C://SECURE2924/7 Cyber Protection
Attacks do not wait
for business hours.
Round-the-clock managed detection and response. Most intrusions begin outside working hours precisely because that is when nobody is watching. This is the service that means somebody is.
THE PROBLEM
The alert that mattered arrived at 2:14am on a Sunday. Nobody read it until Monday.
Attackers work when defenders do not. A compromised account is typically used within hours, and ransomware is usually deployed overnight or over a long weekend, when the gap between detection and response is widest.
Detection tooling is only half a control. Without someone able to act on what it finds, at any hour, with the authority to isolate a machine without waiting for approval, you have bought a very detailed record of how you were breached.
- 01Nobody is on after 5pmAlerts accumulate overnight and get triaged in the morning, if at all.
- 02Too many alerts to readVolume without tuning means the real one is buried among the noise.
- 03Nobody may pull the plugContainment waits for someone senior to wake up and approve it.
- 04Cover has gaps nobody plannedChristmas, Easter, and the week your one security-minded person is away.
WHAT YOU GET
What round-the-clock actually means
Not a dashboard you are expected to watch. A service with people, defined response authority, and a written account of every action taken.
- 01
Continuous monitoring
Identity, endpoints, and cloud services watched every hour of every day, including the ones your team is not working.
- 02
Human triage
Every alert that survives tuning is reviewed by a person. Automation narrows the field; it does not make the call.
- 03
Pre-authorised containment
Agreed in advance: which actions we may take without waking you, such as isolating a device, disabling an account, or revoking a session.
- 04
Threat hunting
Proactive searches for the things detection rules miss, informed by what is currently being used against New Zealand organisations.
- 05
Monthly reporting
What was seen, what was acted on, and what it means, written for a board rather than for a security analyst.
- 06
Direct escalation
A path to a named engineer when something is genuinely wrong. No ticket queue between you and help.
HOW IT RUNS
Tune, watch, act, report
The first month is mostly tuning. A service that cries wolf gets ignored, which is the failure mode we are here to prevent.
- 01Weeks 1 – 2
Onboard
Sensors deployed across identity, endpoints, and cloud. We learn what normal looks like in your environment before deciding what abnormal means.
- 02Weeks 3 – 4
Tune
Rules are adjusted to your actual working patterns, including the night-shift logins and offshore contractors that would otherwise fire an alert every night.
- 03Ongoing
Run
Continuous monitoring with human triage. Containment happens inside the authority you granted, and you are told what was done and why.
- 04Monthly
Review
What we saw, what we stopped, what changed in the threat landscape, and what we recommend adjusting next.
WHAT CHANGES
The difference cover makes
- Overnight and weekend alerts are acted on, not queued.
- Containment happens in minutes because the authority is already agreed.
- Every action taken on your environment is logged and explained.
- Your cyber insurer sees monitoring evidence at renewal.
FAQ
Questions we get asked
01What is MDR?
Managed detection and response. It combines the tooling that spots suspicious behaviour with a team who investigate and act on what it finds. The distinction that matters is the response half: plenty of products detect, far fewer services take action on your behalf.
02Is this a real 24/7 team or an automated system?
Automation does the first pass, because no team can read every event. A person reviews anything that survives it, at any hour. Ask us how the roster is staffed and we will tell you plainly.
03Can you isolate one of our machines without asking?
Only within the authority you set during onboarding. Most clients pre-authorise isolating a device and disabling an account, because the delay in waking someone is usually more damaging than the disruption. You choose where that line sits.
04How is this different from managed cybersecurity?
Managed cybersecurity is the posture: the controls, configuration, and evidence. This is the watch: continuous monitoring and response on top of that posture. Running this without the controls in place is expensive, so we would put the foundations in first.
05What if you miss something?
No monitoring service catches everything, and any provider claiming otherwise is selling something. What we commit to is defined coverage, honest reporting on what was and was not seen, and a response capability ready when something gets through.
06Do we still need cyber insurance?
Yes. Monitoring reduces the likelihood and the cost of an incident; it does not transfer the residual risk. Many insurers now price better, or will only offer cover at all, where continuous monitoring is in place.
07What actually happens at two in the morning when an alert fires?
An analyst reviews it within the agreed triage window, establishes whether it is real, and acts within the authority you have given us in advance. That might mean isolating a device from the network, disabling an account, or revoking active sessions. You get a notification and a written account of what happened. The point of agreeing the authority beforehand is that nobody is trying to reach you for permission while an attacker is still working.
08How much does 24/7 cyber monitoring cost?
It is priced on the number of users and devices being monitored and on what authority you want us to hold. It is a meaningful step up from managed cyber security, and it is worth taking only once the underlying controls are in place. If you have not yet enforced multi-factor authentication everywhere, spend the money there first. We will tell you that rather than sell you this.
09Is this the same as a SOC?
It is the function a security operations centre performs, delivered as a service rather than as a team you build. Standing up an internal SOC means hiring shift coverage, buying the platform, and tuning it, which is beyond the reach of almost every New Zealand organisation outside the largest. Buying it as a service is how the same capability becomes available to a business of thirty people.
10We are a thirty person business. Is this overkill?
It depends entirely on what an incident would cost you rather than on your head count. A thirty person professional services firm holding client confidential information, or one that cannot trade without its systems, has a genuine case. A thirty person business with low data sensitivity and a tolerance for a few days of disruption is probably better served by putting the same money into prevention and tested backups. We would rather establish which you are than assume.
Find out what is already happening.
Most environments have something in them worth knowing about. We can tell you what, before you commit to anything ongoing.
← All services