Managed Defence

We operate it.
You are not left
holding the console.

Most security products are sold and then handed over. The institution becomes responsible for tuning a system it did not build, and the protection degrades quietly from the day the project team leaves.

Managed Defence is the opposite arrangement. The system stays ours to operate. What you hold is the authority to direct it and the evidence of what it did.

What the engagement covers

01

The system watches continuously

Detection, containment and rollback run on the endpoint itself, autonomously, without waiting for anyone to be awake.

02

We operate it, not you

Policy, tuning, model updates, baselines and rollout stages are ours to run. Your team is not asked to become the product's administrator.

03

Escalation to named engineers

Where a decision needs a person, it reaches one of ours — the people who built the system, during agreed coverage hours.

04

Evidence you can hand to an auditor

Every action the system takes is recorded with what it saw and why it acted, in a form a SIEM or a regulator will accept.

05

Periodic re-assessment

The estate is re-examined on a cycle, because the estate changes and a one-time picture stops being true.

06

A standing review

A recurring conversation about what changed, what was stopped, and what is still exposed.

What we do not claim

The machine is awake at four in the morning. A person may not be.

We do not operate a staffed twenty-four-hour floor, and we will not sell you one. What runs continuously is the system: detection, containment, process termination, quarantine and rollback happen on the endpoint at machine speed, whether or not anyone is watching. That is the design — a defence that depends on a human being awake is a defence with a nightly gap in it.

Human response — judgement calls, forensic follow-up, decisions that change policy — happens within agreed coverage hours, by named engineers from the team that built the system. Those hours are written into the engagement rather than implied by a badge on a website. If your risk requires something wider, say so in the request and we will tell you honestly whether we can meet it.

How this relates to the product

Cyber Defense AISOS

The system itself — the operating layer that decides and acts on the endpoint. An institution with its own security engineering function can license it and run it themselves, in their own region or inside their own perimeter.

The system →

Managed Defence

The same system, operated by us under a standing agreement. Chosen by institutions that want the protection without acquiring the specialism required to keep it sharp.

Both run the same engine. Neither is a reduced edition of the other.

It begins with an assessment.

We do not take on the defence of an estate we have not examined. The assessment establishes what is actually there; the managed engagement is scoped and priced against what it finds. There is no standard rate, because there is no standard estate — a quotation is issued against an agreed scope.