Services

Security & recovery, engineered as one.

Four specialist capabilities under one accountable team — from 24/7 threat monitoring with a 15-minute critical-alert SLA, to recovering data others consider permanently lost. Here's exactly how each one works, what's included, and what you receive.

15 min
Critical-alert response SLA
24/7/365
SOC monitoring & response
95%
Ransomware recovery — no ransom
Free
Evaluation & NDA on recovery
01 · Managed security

SOC as a Service — 24/7 Protection.

A fully managed Security Operations Center: certified analysts monitor, hunt and respond around the clock so you get enterprise-grade defense without building — or staffing — your own SOC.

EssentialAdvancedEnterprise
  • SIEM, XDR, NDR, EDR stack, fully monitored & tuned
  • Proactive threat hunting & central logging
  • Dedicated incident response team on standby
  • WAF & NAC as a service
  • Penetration testing & vulnerability assessments
  • Tiered SLAs — critical alerts answered in 15 minutes

How onboarding works

Assess & scope

We map your assets, log sources and crown-jewel systems, then agree alert priorities and escalation paths.

Deploy & integrate

Sensors and log forwarding are connected to our SIEM/XDR; detections are tuned to your environment to cut false positives.

Monitor & hunt

Analysts watch 24/7, triage every alert and proactively hunt for threats that automated tooling misses.

Respond & report

On a confirmed threat we contain and guide remediation, then deliver a written incident report and a monthly review.

What's included by tier

Draft tiers — confirm or adjust the specifics with us; nothing here is locked.

Capability EssentialSmall teams AdvancedGrowing orgs EnterpriseMission-critical
24/7 monitoring & central logging (SIEM)
Endpoint detectionEDREDR + XDRXDR + NDR
Critical-alert response SLA1 hour30 min15 min
Proactive threat huntingMonthlyContinuous
Incident response teamBusiness hours24/724/7 + dedicated lead
Vulnerability assessmentsQuarterlyMonthlyContinuous
Penetration testingAnnualQuarterly
Dark-web & credential monitoring
Compliance reporting (PCI / GDPR / ISO)BasicStandardFull + audit support
Service review cadenceMonthly reportMonthly callWeekly + named contact

What you receive

95%
Ransomware recovery — without paying the ransom

Active incident? Our emergency line triggers a 15-minute response. We contain the blast radius first, then recover — using decryption and rebuild tooling we develop in-house.

Report an incident →
02 · Emergency response

Ransomware Response.

Where most providers stop and advise you to pay, we start. Four stages, one accountable team, no ransom.

The response timeline

Isolate

Contain affected systems to stop lateral spread and preserve forensic evidence — within the first response window.

Analyze

Identify the strain, entry point and scope through malware forensics and behaviour analysis.

Decrypt

Apply proprietary decryption and recovery tooling — no ransom paid, no attacker contact required.

Restore

Rebuild and validate clean systems, restore critical data, and harden against re-entry.

What you receive

03 · Recovery & resilience

Get your data back — and keep it safe.

Two complementary services: recover what's already lost, and make sure the next incident can't take it from you.

Data Recovery as a Service

Physical & logical recovery across every medium, in an ISO-standard cleanroom — confidentiality guaranteed under NDA.

  • HDD, SSD, RAID, NAS, SAN, VM & database recovery
  • Free diagnostic evaluation before any work begins
  • Cleanroom lab operations for physical damage
  • Fixed quote after diagnosis — no recovery, no fee
  • Encrypted handover & certified data wipe of media

Backup Assurance

An insurance-style backup subscription with ransomware-proof, air-gapped architecture — pay monthly, recover anytime at no extra cost.

  • Local offline (air-gapped) + real-time automated backup
  • Immutable snapshots ransomware can't encrypt
  • Regular restore tests so backups actually work
  • Monthly & yearly plans with priority response
  • Recovery included — no surprise bill when you need it
04 · Our commitment

Response times we put in writing.

Every managed engagement carries a contractual SLA. These are the response targets — the window from alert or call to a human taking action.

15 min
Critical incidents (Enterprise)
1 hour
Standard priority alerts
24/7/365
Live SOC coverage — no gaps
99.9%
Monitoring uptime target
Questions

Before you talk to us.

Do we need to replace our existing security tools?

No. Our SOC integrates with the stack you already run wherever possible — we connect to your existing log sources, endpoints and firewalls, and only recommend additions where there's a genuine gap. The goal is coverage, not a rip-and-replace.

What actually happens when a critical alert fires?

A certified analyst triages it within your SLA window (15 minutes for Enterprise). If it's a confirmed threat, we move to containment immediately, notify your named contacts, and guide remediation — then deliver a written incident report with root cause once it's resolved.

Can you really recover data without paying the ransom?

In the large majority of cases, yes — we recover roughly 95% of ransomware incidents using decryption and rebuild tooling we develop in-house, combined with clean backups where they exist. We never contact the attacker or pay on your behalf. Where data is genuinely unrecoverable, we tell you straight.

How fast can you onboard us?

A standard SOC onboarding runs in phases — assess, deploy, tune, go-live — and most environments are under active monitoring within a couple of weeks. For an active incident, response starts the moment you call; onboarding paperwork follows.

How is pricing structured?

Managed services are a fixed monthly subscription based on the tier and scope (assets, log volume, locations). Data recovery is quoted per case after a free diagnostic — no recovery, no fee. We'll give you a clear proposal after a short discovery call.

Is everything kept confidential?

Yes. Every engagement is covered by an NDA, all operations follow strict data-privacy controls, and recovered media is handed over encrypted and then securely wiped. Confidentiality is contractual, not just a promise.

Next step

Not sure which service you need?

Book a free discovery call and we'll assess your current posture and recommend the right protection — no obligation.

Book a discovery call →