Security
Managed security operations, SOC and 24/7 monitoring, identity and zero-trust, and compliance programs — a senior-only security team that defends your business every day, not just at audit time.
01 — Approach
How we engage.
- Managed detection & response (MDR) — 24/7 monitoring, triage, and active response across your endpoints, cloud, identity, and network, run by senior analysts — not a tier-one queue offshore.
- Security operations centre (SOC-as-a-service) — a fully-managed SOC without the headcount: SIEM tuning, detection engineering, threat hunting, and incident response on a retainer.
- SIEM & detection engineering — Microsoft Sentinel, Elastic Security, Wazuh, or Splunk — deployed, tuned to your environment, and continuously improved so the alerts that fire are the ones that matter.
- Identity & access management — Okta, Entra ID, and JumpCloud done properly: SSO, MFA, conditional access, least-privilege, joiner-mover-leaver automation, and privileged access management.
- Zero-trust architecture — replacing implicit-trust networks with identity-aware access, micro-segmentation, and device posture checks on Cloudflare Zero Trust, Zscaler, or Tailscale.
- Endpoint & cloud security — EDR/XDR rollout (CrowdStrike, SentinelOne, Defender), cloud security posture management (CSPM), and hardening across AWS, GCP, and Azure.
- Compliance & GRC programmes — SOC 2, ISO 27001, HIPAA, PCI-DSS, and GDPR — built as a continuous programme with Vanta, Drata, or Secureframe, not a last-minute scramble.
- Virtual CISO (vCISO) — senior security leadership on a fraction of a full-time hire: strategy, board reporting, risk management, vendor reviews, and a roadmap your investors and enterprise customers will respect.
- Incident response & recovery — retained IR with pre-negotiated SLAs, plus forensics, containment, and the morning-after rebuild when something gets through.
- Senior-only delivery. Real security engineers run your programme — not a tier-one alert queue forwarding noise. The person tuning your detections has also written the exploits they detect.
- Defence informed by offence. Our team tests offensively in our audits practice, so the controls we build are the ones attackers actually hit — not a generic best-practice checklist.
- Signal, not noise. We tune your SIEM and EDR so alerts mean something. A managed security service that pages you constantly is one you will learn to ignore — and that is how breaches happen.
- Compliance as a by-product, not the goal. Build real security and the SOC 2 or ISO 27001 certificate falls out of it. We never confuse passing an audit with being secure.
- Identity-first. Most modern breaches are identity breaches. We start with IAM and zero-trust because that is where the leverage is.
- Documented & transparent. You get dashboards you can actually read, monthly reporting your board will understand, and a runbook for every response action we take on your behalf.
- Built to scale with you. Whether you are securing your first ten employees or your first enterprise contract, the programme grows with the business — no rip-and-replace at every stage.
- SIEM & detection: Microsoft Sentinel, Elastic Security, Wazuh, Splunk, Panther; Sigma-based detection-as-code.
- Endpoint & XDR: CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint.
- Identity & access: Okta, Entra ID, JumpCloud, CyberArk and HashiCorp Vault for privileged access and secrets.
- Zero-trust & network: Cloudflare Zero Trust, Zscaler, Tailscale, Twingate.
- Cloud security: Wiz, Prowler, AWS GuardDuty / Security Hub, GCP Security Command Center, Microsoft Defender for Cloud.
- Vulnerability management: Tenable, Qualys, Snyk, Trivy, integrated into a managed remediation workflow.
- GRC & compliance: Vanta, Drata, Secureframe for continuous SOC 2 / ISO 27001 evidence.
- Security assessment & roadmap — $15k–$50k, two to four weeks. Risk baseline, gap analysis, tooling recommendations, and a prioritised roadmap.
- Managed detection & response (MDR) — monthly retainer, from $8k. 24/7 monitoring, triage, active response, and detection engineering, priced by environment size.
- Compliance programme — $30k–$120k plus retainer. SOC 2 or ISO 27001 readiness and continuous evidence, built to pass and stay passed.
