A control is only as good as whoever operates it. The value is in the tuning, in somebody reading the output every day and acting on it — which is the part that quietly stops happening about four months in.
A managed service is not a licence with our name on the invoice. It is us operating the thing: the tuning, the exceptions, the awkward asset nobody wants to touch, and the report that tells you whether any of it moved.
Almost every security control fails the same way. It is bought after an incident or an audit, deployed with enthusiasm, and produces a great deal of output. Then the person who understood it changes role, the output stops being read, and eighteen months later it is a line on a renewal that nobody can defend.
What we sell is the operating half. Our SOC already runs 24/7 and already reads alert output for a living, so the controls we manage are watched by the same people who would be handling the incident if one of them mattered. That is the only reason a managed service is worth more than the licence it sits on.
Run by the same 24/7 SOC that handles detection and response.
Tuned to your estate and your tolerance for noise, then re-tuned as it changes.
Reporting written to be read by someone who is not a security specialist.
Findings worked through to closure, not handed over as a list.
Priced per asset, so the bill tracks what you actually have.
What we run
Two services, one team behind them.
Both are subscriptions, both are priced per asset, and both are operated rather than resold.
Exposure
Vulnerability & Patch Management
Continuous discovery and scanning across everything you own — not only the machines your endpoint tooling already knows about — with patching as the half that actually closes the finding.
Internal, external and web application scanning
Assets your EDR cannot see: network kit, hypervisors, appliances
Operating system and third-party application patching
Prioritised by what is genuinely being exploited
Charged per agent, with the wider modules per site.
A WAF in front of your applications, in blocking mode, kept there. The service is the tuning and the exception handling — which is the work that decides whether it protects anything.
Deployed, tuned and moved into blocking mode
False positives handled without switching protection off
OWASP Top 10, bots and volumetric protection
Rules revisited when the application changes
Charged per application, by traffic and complexity.
Post-incident reviews rarely find a missing product. They find a product that was present, licensed, and configured in a way that guaranteed it would not help.
A vulnerability scanner nobody has opened since the onboarding call. A WAF left in detection-only mode two years ago because it broke a checkout page once and turning it back on felt risky. An agent that stopped reporting when a server was rebuilt. None of these are product failures, and none of them generate an alert saying the control has quietly stopped working.
They happen because operating a control is a standing job and it is nobody’s. It competes with projects, it has no deadline, and it only becomes visible when it has already failed. Handing that job to a team whose entire week is the same job is the difference between owning a control and owning a licence.
Not once at deployment. Estates change, applications get rewritten, and a rule set that was right in March is producing noise or silence by September.
Somebody reads the output daily
The same analysts who staff the SOC overnight. Output that nobody reads is the normal failure mode, and it is the one we are actually being paid to prevent.
Exceptions are handled, not avoided
The awkward legacy app, the server that cannot take a reboot until quarter-end. Those get a documented exception with a review date rather than becoming the reason protection is switched off.
Findings are closed, not listed
A report that ends in a list is a report that becomes somebody else’s backlog. The remediation is inside the service, and the re-check proves it landed.
If you already have the licences, we will run what you have rather than sell you ours. The service is the people, not the product.
How it starts
Find out what is there, then run it properly.
Both services start the same way, because both depend on knowing what you actually have rather than what the asset register says.
01
Discovery
What is on the estate, what is exposed to the internet, and what is running that nobody has thought about in two years. This is usually the uncomfortable part.
02
Baseline
A first assessment that says where you are today. It is useful on its own and it is what everything afterwards gets measured against.
03
Agree the rules
Patch windows, change approval, what we act on without asking and what always comes to you first. Written down before we touch anything.
04
Operate
Scanning, tuning, patching and exception handling on a cycle, with the SOC reading the output the same way it reads everything else.
05
Report on movement
Not a monthly export of everything. What changed, what closed, what regressed and what still needs a decision from you.
Questions
Managed services, answered.
What are managed security services?
Security controls that somebody else operates for you — deploying them, tuning them, reading what they produce and acting on it. The distinction that matters is between buying a licence and buying the standing job of running it properly.
How is this different from your SOC service?
The SOC watches your estate and responds to what it sees. These services run specific controls: finding and fixing weaknesses, and protecting web applications. The same analysts sit behind both, so a finding here reaches the people who would handle the incident.
Do we have to buy the tooling through you?
No. Where you already hold licences we will operate what you have. Where you do not, it is included in the service. We will tell you plainly which of the two is cheaper for your situation.
How are these priced?
Per asset — per agent for vulnerability and patch management, per application for the WAF — so the bill tracks what you actually have rather than a band you grow into. Scope decides the rest, so pricing comes after a conversation.
Can we take one without the other?
Yes. They solve different problems and neither depends on the other. Most organisations start with vulnerability management because it tells you what you are dealing with.
Do we need you to run our SOC as well?
No. Both services stand alone. They are materially better where we also run detection and response, because a finding and an alert end up in front of the same people, and we will be clear about which version you are buying.
Where to start
Start with what is actually there not what the register says.
A first discovery run tells you more than a proposal will. It is the same starting point for both services and it is usually the part that changes the conversation.