Security monitoring and response for the 128 hours a week your IT team is off.

Thornbury is a 24/7 security operations team in Columbus, Ohio, for companies of 200 to 2,000 people. We watch the tools you already own, and a named analyst answers every alert.

Your team works 40 hours a week. We cover the other 128.

Your team works 40 hours a week. We cover the other 128.

Three watches a day in Columbus, a named analyst on every one.

CREST accredited SOC

Assessed in 2025 against CREST’s standard for security operations centres.

SOC 2 Type II

Audited every year by an independent CPA firm. The report is shared under NDA.

ISO/IEC 27001:2022

Certified security management, last surveillance audit in May 2026.

One room in Columbus

Every analyst is a Thornbury employee. No offshore overflow, no subcontracted nights.

Who answers at 3 am? The night watch, in the same room as the day watch.

Three watches a day in one operations room in Columbus. Each has a named lead, a handover briefing at 07:00, 15:00 and 23:00, and the authority to act on your runbook without waking you.

The Thornbury operations room in Columbus after hours, desks with dual monitors and a wall of screens

The operations room in Franklinton on a Tuesday evening. Handovers happen at the long table at 07:00, 15:00 and 23:00.

07:00 to 15:00
Day watch
Led by Dana Okafor, GCIH
7 analysts on weekdays, 4 on weekends
15:00 to 23:00
Evening watch
Led by Luis Ferreira, GCFA
5 analysts on weekdays, 4 on weekends
23:00 to 07:00
Night watch
Led by Priya Raman, GCIA
4 analysts on weekdays, 3 on weekends

Sunday, 02:14. A finance mailbox starts forwarding invoices.

A 600 person parts maker near Dayton. The accounts payable clerk approved an MFA push in her sleep, and forty seconds later a new inbox rule began forwarding anything with invoice in it to an outside address.

Priya Raman had the case three minutes after the first alert. By 02:31 the sessions were revoked, the rule was gone and seventeen outbound messages were held. The IT lead read the written summary with his first coffee.

Alert to a person

3 minutes

Alert to contained

17 minutes

Messages stopped

17 of 17

Written summary sent

07:30

Anonymised and shared with the client’s permission. Names and places changed.

Thornbury incident timeline for a contained business email compromise, minute by minute

From the first call to a covered night in four weeks.

Most companies are fully watched 21 to 28 days after they sign. Here is what happens in between, and what we need from you.

Day 1

A 30 minute risk review

We ask what you run, who is on call and what your insurer wants. You leave with your three biggest after-hours gaps, whether you hire us or not.

Week 1

Scoping and a written quote

A fixed monthly price per employee and a one page runbook: what we may do without calling, who we call, and what we never touch.

Weeks 2 to 3

Connect and tune

Read-only connections to your endpoint, identity, email and firewall logs. We tune out the noise with your IT lead for ten working days.

Week 4 onward

The watch goes live

Three watches a day, a monthly report on the first Monday and a 45 minute review call with your account lead.

Thornbury monthly security report with alerts, incidents, coverage and recommendations

The report on your desk every first Monday.

Every alert we triaged and what happened to it, the incidents minute by minute, the hours covered and three fixes in order. It is also the evidence your insurer and auditor ask for.

Alerts triaged, and how many a person looked at

Incidents contained, with timelines

Hours watched, sources reporting, pages missed

Three fixes for next month, in order

What it costs, in writing.

Per employee, per month, in US dollars. The price does not move with log volume, device count or how busy the month was.