- Virtual CISO (vCISO) — monthly retainer, from $6k. Fractional senior security leadership, board reporting, and programme ownership.
- Incident response retainer — annual, from $25k base. Pre-negotiated rates, named on-call responders, and SLA-backed coverage.
02 — What's included
Every engagement ships with.
Senior lead
A 10+-year practitioner who stays on the work, end-to-end.
Design system
A scalable foundation, not screen-by-screen one-offs.
Production deploys
Fortnightly increments to a staging URL.
Documentation
Runbooks, ADRs, and onboarding materials.
03 — Process
Four phases. Always.
Discovery
1–2 weeks. Audit, listen, scope.
Design
2–4 weeks. Prototypes you can click.
Build
6–16 weeks. Two-week cadences.
Stewardship
Ongoing. Continuity beats handoff.
04 — Common questions
Frequently Asked Questions
How much do managed security services cost?
A security assessment and roadmap starts at $15,000. Ongoing managed detection and response (MDR) starts at $8,000 per month and scales with the size of your environment. Compliance programmes (SOC 2 or ISO 27001) run $30,000–$120,000 plus a retainer, and a virtual CISO engagement starts at $6,000 per month. We price by what you actually need to protect, not by a one-size tier.
What is the difference between Security and your Cybersecurity & Audits service?
Our Cybersecurity & Audits practice is offensive and point-in-time: penetration testing, threat modelling, and security audits that find vulnerabilities. This Security practice is defensive and ongoing: managed detection and response, SOC operations, identity, zero-trust, and compliance programmes that protect you every day. Most clients use both — we test offensively, then defend what we found. They share a team, so nothing falls between the two.
Should we build an in-house SOC, use an MSSP, or run MDR?
We are agnostic and will tell you honestly. An in-house SOC makes sense once you can staff 24/7 coverage (realistically 8+ analysts) and security is core to your product. Traditional MSSPs are often alert factories that forward noise and own no outcome. MDR — senior-run detection and active response — is what we recommend for almost everyone in between: real coverage without the hiring burden, and someone who owns containing the threat, not just flagging it.
Can you help us get and stay SOC 2 or ISO 27001 compliant?
Yes — compliance is a core practice. We build the programme on Vanta, Drata, or Secureframe, implement the technical controls (logging, access review, vulnerability management, change control), collect evidence continuously, and prepare you for the audit. We do not certify — that is the auditor — but we get teams to a short findings list, and we keep the programme passing year after year rather than scrambling each renewal.
Do you provide 24/7 security monitoring?
Yes. Our managed detection and response service provides round-the-clock monitoring, triage, and active response across endpoints, cloud, identity, and network. Senior analysts run it — not a tier-one offshore queue — and we measure ourselves on mean-time-to-detect and mean-time-to-respond, with monthly reporting your board can actually read.
What is a virtual CISO and do we need one?
A virtual CISO (vCISO) is fractional senior security leadership — strategy, risk management, board and investor reporting, vendor security reviews, and programme ownership — for a fraction of the cost of a full-time CISO hire. You likely need one if you are facing enterprise security reviews, raising a round where security diligence matters, or scaling past the point where security is somebody's side responsibility.
How quickly can you respond if we are breached?
With an incident response retainer in place, response is SLA-backed with named on-call responders and pre-negotiated rates — so you are not doing procurement during an active incident. We handle containment, forensics, and the recovery rebuild. Without a retainer we respond on a best-effort basis, but a retained relationship gets you faster, cheaper, and calmer coverage when it matters most.
We are a small team — is managed security overkill for us?
No — the programme scales down as well as up. For a ten-person company we start with identity, MFA, endpoint protection, and the handful of controls that stop the most common attacks, then grow coverage as you do. Most breaches at small companies come from basic gaps (identity, phishing, unpatched systems), and those are exactly what an early managed-security programme closes first.
05 — Selected work
Related projects.
— From the journal