Cyber Services
Threat Mitigation & SOC
System, device and credential hardening, with WhiteBox network monitoring watched by our Security Operations Center around the clock.
Detected as it happens, not in an audit months later
Most breaches are not sophisticated. They are an unpatched server, a credential that was never rotated, or an endpoint nobody was watching at 2am on a Sunday. Threat mitigation closes those gaps deliberately — endpoints, servers, network, cloud environments, and identity and access controls — and then somebody watches what is left.
Our SOC runs continuously. Suspicious activity, potential compromise, malware and unauthorized access are detected, triaged and escalated as they occur, against an escalation path agreed with you in writing before anything happens.
What is included
Security Hardening & Remediation
Endpoints, servers, networks, cloud and identity controls strengthened to lift overall security posture.
WhiteBox Network Monitoring
Continuous visibility across the estate rather than sampling, with alerting tuned to your environment.
Intrusion Detection
Suspicious activity, malware and unauthorized access detected as it happens and escalated on your path.
Security Monitoring & Management
Ongoing management of controls, alerts, vulnerabilities, endpoints, infrastructure and security events.
Who this is for
- Law firms
- Corporate IT
- Small business
- Regulated industries
- Government contractors
- Healthcare
- Financial services
The question that separates a real SOC from an alert forwarder
Ask any provider one question: at 3am on a Sunday, when something is happening, who acts?
A large share of what is sold as a security operations centre is a monitoring service that sends you an email. The alert arrives, it lands in an inbox nobody is watching, and the answer to “why did nobody stop this” turns out to be that nobody was ever contracted to. The distinction is not marketing — it is the entire value of the service.
What we contract to is detection, triage and action: an analyst who investigates the alert, determines whether it is real, and where it is real takes agreed containment steps under a pre-authorised playbook — isolating an endpoint, disabling an account, blocking a destination — and then calls you. Pre-authorisation is the part that has to be agreed in advance, in writing, because at 3am there is no time to find out who can approve pulling a machine off the network.
The honest limit alongside it: no monitoring service prevents every intrusion. The measure that matters is dwell time — how long an attacker is inside before they are found and stopped. A provider who promises prevention is selling something that does not exist; one who commits to detection and response times is selling something you can hold them to.
What is actually monitored, and why identity comes first
Identity. This is where modern intrusions begin far more often than at the firewall — stolen session tokens, push-notification fatigue against multi-factor prompts, a legacy protocol that never enforced it, a service account with a password from four years ago, and a helpdesk social-engineered into a reset. Identity telemetry is the highest-value signal in most environments and the most commonly unmonitored.
Endpoints. Detection and response on servers and workstations, which is where execution, persistence and lateral movement become visible, and where containment is actually possible.
Email. Still the dominant delivery route, and the origin of the business email compromise cases that cost mid-sized organisations more than ransomware does.
Cloud and SaaS. Configuration drift, new administrative grants, anomalous data access, and the third-party application somebody authorised against the company tenant in 2022.
Network and edge. Perimeter devices, VPN concentrators and remote access — the appliances that get exploited within days of a disclosure because they cannot be patched during business hours.
Operational technology where it exists, monitored with the understanding that an OT network cannot be treated like an office one.
Detection is written against MITRE ATT&CK techniques rather than against indicator lists, because indicators expire and behaviours do not, and the programme is structured to NIST and CIS Controls so it maps to whatever framework your auditor already uses.
The clocks that start when something happens
An incident is not only a technical event. It starts legal and regulatory timers, and the organisations that handle incidents badly are usually the ones that discovered those timers afterwards.
Arizona requires notification of affected individuals following a breach of unencrypted personal information within a defined statutory window — currently 45 days — with additional obligations where the number affected is large. Other states apply their own rules to their own residents, which means a single incident can trigger many. Sector rules add more: HIPAA for health data, PCI DSS for card data, and for defense contractors, CMMC and DFARS reporting obligations. Public companies face SEC current-report obligations on material cybersecurity incidents measured in business days from the materiality determination. And your cyber insurance policy almost certainly requires notice within a short window and may require you to use their panel counsel and forensics firm — which is worth reading now rather than at hour six.
