Managed security · Recurring

Someone is watching your estate, every day, and telling you what matters.

Most small Australian businesses cannot justify a security hire, so nobody owns the job and it quietly goes undone. We take it on month to month: we run the detection, we watch the infrastructure, we triage what comes back, and we send you a short list of things that actually need doing.

Detection

Endpoint detection and alerting

We deploy and manage detection agents across your workstations and servers, keep them healthy and current, and watch what they report. When something fires, a person looks at it before you hear about it, so what reaches you is a judgement rather than a raw event.

Included

  • Agent deployment, enrolment and health monitoring
  • Continuous detection across endpoints and servers
  • Human triage of every alert, with false positives tuned out
  • Notification to you with context and a recommended action
  • Monthly summary of what fired and what it turned out to be

Worth knowing

  • Detection quality depends on a known baseline, so we review before we enrol
  • Coverage is what we enrol. Anything outside the fleet is not watched
  • Response beyond triage is a separate authorisation, never assumed
Infrastructure

Domain, DNS and certificate monitoring

Your domains are the part of your estate an attacker can see without touching you, and the part that breaks silently. We monitor every record, catch changes you did not make, and make sure nothing expires on a weekend. This runs on the same engine behind our free tools, tuned and watched by us rather than left to you.

Included

  • DNS record change detection across every domain and subdomain
  • TLS certificate expiry, chain and protocol validation
  • Email authentication monitoring for SPF, DKIM and DMARC drift
  • Domain health grading, tracked over time rather than one off
  • Subdomain discovery, so new exposure gets noticed

Why it matters

  • An unnoticed DNS change is how mail gets silently redirected
  • A lapsed certificate takes you offline and costs you trust
  • A weak DMARC policy lets anyone send invoices as you
DNS CanarySSL SentinelSPF / DKIM / DMARCMTA-STS
Posture

Patching and Essential Eight uplift

Detection tells you when something got in. Posture is what stops it. We track your patch state, hardening and control maturity against the ASD Essential Eight, work the gaps in a sensible order, and keep a record you can show an insurer, an auditor or a customer doing vendor due diligence.

Included

  • Patch and update status across the managed fleet
  • Essential Eight maturity tracking, scored and dated
  • A prioritised uplift plan, worked steadily rather than in a panic
  • Evidence kept as we go, so audits are not a scramble

Maps to

  • ASD Essential Eight maturity levels
  • Insurer and broker security questionnaires
  • Customer vendor risk assessments
Essential EightCIS BenchmarksNIST CSF
Advisory

A security person on call

The part clients use most and expect least. A retainer includes someone to ask before you sign the contract, buy the tool, approve the integration or answer the questionnaire. Not a ticket system, and not an account manager. The person who does the work.

Typical use

  • Reviewing a vendor or a new integration before you commit
  • Completing insurer and customer security questionnaires
  • Second opinions on advice you have been given
  • Policy and procedure review as you grow

Not included

  • General IT help desk. We will tell you honestly if that is what you need
  • Unlimited project work. Larger pieces get their own written scope

The boundary, stated plainly

A lot of managed security is sold as though the provider will quietly handle everything. We do not work that way, and you should be wary of anyone who says they do without telling you what they will change on your systems.

We detect, we triage, and we advise. Anything that changes state on your estate, isolating a machine, disabling an account, rolling a credential, pushing a configuration, happens only with your written authorisation, and is billed separately at agreed rates. You always know who changed what and when.

alert-2026-0914.log
04:12 detection suspicious sign in, ACME-LT-04 04:14 triage reviewed by analyst 04:19 context new country, valid MFA, VPN off 04:21 assessment likely travel, confirm with user 04:22 notify sent to client contact 08:40 confirmed user in Singapore, no action 08:41 closed tuned, no repeat alert
$

Getting started

01

Scoping call

We work out what you have, who looks after it now, and whether managed security is even the right answer for you yet.

02

Baseline review

Before we monitor anything we establish what normal looks like. Detection against an unknown baseline is guesswork, so this step is not optional.

03

Deploy and tune

Agents go on, monitors go up, and we spend the first weeks tuning out the noise so your alerts stay worth reading.

04

Run and report

Continuous monitoring, triaged alerts as they happen, and a monthly report. Scope is reviewed as your estate changes.

Find out what you are not seeing.

A scoping call is a conversation, not a sales process. If you are already covered we will say so.

Book a scoping call →