Endpoint and email, covered properly
The overwhelming majority of small-business compromise begins on an endpoint or in a mailbox. This tier covers those two surfaces properly rather than covering everything thinly.
What you get
- 24/7 SOC monitoring — endpoint and mailbox telemetry monitored continuously by a staffed operations centre.
- Analyst triage — alerts are investigated before escalation. You are contacted for findings, not noise.
- Guided containment — confirmed detections come with specific, ordered steps for your environment.
- Mailbox threat handling — suspicious message analysis, reported-phish investigation and post-delivery clawback recommendations.
- Weekly reporting — detections, investigations, dismissals with reasoning, and coverage health.
- Monthly tuning — false positive reduction and detection adjustment as your estate changes.
Response targets
- SEV-1 Critical — 15 minutes, 24/7
- SEV-2 High — 1 hour, 24/7
- SEV-3 Medium — 4 business hours
- SEV-4 Low — 1 business day
Acknowledgement targets — the time to a human analyst opening the case and contacting you. Not resolution times.
What is not included
- Containment executed on your behalf — that is the Complete tier.
- Server, network, cloud workload and OT coverage.
- Phishing simulation and awareness training — available as a separate program.
- Remediation labour, rebuilds and restores.
Your first 30 days
- Day 0–2 — kickoff; scope, contacts and escalation path agreed in writing.
- Day 3–7 — endpoint agent and mailbox connector deployment; coverage verified.
- Day 8–14 — baseline period; we learn what normal looks like for you.
- Day 15–21 — tuning review.
- Day 22–30 — steady state; first full reporting cycle.
Billed monthly. No minimum term. Cancel any time before your next renewal date.