Line 04 · Continuous operations

Security that runs while you sleep.

Managed Security is the continuous half of the practice — detection and response, vulnerability management, identity operations, cloud posture, third-party risk, and the awareness program your people actually see, run week after week by the same senior team. It's how the improvements from an assessment stay true a year later.

MGD-01of 06 · Detection & response

Managed Defence (MDR)

24/7 eyes on glass, with endpoint depth built in.

Managed Defence is continuous detection and response run by people who investigate before they page you: telemetry from your endpoints, identities, and cloud is watched around the clock, triaged by analysts, and acted on within agreed response times. Endpoint protection is part of the service, not a separate line item — the EDR platform is deployed, tuned, and driven by the same team that answers the alert. You get a security operation without building one.

  • 24/7 monitoring & triage
  • Endpoint (EDR) included
  • Guided & active response
  • Agreed response times
Read moreRead less

What the service includes

  • Around-the-clock alert monitoring & validation
  • Analyst-led triage & investigation
  • Managed threat hunting for undetected activity
  • Predefined playbooks & response actions
  • Campaign response when your industry is targeted
  • Escalation into full incident response when warranted

Coverage options

Coverage is sized to the operation you actually need — after-hours monitoring that complements a business-hours team, full 24/7 operations, or extended coverage for OT and ICS environments where the assets never sleep and neither can the watching.

Platform depth

The service runs on the leading detection platforms — CrowdStrike first among them, backed by our dedicated Center of Excellence — so the telemetry, tuning, and response actions come from people who work the platform every day.

MGD-02of 06 · Continuous vulnerability management

Managed Vulnerability

A vulnerability program that runs every week, not once a year.

Scanning is easy; the program around it is the hard part. We run yours continuously — discovering assets, scanning on a cadence, deduplicating and prioritizing by actual exploitability in your environment, and routing fixes to the teams that own them. Ongoing risk reporting is the natural output, so leadership always knows the trend line, not just the latest snapshot.

  • Continuous discovery & scanning
  • Exploitability-based priority
  • Remediation routing
  • Ongoing risk reporting
Read moreRead less

The program we run

  • Asset discovery & inventory upkeep
  • Scheduled scanning with validated results
  • Exploitability-based prioritization & risk scoring
  • Remediation routing, tracking & verification
  • Custom dashboards & trend reporting
  • Policy, procedure & process development

Compliance output

The same program produces the scanning evidence your obligations ask for — PCI DSS, NIST, HIPAA, and CIS among them — as a by-product of running well, not as a separate annual exercise.

Platforms

We operate the scanning platforms you already own or help you choose one — certified across Qualys, Tenable, Rapid7, and Tanium — rather than forcing a rip-and-replace to fit our tooling.

MGD-03of 06 · Identity operations

Managed Identity

Access that stays clean after the project ends.

Identity programs decay quietly: accounts outlive employees, permissions accumulate, and the access review slips a quarter. We operate the routine that prevents that — joiner-mover-leaver execution, scheduled access reviews, privileged account monitoring, and MFA coverage that holds instead of quietly drifting. The governance model your advisory work designed keeps being true a year later.

  • Lifecycle (JML) operations
  • Scheduled access reviews
  • Privileged account monitoring
  • MFA coverage upkeep
Read moreRead less

Operations we take on

  • Joiner-mover-leaver lifecycle execution
  • Access review & certification campaigns
  • Privileged vault administration & monitoring
  • Platform updates, upgrades & patch management
  • High-availability & disaster-recovery support
  • Compliance & audit reporting

Coverage & platforms

Engagements run from business-hours support to full 24/7 operations, delivered by engineers certified across the identity stack — SailPoint, Saviynt, CyberArk, Delinea, Okta, BeyondTrust, and Microsoft Entra. The same people who administer the vault can harden it.

MGD-04of 06 · Cloud posture — operate

Managed CloudSec

Continuous guardrails for an environment that changes daily.

