Request a proposal
Managed Security
MDR EssentialsMDR CompleteSMB Security EssentialSMB Full Stack Managed SecurityContinuous Compliance (Delve)Security Compliance SuiteSMB Premium + Compliance
Programs
Grid CommandMulti-Modal Threat IntelligencePhishing + Awareness TrainingTrust Center ManagedCompliance Audit + Remediation Project
Trust Center
Cybersecurity Trust Center BuildTrust Center Care Plan
Company
Managed PlansFree AssessmentAboutBlogContactRequest a proposal

MDR Complete — $997/month

We do not just tell you. We act.

Everything in MDR Essentials, plus the part that matters most at 3am: within the authority you grant in writing, we isolate hosts, disable accounts and block indicators directly, rather than waiting for someone on your side to wake up and act.

What you get

  • Everything in MDR Essentials — 24/7 monitoring, analyst triage, weekly reporting, monthly tuning, same fixed-price model.
  • Active containment on your behalf — we act within your documented authority instead of handing you a task list.
  • Standing response authority — a written matrix defining exactly what we may do without asking, what needs a call first, and who can approve out of hours.
  • Incident timeline and after-action — confirmed incidents get a written timeline, root cause where determinable, and a remediation plan with owners.
  • Monthly executive report — a one-page version for leadership alongside the technical detail.
  • Quarterly posture review — a session on recurring root causes and what to fix structurally rather than repeatedly.

Response authority — the default matrix

Agreed and signed at kickoff. This is the single most important document in the engagement, so it is written before anything goes live rather than improvised during an incident.

  • Act immediately, notify after — isolate a workstation, disable a standard user account, block a domain, IP or file hash.
  • Call first — isolate a server (we act if there is no answer within 15 minutes at SEV-1); disable a privileged or service account.
  • Explicit approval required — anything affecting production availability. No standing authority.

Response targets

  • SEV-1 Critical — 15 minutes, 24/7
  • SEV-2 High — 1 hour, 24/7
  • SEV-3 Medium — 4 business hours
  • SEV-4 Low — 1 business day

Acknowledgement targets, not resolution times. Resolution depends on environment access, your approval steps and the nature of the incident.

What is not included

  • Remediation labour — rebuilds, restores and change-controlled fixes stay with you or your IT partner.
  • Legal, regulatory notification or public relations handling during an incident.
  • Forensic work intended for litigation or insurance claims.
  • OT/ICS and specialist cloud workload protection unless separately scoped.

Billed monthly. No minimum term. Cancel any time before your next renewal date.