SOC status: Operational/Continuous monitoring active

Acronis MDR / XDR available +230 5254 7558

Home/How we work

Onboarding

Seamless onboarding, immediate protection

A structured, low-friction pathway to total cyber resilience — designed so that switching provider costs you no downtime and no coverage gap.

The pathway

Four to six weeks, end to end

Assessment takes one to two weeks. Proposal and approval, one. Deployment, two to three depending on estate size. Emergency engagements compress this substantially.

Initial Risk & Environment Assessment

A comprehensive review of your existing infrastructure, active contracts and current security posture to identify immediate vulnerabilities and coverage gaps.

  • Asset and identity inventory
  • Existing contract and licence review
  • External attack-surface scan
  • Gap analysis against your obligations
  • Findings session with prioritised risks

Tailored Architecture & Proposal

Our engineering team designs a custom, budget-aligned defence roadmap, scoping precise services without forcing unnecessary bloat or redundant toolsets.

  • Workload tiering and RTO/RPO targets
  • Control design mapped to findings
  • Phased cost model across agreed milestones
  • RACI between your team and ours
  • Written proposal with no bundled surprises

Frictionless Onboarding & Migration

A zero-downtime deployment, managing all software configurations, policy setups and contract takeovers with complete technical precision.

  • Pilot ring before fleet-wide rollout
  • Policy and exclusion tuning per application
  • Contract and licence takeover
  • Runbook authoring and first restore test
  • Handover briefing for your team

Continuous Monitoring & Advisory

Once live, your dedicated cyber analysts provide proactive threat hunting, continuous system updates and regular executive intelligence briefings.

  • Acronis MDR/XDR monitoring with defined escalation
  • Monthly protection and patch compliance report
  • Quarterly posture review and scope adjustment
  • Threat advisories relevant to your sector
  • Annual tested recovery exercise

Service levels

What “we will respond” actually means

Priority Definition Acknowledgement Response Reporting
P1 — Critical Active compromise, ransomware, data exfiltration, total outage 15 minutes Continuous until contained Executive brief within 24 hours
P2 — High Confirmed malware on an endpoint, targeted phishing, failed backup on Tier 0 1 hour Same business day Written summary within 3 days
P3 — Medium Policy violation, single-user issue, non-critical alert triage 4 business hours Next business day In the monthly report
P4 — Low Requests, reporting queries, scheduled changes 1 business day Agreed change window In the monthly report

Indicative targets. Final SLAs are contracted per engagement and vary with the service tier you select.

Questions we get asked

Before you commit

How long does onboarding actually take?

For a typical estate of 50 to 250 endpoints, assessment takes one to two weeks, proposal one week, and deployment two to four weeks depending on maintenance windows. Protection on critical assets usually goes live in the first week of deployment rather than at the end.

We are mid-contract with another provider. Can you still take over?

Yes. We assess in parallel, agree a takeover date at your contract boundary, and match or beat your existing terms. There are no hidden takeover fees. Where your incumbent holds licences we can usually transfer rather than repurchase them.

Do you replace our IT provider?

Not unless you want us to. The co-managed model is the most common: your IT team or provider keeps operations and first-line support, we own security tooling, detection, response and advisory. The split is written down before we start.

What happens at 2am when something breaks?

Detection and first response run through Acronis MDR, which monitors your estate around the clock and can contain a threat the moment it is detected. Our Solutions Specialists then take over with full context — not an anonymous ticket queue. For declared incidents we run the containment with your team rather than emailing instructions.

Will you sign our client’s security questionnaire?

We complete supplier questionnaires and provide the control evidence behind our answers. Where a client or regulator asks for something we do not do, we say so rather than answering optimistically.

Where is our data stored?

Storage region is chosen deliberately per engagement. Where contracts, client mandates or regulators constrain where data may sit, that constraint drives the architecture. We document it so you can show it.

What do you not do?

We do not sell certification, we do not provide legal advice on regulatory interpretation, and we do not run general IT helpdesk. Where you need those, we will say so and work alongside whoever does.

Get in touch

Start with the assessment

No cost, no obligation, and the findings are yours either way.