Services
Everything a security programme needs, from one team.
Six disciplines that feed each other. What the testers find becomes a detection. What the SOC sees becomes an audit artefact. What the auditor needs is already collected.
01 — Detect & contain
Managed Detection & Response
An adversary who lands on a laptop at 2 a.m. does not wait for business hours, and neither does a dashboard alert that nobody reads until Monday. Our analysts work continuous shifts across endpoint, identity, cloud, email, and network telemetry, and they hold pre-authorised containment authority so the response happens before the phone call, not after it.
We tune against your environment before we ever page your staff. The measure of a good SOC is not how many alerts it forwards — it is how few times it wakes you up and how rarely it is wrong when it does.
- Full-stack telemetry. EDR/XDR, Entra ID and Okta, Microsoft 365 and Workspace, AWS/Azure/GCP, firewalls, VPN, and SaaS audit logs.
- Containment authority. Host isolation, session revocation, account disablement, and egress blocking — pre-authorised, logged, reversible.
- Human verdicts. Every escalation carries a named analyst's assessment and reasoning, not a severity score.
- Detection engineering. New rules written from our own pen-test findings and threat intelligence, deployed across the whole client base.
Coverage & commitments
- Coverage
- 24/7/365
- Critical containment
- ≤ 15 min
- Median triage
- 4m 51s
- False-positive rate
- < 2.1%
- Analyst location
- US only
- Hot retention
- up to 1 yr
Included in Signal and above. Containment SLA improves to 15 minutes on Sentinel. See pricing →
Typical first 12 months
- Month 1
Baseline & risk register
Control assessment against your obligations, ranked by business impact rather than tool output.
- Month 2–3
Roadmap & budget
A costed 24-month plan your CFO can approve, with each item tied to a risk it retires.
- Quarterly
Board reporting
Six slides your directors understand, defensible under examination.
- Ongoing
Policy & vendor work
Policy set maintained, questionnaires answered, third-party risk reviewed.
02 — Lead & report
vCISO & Security Program
Most organisations between 50 and 2,500 seats need about a third of a CISO. Hiring one costs $280,000 and takes seven months; hiring none means the security programme lives in whoever's inbox is least full. A fractional or dedicated security officer from our practice gives you the accountability without the search.
Your vCISO owns the roadmap, chairs the security committee, maintains the risk register, and shows up to the audit committee. They are a named person you meet before you sign — not a pooled resource.
- Board-ready reporting. Quarterly packs in the language directors use, with trend lines rather than raw alert counts.
- Risk register that moves. Maintained against actual findings from the SOC and the testing team.
- Policy and standards. A complete, maintained set mapped to your frameworks — not a template pack with your logo dropped in.
- Insurance and questionnaires. We complete carrier applications and customer security reviews on your behalf.
03 — Prove it breaks
Penetration Testing & Red Teaming
A vulnerability scan tells you a port is open. A penetration test tells you that the open port led to a service account, which led to the file share, which held the wire-transfer approvals. Our CREST-registered engineers test by hypothesis, by hand, and they write the report so that a non-technical executive can follow the path.
Findings feed straight into our detection engineering. If our own testers found a way in that your monitoring did not see, that is a detection gap we fix — for you and for every other client.
- Scopes we run. External perimeter, internal and assumed-breach, web and API, cloud configuration, wireless, physical, and social engineering.
- Attack narrative. The report opens with the story of the compromise, then the technical detail, then a prioritised remediation plan.
- Free retest. Every finding retested within 90 days at no charge, with an updated attestation letter.
- Attestation letter. A shareable summary for auditors, customers, and insurers that discloses no exploitable detail.
Engagement shape
- Team
- CREST-registered
- Duration
- 5–15 days
- Report in
- 10 business days
- Retest
- Free, 90 days
- Debrief
- Technical + exec
- From
- $9,500
Included annually with Sentinel, twice yearly with Sovereign. Add-on pricing →
Frameworks we operate
04 — Evidence, continuously
Compliance Operations
Compliance goes wrong when it is an annual event. Six weeks before the audit somebody starts collecting screenshots, and the evidence describes a system that only existed during evidence collection. We run compliance as an operation: controls implemented once, evidence captured automatically as the control operates, and an auditor-readable library that is always current.
We are not your auditor — that would be a conflict — but we sit beside you in the audit, answer the technical questions, and produce the artefacts on request.
- Gap assessment first. Mapped to the tooling you already own, so you buy the minimum required to close it.
- Automated collection. Access reviews, patch state, backup verification, log integrity, and training completion captured on schedule.
- One control, many frameworks. Evidence collected once satisfies overlapping requirements across every framework you carry.
- Examiner support. We have sat across from NCUA, FDIC, OCR, and state examiners. We know what they will ask for.
05 — Shrink the target
Exposure Management
Almost every organisation we onboard is running something on the internet that nobody remembers standing up — a forgotten marketing subdomain, a test VPN appliance, a file-transfer server from a project that ended in 2021. Attackers find these first because they are looking for exactly that.
We continuously discover your real external footprint, decide what is genuinely exploitable today rather than what merely scores high, and verify that remediation actually landed instead of trusting the patch report.
- Attack-surface discovery. Domains, subdomains, certificates, cloud buckets, exposed services, and shadow IT nobody declared.
- Exploitability-first triage. Prioritised by known exploitation in the wild and reachability from your perimeter, not CVSS alone.
- Credential exposure. Continuous monitoring of breach corpora and paste sites for your domains and executives.
- Verified closure. We re-test the specific finding, so "patched" means confirmed rather than reported.
What a first scan usually finds
- Between 2 and 9 internet-facing assets the organisation did not know it owned
- At least one expired or misissued TLS certificate on a live service
- Employee credentials in a public breach corpus, still valid
- An administrative interface reachable without network restriction
- A cloud storage container permitting anonymous listing
The free 30-minute exposure review covers this ground. Book one →
Retainer terms
- Engagement SLA
- ≤ 60 min
- Availability
- 24/7/365
- Paperwork
- Pre-signed
- Unused hours
- Roll to proactive
- Hotline
- (833) 761-0695
- From
- $1,450 / mo
In an active incident? Call (833) 761-0695. We take non-client emergency calls.
06 — When it happens
Incident Response & Forensics
The worst time to negotiate a contract is while your file servers are encrypting. A retainer means the master agreement, NDA, and data-handling terms are signed in advance, your environment is documented, and a named forensic lead is engaged within an hour of your call.
We handle the technical work and the surrounding machinery: preserving evidence properly, coordinating with breach counsel and your carrier, and producing the timeline that regulators and insurers will demand months later.
- Containment and eradication. Stop the spread, remove persistence, and restore in an order that does not reinfect.
- Forensic timeline. Defensible imaging and analysis establishing initial access, dwell time, and what was actually taken.
- Counsel and carrier coordination. We work under privilege where your counsel directs, and we speak the carrier's language.
- Regulatory notification support. The facts, in the form your obligation requires, within the window it requires.
Next step
See what an attacker sees — in 30 minutes, at no cost.
We run passive reconnaissance against your public perimeter, map exposed services and leaked credentials, and walk your team through the findings. No agents to install, no obligation.
- Findings report delivered in 3 business days
- No sales engineer required to read it
- Yours to keep, whether or not you hire us