Skip to content

Platform / Detect24/7

Managed XDR

Continuous detection and response run by our CERT analysts, not a ticket queue. Every alert is triaged by a human before it reaches you, and we will take containment action on your behalf where you have authorised it.

24/7

analyst coverage, not on-call rotation

What you receive

  • Human triage on every escalation — no auto-forwarded alerts
  • Endpoint, network, cloud and identity telemetry in one timeline
  • Delegated containment authority, scoped by written playbook
  • Full telemetry retention for forensic reconstruction

When you need this

Three situations that call for it. If none of them is yours, it probably is not the right spend.

  • 01

    Nobody is watching between Friday and Monday

    Intrusions are timed for when your staff are not there — weekends and public holidays are chosen deliberately, because the gap between execution and someone noticing is the attacker's whole advantage. Cover has to be staffed, not on-call.

  • 02

    Your EDR console is full and nobody reads it

    A detection tool producing more alerts than your team can triage is not doing the work, it is describing it. Triage by an analyst who can decide, contain and tell you what happened turns that volume into a small number of things that actually matter.

  • 03

    A customer or insurer is asking for 24/7 cover

    Contract schedules and insurance proposal forms increasingly ask for continuous monitoring and a defined containment authority. Answering that with an EDR licence and office hours is where these conversations usually stall.

How it runs

  1. 01

    Scoping call

    Thirty minutes with an engineer. We establish what you already run, where the gaps actually are, and whether a module earns its place beside your existing tooling.

  2. 02

    Connect and baseline

    We connect the data sources the module reads and spend the first weeks learning what normal looks like in your estate. Tuning against your traffic is what stops the alerts being noise.

  3. 03

    Go live

    The module starts writing to the adversary graph and escalating to you. Escalation routes, thresholds and who gets woken at 03:00 are agreed in writing beforehand.

  4. 04

    Continuous review

    A standing review of what fired, what did not, and what changed in your estate. A detection set that is not revisited decays — the attacks move even when your systems do not.

No lock-in

Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.

Who turns up

The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.

Scope

What this does not cover

  • We monitor what you send us — telemetry you do not forward, and endpoints without an agent, sit outside detection coverage.

  • Containment stops the incident; forensic reconstruction, attribution and regulator reporting are Incident Response and Digital Forensics.

  • Monitoring does not test whether your controls work — that is Penetration Testing and Red Teaming.

Measured against

NIS2 Directive (EU) 2022/2555, Art. 23
Requires an early warning within 24 hours of becoming aware of a significant incident, an incident notification with an initial assessment within 72 hours, and a final report within one month.
ISO/IEC 27001:2022 Annex A 8.16
Requires networks, systems and applications to be monitored for anomalous behaviour, with potential incidents evaluated.
DORA Regulation (EU) 2022/2554, Art. 17
Requires financial entities to run a process that detects, manages and notifies ICT-related incidents, and to log and categorise them; the criteria that make an incident major sit in Art. 18.

If the scope is wrong

Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.

Questions

The ones we are actually asked.

What happens if containment breaks production?

It can, which is why containment authority is written down before it is used — which hosts, which actions, which hours, and who we telephone first. Where an action falls outside that playbook we escalate to you instead of acting.

Can we keep our existing EDR and SIEM?

Usually — the value is in the analysis, not in replacing tools you already pay for. Where a source cannot give us the fields needed to triage properly, we will tell you that rather than pretend the coverage exists.

How does this help with NIS2 24-hour reporting?

The clock in NIS2 Article 23 starts when you become aware of a significant incident, so detection time and reporting time are the same problem. Continuous monitoring is what makes an early warning achievable rather than reconstructed.

Next step

See what an attacker sees

We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.

30 min

A scoping call, with an engineer rather than a sales rep.

What it costs

Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.

Under attack now?

Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.