We build the notification and escalation path into the runbook before an incident, including who calls counsel and who calls the carrier. That sequencing decides how the next month goes.
Onboarding, and what the first ninety days look like
Deployment of telemetry across endpoints, identity, email and cloud. Baseline period to learn what normal looks like in your environment, because generic detections in an unfamiliar network produce noise and noise trains people to ignore alerts. Tuning against that baseline. Playbook development with your pre-authorised containment actions written down and approved. An escalation matrix with names and numbers rather than roles. Then a tabletop exercise, because the first time your leadership team makes an incident decision should not be during an incident.
Reporting runs monthly on what was detected, what was actioned and what changed, with an annual review of the detections themselves. A detection library nobody has revisited in a year is decaying whether or not the dashboard is green.
Where it connects
Monitoring is one control among several and works best where it is not the only one. Penetration testing tells you what an attacker could actually do and generates the detections worth writing. Security awareness training addresses the delivery route most intrusions still use. Ransomware readiness and recovery covers the scenario with the worst downside. Digital forensics answers what actually happened when an incident becomes a legal matter. And where an incident turns out to be a person rather than a payload, cyber investigations takes it.
How it is priced
Monitoring is quoted monthly, driven by the number of endpoints and identities, the telemetry sources in scope, data retention, and whether coverage is business hours or 24/7. Onboarding is quoted once. Incident response beyond contracted containment is quoted hourly or under a retainer — and a retainer is worth having, because the worst time to negotiate a rate is while an attacker has your domain.
Included: telemetry deployment, tuning, detection engineering, 24/7 triage where contracted, pre-authorised containment, escalation and monthly reporting. Quoted separately: full incident response and forensics, penetration testing, remediation engineering and compliance evidence packages.
Frequently asked questions
Do you just send alerts, or do you act?
We act, within pre-authorised playbooks agreed with you in writing — isolating an endpoint, disabling an account, blocking a destination — and then we call you. Ask every provider this. A great many will only send the email.
Will this stop us being breached?
No, and be careful of anyone who says otherwise. What good monitoring does is compress dwell time from months to minutes, which is the difference between an incident and a catastrophe. Judge providers on detection and response commitments, not on prevention claims.
We already have antivirus and a firewall. Is that not enough?
Those are controls, not detection. Most modern intrusions use valid credentials and legitimate tools, which means nothing is flagged as malicious — the attacker looks like an employee. Detecting that requires behavioural monitoring across identity and endpoint, and someone watching it.
How quickly do you respond?
Triage and response targets are contracted rather than aspirational, and they vary by severity. What we will not do is quote a number that assumes an analyst is already looking at your environment when they are not — ask any provider how many customers one analyst covers at 3am.
What happens the moment something serious is confirmed?
Containment under the agreed playbook, then a call to your named contacts, then the notification path — counsel, insurer, and any regulatory clock that has started. That sequence is written before an incident because it is impossible to work out during one.
Can you help us meet CMMC, HIPAA or PCI requirements?
The monitoring, logging, retention and reporting are built to produce the evidence those frameworks ask for. We will be clear about which requirements the service satisfies and which sit with you — a provider who implies their service makes you compliant is overstating what any service can do.
In detail
It’s far easier to prevent problems than to deal with the aftermath once they’ve occurred. We specialize in cybersecurity by proactively mitigating digital threats through comprehensive system assessments. This includes evaluating your devices, software, website, passwords, and by implementing two-factor authentication (2FA). Additionally, our WhiteBox service functions as a digital security system and honeypot for your entire network, providing protection for any device connected to your Wi-Fi network. Our Security Operations Center (SOC) monitors WhiteBoxes around the clock, every day of the year. This service is available on a monthly subscription basis.
Scope your requirement
We will want to know what is currently outsourced and to whom, the tools already in the environment, your compliance obligations, and the number of users, endpoints, servers and cloud tenants. From that we build the technical solution and staffing model — rather than quoting a package and hoping it fits.