Enterprise Services

Managed Security

Detection monitoring with rules tested quarterly, measured remediation times, third-party access kept current, and a monthly evidence pack an auditor can read.

Managed Security
How it is boughtMonthly recurring
Duration12-month term, 30 days notice after month 3
Written forOrganisations that need continuous security operations without building a SOC

A control set is a snapshot. Attack paths change weekly, third-party exposure changes without warning, and a detection rule nobody tests is an assumption.

What you receive

Named artifacts, not activities. If one of these is not delivered, the engagement is not complete.

  • Detection monitoring with tuned rules, and a quarterly test that each rule still fires
  • Vulnerability management with a measured, reported time from publication to remediation
  • Third-party access review, so the inventory stays current rather than ageing
  • Incident response to the published SLA, with a written post-incident review
  • A monthly evidence pack: what operated, what fired, what was remediated, ready for an auditor

How it runs

  • Month 1 is onboarding: asset and identity inventory, log sources, detection baseline.
  • Quarterly: detection testing and a control evidence review rather than a status update.

What this deliberately does not include

Published with the same prominence as the deliverables. A scope with no stated exclusions is a scope that will be argued about later, and the argument always happens at the worst possible moment.

  • Penetration testing and red teaming, which are separate engagements.
  • Physical security and personnel vetting.
  • Acting as your legal or regulatory reporting authority during an incident, though we support it.

How you know it is finished

You can answer an audit from the monthly evidence packs rather than from a scramble.

What you need ready

Log source access, an asset inventory, and agreement on who can authorise containment at 3am.

Start this engagement

Every engagement starts with a written scope confirmation before any invoice is raised. Nothing here is a click-to-buy: we confirm what you need, agree the scope in writing, then invoice. If the scoping conversation shows that a smaller engagement, or none at all, is the right answer, we say so before anything is signed.

Request this engagement Check your evidence position in the Cyber Lab

Browse enterprise services