Four specialist capabilities under one accountable team — from 24/7 threat monitoring with a 15-minute critical-alert SLA, to recovering data others consider permanently lost. Here's exactly how each one works, what's included, and what you receive.
A fully managed Security Operations Center: certified analysts monitor, hunt and respond around the clock so you get enterprise-grade defense without building — or staffing — your own SOC.
We map your assets, log sources and crown-jewel systems, then agree alert priorities and escalation paths.
Sensors and log forwarding are connected to our SIEM/XDR; detections are tuned to your environment to cut false positives.
Analysts watch 24/7, triage every alert and proactively hunt for threats that automated tooling misses.
On a confirmed threat we contain and guide remediation, then deliver a written incident report and a monthly review.
Draft tiers — confirm or adjust the specifics with us; nothing here is locked.
| Capability | EssentialSmall teams | AdvancedGrowing orgs | EnterpriseMission-critical |
|---|---|---|---|
| 24/7 monitoring & central logging (SIEM) | ✓ | ✓ | ✓ |
| Endpoint detection | EDR | EDR + XDR | XDR + NDR |
| Critical-alert response SLA | 1 hour | 30 min | 15 min |
| Proactive threat hunting | — | Monthly | Continuous |
| Incident response team | Business hours | 24/7 | 24/7 + dedicated lead |
| Vulnerability assessments | Quarterly | Monthly | Continuous |
| Penetration testing | — | Annual | Quarterly |
| Dark-web & credential monitoring | — | ✓ | ✓ |
| Compliance reporting (PCI / GDPR / ISO) | Basic | Standard | Full + audit support |
| Service review cadence | Monthly report | Monthly call | Weekly + named contact |
Active incident? Our emergency line triggers a 15-minute response. We contain the blast radius first, then recover — using decryption and rebuild tooling we develop in-house.
Report an incident →Where most providers stop and advise you to pay, we start. Four stages, one accountable team, no ransom.
Contain affected systems to stop lateral spread and preserve forensic evidence — within the first response window.
Identify the strain, entry point and scope through malware forensics and behaviour analysis.
Apply proprietary decryption and recovery tooling — no ransom paid, no attacker contact required.
Rebuild and validate clean systems, restore critical data, and harden against re-entry.
Two complementary services: recover what's already lost, and make sure the next incident can't take it from you.
Physical & logical recovery across every medium, in an ISO-standard cleanroom — confidentiality guaranteed under NDA.
An insurance-style backup subscription with ransomware-proof, air-gapped architecture — pay monthly, recover anytime at no extra cost.
Every managed engagement carries a contractual SLA. These are the response targets — the window from alert or call to a human taking action.
No. Our SOC integrates with the stack you already run wherever possible — we connect to your existing log sources, endpoints and firewalls, and only recommend additions where there's a genuine gap. The goal is coverage, not a rip-and-replace.
A certified analyst triages it within your SLA window (15 minutes for Enterprise). If it's a confirmed threat, we move to containment immediately, notify your named contacts, and guide remediation — then deliver a written incident report with root cause once it's resolved.
In the large majority of cases, yes — we recover roughly 95% of ransomware incidents using decryption and rebuild tooling we develop in-house, combined with clean backups where they exist. We never contact the attacker or pay on your behalf. Where data is genuinely unrecoverable, we tell you straight.
A standard SOC onboarding runs in phases — assess, deploy, tune, go-live — and most environments are under active monitoring within a couple of weeks. For an active incident, response starts the moment you call; onboarding paperwork follows.
Managed services are a fixed monthly subscription based on the tier and scope (assets, log volume, locations). Data recovery is quoted per case after a free diagnostic — no recovery, no fee. We'll give you a clear proposal after a short discovery call.
Yes. Every engagement is covered by an NDA, all operations follow strict data-privacy controls, and recovered media is handed over encrypted and then securely wiped. Confidentiality is contractual, not just a promise.
Book a free discovery call and we'll assess your current posture and recommend the right protection — no obligation.
Book a discovery call →