A cloud assessment is a photograph; your cloud is a movie. Managed CloudSec watches posture continuously across AWS, Azure, GCP, and Microsoft 365 — catching risky configuration changes, public exposure, and identity drift close to when they happen, and fixing them under agreed guardrails. It is the operate side of the cloud pathway that begins with the Compliance assessment.

  • Continuous posture monitoring
  • Misconfiguration response
  • Identity & exposure drift
  • Follows Cloud Security Assessment
Read moreRead less

What's included

  • Continuous posture & configuration management
  • Cloud threat detection & response
  • Workload & runtime protection
  • Container & Kubernetes security
  • Identity & access activity monitoring
  • Telemetry routing & log-cost optimization

Frameworks & platforms

Posture is enforced against the benchmarks your auditors recognize — CIS, ISO 27017, NIST CSF, SOC 2 — using cloud-native security platforms we hold certifications on, CrowdStrike Cloud Security and Wiz among them. Findings map back to the same risk language as the rest of your program.

MGD-05of 06 · Third-party & exposure risk

Managed Risk

Your vendors and your external footprint, watched between reviews.

Third-party risk decays the way everything else does: a vendor is assessed at onboarding and nobody looks again until renewal. Managed Risk keeps the picture current — external attack surface and security ratings monitored continuously across your vendor base, data-leak alerting when something of yours surfaces where it should not, and assessment questionnaires issued and chased on a schedule instead of in a spreadsheet. Analysts read the output before you do, so what reaches you is the handful of vendors whose position actually changed.

  • Continuous vendor monitoring
  • Security ratings & data-leak alerts
  • Questionnaire campaigns
  • Analyst-reviewed findings
Read moreRead less

What we run

  • Continuous external attack-surface visibility
  • Security ratings tracked across the vendor base
  • Proactive data-leak alerting
  • Custom and regulation-specific questionnaires
  • Assessment workflow, chasing & escalation
  • Vendor tiering & lifecycle review cadence

How much we take on

The engagement scales to the team you have. At its lightest we assess vendors and point you at what matters; in the middle we run the operational side while your team keeps the decisions; at its fullest we run the program end to end. Moving between those is a conversation, not a re-scope.

How this differs from the Advisory assessment

Risk & Exposure Management is an engagement: a defined set of vendors and systems, assessed over weeks, finished when you hold the register and the ranked decisions. Managed Risk is the standing service — wider coverage across the whole vendor base rather than a sampled set, and continuous rather than dated. Plenty of clients take the assessment alone and run it in-house. This is for the ones who would rather not.

MGD-06of 06 · Human risk — operate

Managed Security Awareness Training

Training that answers what your people actually clicked.

Annual awareness training is a compliance artifact; the attacks are continuous, so the program has to be too. We run yours: randomized phishing simulations built from pretexts your sector genuinely sees, training assigned automatically to the people a given campaign caught rather than to everyone, and risk scored per person and per department so you can see which teams carry the exposure. The measurement is honest — the point is a trend line that moves, not a pass rate to present.

  • Continuous phishing simulation
  • Training assigned by behaviour
  • Per-team risk scoring
  • Reporting for both audiences
Read moreRead less

What the program runs

  • Randomized simulation campaigns on a continuous cadence
  • Role- and behaviour-driven training assignment
  • Per-user and per-department risk scoring
  • Onboarding and refresher tracks
  • Compliance evidence for training obligations
  • Quarterly review of results and next-quarter focus

Reporting for two audiences

Security teams get campaign-level detail — who was targeted, what the pretext was, where the click came from. Leadership gets the trend and the comparison to where you started. Both come from the same run, so the numbers in the board pack are the numbers in the console.

How this differs from Social Engineering testing

They are separate services and neither contains the other. Offensive Security runs a scoped, time-boxed test to find out how the organization holds up against a credible pretext — it produces findings. This produces behaviour change: a continuous cadence, training assigned by what someone actually clicked, and a trend measured by team over quarters. Most organizations want both, and they are bought and delivered differently.