MDR — Managed Detection & Response
24/7 detection, investigation and response across endpoint, identity and cloud. Built on SentinelOne Singularity telemetry, extended with our own detection logic, runbooks and DFIR-grade triage.
- Endpoint, cloud workload and identity telemetry in one pane
- Human-led investigation — no auto-close queues
- Containment actions pre-authorised under written runbooks
- Escalation path lands with the same team that handles IR
CTEM — Continuous Threat Exposure Management
Scope, discover, prioritise, validate, mobilise — the Gartner CTEM loop, run as a managed programme. External attack surface, internal exposures and identity misconfigurations, continuously measured and continuously closed.
- External attack-surface enumeration and validation
- Identity exposure analysis — IdP, tenancy and privileged paths
- Prioritisation by exploitability and business criticality, not CVSS alone
- Mobilisation reporting aligned to board-level risk language
Identity Protection
Identity is the modern perimeter. Token theft, OAuth abuse, MFA fatigue and IdP misconfigurations are the initial-access vectors we see most often. We instrument and defend them as a first-class discipline.
- Entra ID & Okta posture review, tuned detections and drift alerts
- Session-token and refresh-token theft monitoring
- Privileged-path analysis and standing-access reduction
- Conditional access, PAM and break-glass policy review
Dark-Web & Exposure Monitoring
Leaked credentials, broker listings, initial-access-broker chatter, ransomware leak-site naming — monitored, triaged and actioned. If your brand, staff or supply-chain is being staged for sale, you hear it from us first.
- Credential and session-cookie leak monitoring across criminal forums
- Leak-site and data-brokerage tracking for your brand and third parties
- Executive and VIP exposure monitoring
- Intelligence routed straight into IR runbooks, not a monthly PDF