Security monitoring and response for the 128 hours a week your IT team is off.
Thornbury is a 24/7 security operations team in Columbus, Ohio, for companies of 200 to 2,000 people. We watch the tools you already own, and a named analyst answers every alert.
Three watches a day in Columbus, a named analyst on every one.
CREST accredited SOC
Assessed in 2025 against CREST’s standard for security operations centres.
SOC 2 Type II
Audited every year by an independent CPA firm. The report is shared under NDA.
ISO/IEC 27001:2022
Certified security management, last surveillance audit in May 2026.
One room in Columbus
Every analyst is a Thornbury employee. No offshore overflow, no subcontracted nights.
Six services, one team, one monthly bill.
Pick a plan, not a shopping list. Every service is run by the same people who watch your network at night.
Managed detection and response
Analysts watch your endpoints, identities and cloud around the clock, and contain what they find.
24/7, a person on it within 15 minutes
Included in every plan
Managed SIEM and log retention
Firewall, VPN, identity and server logs in one place, kept for 13 months and searched every week.
13 months of searchable logs
From $14 per employee a month
Incident response retainer
When something gets past the watch, our response lead takes over within the hour, with hours already paid for.
Response lead on the phone within 1 hour
40 hours a year in the top plan, or $325 an hour
Vulnerability management
Monthly scans of everything you own, turned into a short list of fixes in the order that matters.
Scanned monthly, reviewed on the call
Included from Watch and Hunt
Microsoft 365 and identity monitoring
Account takeover and new inbox rules caught in minutes, which is where most business email fraud starts.
Every sign-in and rule change, day and night
Included in every plan
Virtual CISO and compliance
Four hours a month of a senior security lead for policies, audits, board updates and insurer questionnaires.
4 hours a month from one named person
Included in Watch, Hunt and Respond
Who answers at 3 am? The night watch, in the same room as the day watch.
Three watches a day in one operations room in Columbus. Each has a named lead, a handover briefing at 07:00, 15:00 and 23:00, and the authority to act on your runbook without waking you.

The operations room in Franklinton on a Tuesday evening. Handovers happen at the long table at 07:00, 15:00 and 23:00.
Sunday, 02:14. A finance mailbox starts forwarding invoices.
A 600 person parts maker near Dayton. The accounts payable clerk approved an MFA push in her sleep, and forty seconds later a new inbox rule began forwarding anything with invoice in it to an outside address.
Priya Raman had the case three minutes after the first alert. By 02:31 the sessions were revoked, the rule was gone and seventeen outbound messages were held. The IT lead read the written summary with his first coffee.
Alert to a person
3 minutes
Alert to contained
17 minutes
Messages stopped
17 of 17
Written summary sent
07:30
Anonymised and shared with the client’s permission. Names and places changed.

From the first call to a covered night in four weeks.
Most companies are fully watched 21 to 28 days after they sign. Here is what happens in between, and what we need from you.
Day 1
A 30 minute risk review
We ask what you run, who is on call and what your insurer wants. You leave with your three biggest after-hours gaps, whether you hire us or not.
Week 1
Scoping and a written quote
A fixed monthly price per employee and a one page runbook: what we may do without calling, who we call, and what we never touch.
Weeks 2 to 3
Connect and tune
Read-only connections to your endpoint, identity, email and firewall logs. We tune out the noise with your IT lead for ten working days.
Week 4 onward
The watch goes live
Three watches a day, a monthly report on the first Monday and a 45 minute review call with your account lead.

The report on your desk every first Monday.
Every alert we triaged and what happened to it, the incidents minute by minute, the hours covered and three fixes in order. It is also the evidence your insurer and auditor ask for.
Alerts triaged, and how many a person looked at
Incidents contained, with timelines
Hours watched, sources reporting, pages missed
Three fixes for next month, in order
What it costs, in writing.
Per employee, per month, in US dollars. The price does not move with log volume, device count or how busy the month was.
Annual agreements bill monthly. If we miss the 15 minute response target two months in a row, you can leave on 30 days notice with no fee.
The people on your account.
Twenty eight people work in the Columbus operations room. These six lead the watches and the accounts, and you will know their names by the second month.
Tom Brennan
Founder and incident response lead
Response
GCFA, CISSP
19 years
Spent twelve years answering breach calls for insurers’ response panels, then started Thornbury in 2014 so mid-size companies could have the same people on their side before the call.
Keisha Morrow
Head of client security
Accounts
CISM, CISSP
14 years
Runs the account leads. Every client has one named person who writes the monthly report and answers the phone.
Dana Okafor
Day watch lead
07:00 to 15:00
GCIH
11 years
Came from a regional bank’s security team. Leads seven analysts and the handover briefings at 07:00 and 15:00.
Luis Ferreira
Evening watch lead
15:00 to 23:00
GCFA
9 years
Former Army cyber operations. Covers the hours when most phishing lands and most IT teams have gone home.
Priya Raman
Night watch lead
23:00 to 07:00
GCIA
8 years
Has led the night watch since 2021 and wrote most of our Microsoft 365 detections after a year of 3 am inbox rules.
Sam Whitaker
Detection engineering lead
Engineering
GCDA
7 years
Tunes the rules so the watch sees fewer and better alerts, and owns the noise number in every monthly report.
Before you sign anything.
The questions every IT director asks on the first call, answered the way we answer them.
Thirty minutes to find out who is watching your network tonight.
Bring your last insurance questionnaire or audit finding. We tell you in plain words where you are exposed after hours and what closing it would cost, then send a written quote within two business days.