Home/How we work
Onboarding
Seamless onboarding, immediate protection
A structured, low-friction pathway to total cyber resilience — designed so that switching provider costs you no downtime and no coverage gap.
The pathway
Four to six weeks, end to end
Assessment takes one to two weeks. Proposal and approval, one. Deployment, two to three depending on estate size. Emergency engagements compress this substantially.
Initial Risk & Environment Assessment
A comprehensive review of your existing infrastructure, active contracts and current security posture to identify immediate vulnerabilities and coverage gaps.
- Asset and identity inventory
- Existing contract and licence review
- External attack-surface scan
- Gap analysis against your obligations
- Findings session with prioritised risks
Tailored Architecture & Proposal
Our engineering team designs a custom, budget-aligned defence roadmap, scoping precise services without forcing unnecessary bloat or redundant toolsets.
- Workload tiering and RTO/RPO targets
- Control design mapped to findings
- Phased cost model across agreed milestones
- RACI between your team and ours
- Written proposal with no bundled surprises
Frictionless Onboarding & Migration
A zero-downtime deployment, managing all software configurations, policy setups and contract takeovers with complete technical precision.
- Pilot ring before fleet-wide rollout
- Policy and exclusion tuning per application
- Contract and licence takeover
- Runbook authoring and first restore test
- Handover briefing for your team
Continuous Monitoring & Advisory
Once live, your dedicated cyber analysts provide proactive threat hunting, continuous system updates and regular executive intelligence briefings.
- Acronis MDR/XDR monitoring with defined escalation
- Monthly protection and patch compliance report
- Quarterly posture review and scope adjustment
- Threat advisories relevant to your sector
- Annual tested recovery exercise
Service levels
What “we will respond” actually means
| Priority | Definition | Acknowledgement | Response | Reporting |
|---|---|---|---|---|
| P1 — Critical | Active compromise, ransomware, data exfiltration, total outage | 15 minutes | Continuous until contained | Executive brief within 24 hours |
| P2 — High | Confirmed malware on an endpoint, targeted phishing, failed backup on Tier 0 | 1 hour | Same business day | Written summary within 3 days |
| P3 — Medium | Policy violation, single-user issue, non-critical alert triage | 4 business hours | Next business day | In the monthly report |
| P4 — Low | Requests, reporting queries, scheduled changes | 1 business day | Agreed change window | In the monthly report |
Indicative targets. Final SLAs are contracted per engagement and vary with the service tier you select.
Questions we get asked
Before you commit
How long does onboarding actually take?
For a typical estate of 50 to 250 endpoints, assessment takes one to two weeks, proposal one week, and deployment two to four weeks depending on maintenance windows. Protection on critical assets usually goes live in the first week of deployment rather than at the end.
We are mid-contract with another provider. Can you still take over?
Yes. We assess in parallel, agree a takeover date at your contract boundary, and match or beat your existing terms. There are no hidden takeover fees. Where your incumbent holds licences we can usually transfer rather than repurchase them.
Do you replace our IT provider?
Not unless you want us to. The co-managed model is the most common: your IT team or provider keeps operations and first-line support, we own security tooling, detection, response and advisory. The split is written down before we start.
What happens at 2am when something breaks?
Detection and first response run through Acronis MDR, which monitors your estate around the clock and can contain a threat the moment it is detected. Our Solutions Specialists then take over with full context — not an anonymous ticket queue. For declared incidents we run the containment with your team rather than emailing instructions.
Will you sign our client’s security questionnaire?
We complete supplier questionnaires and provide the control evidence behind our answers. Where a client or regulator asks for something we do not do, we say so rather than answering optimistically.
Where is our data stored?
Storage region is chosen deliberately per engagement. Where contracts, client mandates or regulators constrain where data may sit, that constraint drives the architecture. We document it so you can show it.
What do you not do?
We do not sell certification, we do not provide legal advice on regulatory interpretation, and we do not run general IT helpdesk. Where you need those, we will say so and work alongside whoever does.
Get in touch
Start with the assessment
No cost, no obligation, and the findings are yours either way.