Managed detection and response

Analysts watch your endpoints, identities and cloud around the clock, and contain what they find.

Coverage

24/7, a person on it within 15 minutes

Price

Included in every plan

Most mid-size companies already own good tools: Microsoft Defender, CrowdStrike or SentinelOne on the laptops, Microsoft 365 or Google Workspace for mail. What they do not have is a person reading the alerts at 2 am. That is the job.

What the watch does

  • Reads every alert from your endpoint, identity and email tools, day and night.

  • Investigates the ones that matter with the context of your business, not a generic playbook.

  • Contains the threat: isolates a laptop, revokes a session, blocks a sender, disables an account.

  • Calls your on-call contact within 30 minutes of anything we contain.

What we agree before we start

A one page runbook for your company: which actions we may take without calling, who we call and in what order, and which systems we never touch without a person saying yes. You sign it, and we review it every quarter.

How we measure it

Time from alert to a named analyst, and time from alert to contained. Both go in the monthly report. Our target is 15 minutes to a person; the median over the last 90 days was 11.

Is it right for you?

In a 30 minute risk review we look at what you run today and tell you whether this service would change anything. If it would not, we say so.

Thirty minutes to find out who is watching your network tonight.

Bring your last insurance questionnaire or audit finding. We tell you in plain words where you are exposed after hours and what closing it would cost, then send a written quote within two business days.

Create a free website with Framer, the website builder loved by startups, designers and agencies.