24/7/365 SOC — average triage time 4m 51s

SOC staffed 24/7/365 Delaware corporation Operating since 2011 — 15 years

Security operations that produce proof, not promises.

National Cyber Protection Services runs detection, response, testing, and compliance evidence as one service — so your auditors, your insurer, and your board all get the same answer.

15-minute containment SLA No long-term lock-in Fixed per-endpoint pricing

Representative detections and automated responses. How the SOC works →

Programs we build, run, and evidence

SOC 2 Type II HIPAA Security Rule PCI DSS 4.0 CMMC Level 2 ISO/IEC 27001 GLBA Safeguards NIST CSF 2.0
15yrs

Continuous operation since 2011, under the same leadership team.

4.85min

Median time from alert to analyst triage across all monitored tenants.

312+

Organizations under contract for detection, testing, or compliance work.

99.98%

Monitoring-platform uptime measured over the last 24 months.

What we do

Six disciplines, one accountable team.

Most mid-market security stacks are four vendors that each blame the other three. We put detection, testing, remediation, and evidence under one contract with one escalation path — and we publish the SLA we are held to.

Managed Detection & Response

A staffed SOC watching endpoints, identity, cloud, and network telemetry — with the authority to contain a host without waiting for a ticket.

  • EDR/XDR deployment and tuning included
  • 15-minute containment SLA on critical detections
  • Every alert closed with a written analyst verdict

vCISO & Security Program

A named security leader who owns your roadmap, risk register, policy set, and the slide your board actually reads each quarter.

  • Quarterly board and audit-committee reporting
  • Risk register maintained against real findings
  • Vendor and cyber-insurance questionnaire support

Penetration Testing

Manual, hypothesis-driven testing by CREST-registered engineers — external, internal, web, API, cloud, wireless, and social engineering.

  • Attack narrative, not a scanner export
  • Free retest of every finding within 90 days
  • Auditor-ready letter of attestation

Compliance Operations

Control implementation and continuous evidence collection for SOC 2, HIPAA, PCI DSS, CMMC, ISO 27001, and GLBA — run as an operation, not a scramble.

  • Evidence gathered continuously, not at audit time
  • Gap assessment mapped to your existing tooling
  • We sit in the audit with you

Exposure Management

Continuous discovery of what you actually have on the internet, which of it is exploitable today, and whether the patch really landed.

  • External attack-surface and shadow-IT discovery
  • Vulnerability prioritisation by exploitability, not CVSS alone
  • Patch orchestration with verified closure

Incident Response

Retainer-backed digital forensics and incident response with a 60-minute engagement SLA — including the counsel, insurer, and regulator paperwork.

  • Forensic imaging and root-cause timeline
  • Breach-counsel and carrier coordination
  • Retainer hours roll into proactive work if unused

How onboarding runs

Monitored in ten business days.

No six-month implementation project. We have run this sequence more than three hundred times.

Exposure review

Thirty minutes, no agents. We show you the external footprint, exposed services, and leaked credentials an attacker can already see.

Scope & baseline

We count endpoints, identities, and cloud tenants, agree the SLA, and map your obligations to a control set. Fixed price, signed in days.

Deploy & tune

Sensors roll out in rings. We tune out the noise against your real environment before we ever page your staff.

Run & prove

24/7 monitoring, monthly metrics, quarterly reviews, annual testing — and an evidence library your auditor can read without translation.

Why teams switch to us

The difference is who is accountable at 3 a.m.

Plenty of providers will sell you a dashboard and call it managed security. When something actually burns, the dashboard does not pick up the phone. Our analysts contain the host, call your named contact, and write the timeline — before the shift ends.

  • One invoice, one throat to choke. Detection, testing, and compliance evidence come from the same team, so nothing falls between vendors.
  • Contractual SLAs, published. 15-minute containment on criticals, 60-minute IR engagement, 99.9% platform availability — with service credits attached.
  • Analysts, not a ticket queue. Every escalation carries a named analyst's verdict and the reasoning behind it.
  • Your data stays yours. Full log export on demand, and on exit we hand over configuration, detection rules, and history.
  • No multi-year lock-in. Annual terms with a 60-day out. We keep clients by being worth keeping.

How we got here — 15 years of it

Service level commitments

Critical containment
≤ 15 min
IR engagement
≤ 60 min
Analyst triage (median)
4m 51s
Platform availability
99.9%
Pen-test retest
Free, 90 days
Support coverage
24/7/365

Measured monthly and published in your service review. Missed targets earn service credits under the master services agreement.

Customer reviews

What it is like to be a client.

4.9 / 5 average across 87 verified client reviews · 96% renewal rate

Read all 15 years of customer outcomes

  1. 2011

    Incorporated in Delaware

    Founded by three incident responders who kept meeting the same mid-market victims — organisations with real obligations and no security staff.

  2. 2016

    24/7 SOC goes live

    Round-the-clock staffing replaced the on-call rotation. Containment authority was written into the standard contract that year.

  3. 2020

    Offensive practice formed

    CREST-registered testers joined in-house, so findings feed detection engineering instead of a PDF nobody re-reads.

  4. 2026

    15 years, 312 organisations

    Still privately held, still Delaware-incorporated, still measured on the same published SLAs.

Years of activity

15 years is the shortest version of our reference check.

Security vendors appear and disappear on a three-year cycle. We have renewed the same clients through four framework rewrites, a pandemic, and the ransomware era — and we can put you on the phone with people who have been with us for a decade.

Every claim on this site is backed by something we will show you: the SLA report, the audit letter, the retest, or the client who will take your call.

Our full history and leadership

Questions we get first

Straight answers.

Alongside, in the overwhelming majority of cases. Your IT team knows the business; we bring the 24/7 eyes, the offensive perspective, and the evidence discipline. We define the RACI in week one so nobody is waiting on anybody. For organisations with no internal IT at all, we can bring a managed-IT partner into the engagement or work with the one you already use.

For any detection our analysts classify as critical, we take a containment action — isolating the host, revoking the session, disabling the account, or blocking the egress — within 15 minutes of the detection firing, without waiting for your approval. You pre-authorise the action classes during onboarding, and every action is logged and reversible. The commitment is contractual and carries service credits.

Per protected endpoint per month, with identities and cloud workloads included at published ratios. No per-gigabyte log-ingestion charges and no per-incident fees — a bad month costs you the same as a quiet one. Penetration testing and incident-response retainers are priced separately and shown on the pricing page.

We are deliberately tool-agnostic. If you already own a supported EDR, identity provider, or SIEM, we will operate it — that is usually cheaper for you and faster to deploy. If you do not, our licensing is included in the per-endpoint price. What we never do is make you buy a platform you cannot take with you when you leave.

All monitoring and response is delivered from US-based facilities by US-person employees — never offshored or subcontracted. That is a hard requirement for our CJIS, CMMC, and financial-services clients, so it is the standard for everybody.

The exposure review happens within a few business days of your first call. Once a scope is signed, typical time to full monitoring is ten business days for organisations under 500 endpoints. If you are in an active incident, call the hotline at (833) 761-0695 — we onboard emergencies the same day.

Next step

See what an attacker sees — in 30 minutes, at no cost.

We run passive reconnaissance against your public perimeter, map exposed services and leaked credentials, and walk your team through the findings. No agents to install, no obligation.

  • Findings report delivered in 3 business days
  • No sales engineer required to read it
  • Yours to keep, whether or not you hire us