team agent)
An AI red team agent that verifies attack chains on production data
Security Posture and Compliance4
Runtime CSPM
Misconfigurations detected in real time, with runtime context
Governance & Compliance
Continuous compliance checks against CIS, NIST, SOC 2, PCI DSS, HIPAA, ISO 27001 and GDPR
Data Security (DSPM and data in motion)
Where sensitive data sits, who can reach it and whether it leaves
CI/CD Security
From commit to runtime: the full image lifecycle and an owner for every vulnerability
AI Security (AI Security Platform)4
AI-SPM and AI-BOM
An inventory of AI models and components and their security posture
AI Agent Security
Discovery, tracing and permission control for AI agents, including shadow AI
AIDR (AI Detection & Response) with Agentic AI Blocking
Blocking prompt injection, unauthorized tool calls and data leakage through agents
MCP Gateway (MCP Control Plane)
Authorization at the moment an MCP operation executes, not only when a token is issued
How ICWT works with Sweet Security
ICWT deploys Sweet Security in your environment, runs managed services on the platform and uses the Sweet Attack agent to find which cloud attack paths can actually be exploited. The team works from Poland and supports customers in Poland and internationally.
Ask about Sweet Security implementation, managed services or attack path validation
Implementation
We start with a pilot in a single cluster, against success criteria agreed up front. Then we connect cloud accounts and logs, install sensors in Kubernetes and on VMs, and wire the platform into SIEM, SOAR and ticketing. We finish by tuning the baseline and the detection rules, then training your team.
Managed services
After go-live, we monitor incidents and runtime risks on the platform, triage alerts and support incident response within an agreed scope and SLA. You receive regular reports and periodic configuration reviews, and escalations to the vendor go through us.
Attack path validation
We validate attack paths with Sweet Attack, the AI red team agent built into the Sweet Security platform. We review the confirmed attack chains with your team, build a prioritized remediation plan and re-check the results after fixes.
Sweet Security expertise backed by Authorized Partner status and our position as the main partner in Poland
ICWT backs its Authorized Sweet Security Partner status with hands-on cloud deployments and managed services on the platform.
Partner status
Authorized Sweet Security Partner
Market position
Main partner in Poland
Planning a Sweet Security project?
Talk to us about licensing, implementation, managed services or attack path validation, whether you operate in Poland or internationally.