USD, per employee, per month. 150 employee minimum. No onboarding fee.
Every plan includes the watch, the monthly report and a 30 day onboarding.
Watch24/7 monitoring and response on the tools you own.$9per employee a month
Most clients start hereWatch and HuntAdds a managed SIEM, log retention and monthly hunts.$14per employee a month
Watch, Hunt and RespondAdds incident response hours and a part-time vCISO.$19per employee a month
24/7 monitoring and response
Included
Included
Included
Microsoft 365 and identity monitoring
Included
Included
Included
Managed SIEM, 13 months of logs
Not included
Included
Included
Threat hunting
Not included
Monthly
Weekly
Incident response hours
$325 an hour
10 a year
40 a year
Monthly report and review call
Included
Included
Included
Named account lead
Shared
Named
Named
vCISO time for policies and audits
Not included
Not included
4 hours a month
Watch
24/7 monitoring and response on the tools you own.
$9
per employee a month
24/7 monitoring and responseIncluded
Microsoft 365 and identity monitoringIncluded
Managed SIEM, 13 months of logsNot included
Threat huntingNot included
Incident response hours$325 an hour
Monthly report and review callIncluded
Named account leadShared
vCISO time for policies and auditsNot included
Most clients start here
Watch and Hunt
Adds a managed SIEM, log retention and monthly hunts.
$14
per employee a month
24/7 monitoring and responseIncluded
Microsoft 365 and identity monitoringIncluded
Managed SIEM, 13 months of logsIncluded
Threat huntingMonthly
Incident response hours10 a year
Monthly report and review callIncluded
Named account leadNamed
vCISO time for policies and auditsNot included
Watch, Hunt and Respond
Adds incident response hours and a part-time vCISO.
$19
per employee a month
24/7 monitoring and responseIncluded
Microsoft 365 and identity monitoringIncluded
Managed SIEM, 13 months of logsIncluded
Threat huntingWeekly
Incident response hours40 a year
Monthly report and review callIncluded
Named account leadNamed
vCISO time for policies and audits4 hours a month

Annual agreements bill monthly. If we miss the 15 minute response target two months in a row, you can leave on 30 days notice with no fee.

The people on your account.

Twenty eight people work in the Columbus operations room. These six lead the watches and the accounts, and you will know their names by the second month.

Tom Brennan

Founder and incident response lead

Response

GCFA, CISSP

19 years

Spent twelve years answering breach calls for insurers’ response panels, then started Thornbury in 2014 so mid-size companies could have the same people on their side before the call.

Keisha Morrow

Head of client security

Accounts

CISM, CISSP

14 years

Runs the account leads. Every client has one named person who writes the monthly report and answers the phone.

Dana Okafor

Day watch lead

07:00 to 15:00

GCIH

11 years

Came from a regional bank’s security team. Leads seven analysts and the handover briefings at 07:00 and 15:00.

Luis Ferreira

Evening watch lead

15:00 to 23:00

GCFA

9 years

Former Army cyber operations. Covers the hours when most phishing lands and most IT teams have gone home.

Priya Raman

Night watch lead

23:00 to 07:00

GCIA

8 years

Has led the night watch since 2021 and wrote most of our Microsoft 365 detections after a year of 3 am inbox rules.

Sam Whitaker

Detection engineering lead

Engineering

GCDA

7 years

Tunes the rules so the watch sees fewer and better alerts, and owns the noise number in every monthly report.

Before you sign anything.

The questions every IT director asks on the first call, answered the way we answer them.

Watch starts at $9 per employee a month on an annual agreement, with a 150 employee minimum. A 600 person company on Watch and Hunt pays $8,400 a month. The price does not change with log volume or device count, and there is no onboarding fee.

Twelve months, billed monthly. If we miss our response target two months in a row, you can leave on 30 days notice with no fee. Month to month is available at a higher rate. Your logs, rules and reports are yours and export on request.

Our target is 15 minutes from alert to a named analyst, day or night. The median over the last 90 days was 11 minutes. High severity alerts page the watch lead directly, and we call your on-call contact within 30 minutes of anything we contain.

Most carriers now ask for 24/7 monitoring with a human response, MFA evidence and tested backups. The monthly report covers the first, and we fill in the insurer's questionnaire with you before renewal. We cannot promise a premium.

No. We work with Microsoft Defender, CrowdStrike, SentinelOne, Microsoft 365, Google Workspace, Okta and the major firewalls. If you have no endpoint tool yet, we license one at cost.

Thornbury employees in one room in Columbus, Ohio. We do not use offshore overflow or subcontract the night watch. Every analyst passes a background check and holds at least one GIAC certification.

The watch contains what it can in the first hour, then our incident response lead takes over. Watch, Hunt and Respond includes 40 hours of incident response a year; on other plans it is $325 an hour. We work alongside your insurer's breach panel if they appoint one.

Thirty minutes to find out who is watching your network tonight.

Bring your last insurance questionnaire or audit finding. We tell you in plain words where you are exposed after hours and what closing it would cost, then send a written quote within two business days.

Create a free website with Framer, the website builder loved by startups, designers and agencies.