Managed detection and response
Analysts watch your endpoints, identities and cloud around the clock, and contain what they find.
Coverage
24/7, a person on it within 15 minutes
Price
Included in every plan
Most mid-size companies already own good tools: Microsoft Defender, CrowdStrike or SentinelOne on the laptops, Microsoft 365 or Google Workspace for mail. What they do not have is a person reading the alerts at 2 am. That is the job.
What the watch does
Reads every alert from your endpoint, identity and email tools, day and night.
Investigates the ones that matter with the context of your business, not a generic playbook.
Contains the threat: isolates a laptop, revokes a session, blocks a sender, disables an account.
Calls your on-call contact within 30 minutes of anything we contain.
What we agree before we start
A one page runbook for your company: which actions we may take without calling, who we call and in what order, and which systems we never touch without a person saying yes. You sign it, and we review it every quarter.
How we measure it
Time from alert to a named analyst, and time from alert to contained. Both go in the monthly report. Our target is 15 minutes to a person; the median over the last 90 days was 11.
Is it right for you?
In a 30 minute risk review we look at what you run today and tell you whether this service would change anything. If it would not, we say so.
Other services in the plan
Managed SIEM and log retention
13 months of searchable logs
Incident response retainer
Response lead on the phone within 1 hour
Vulnerability management
Scanned monthly, reviewed on the call
Microsoft 365 and identity monitoring
Every sign-in and rule change, day and night
Virtual CISO and compliance
4 hours a month from one named person
Thirty minutes to find out who is watching your network tonight.
Bring your last insurance questionnaire or audit finding. We tell you in plain words where you are exposed after hours and what closing it would cost, then send a written quote within two business days.