Managed Security Service
Managed Security Services
Managed security means someone else runs the tools that defend you. APT is vendor-neutral, so we recommend what fits rather than what we are quota-bound to sell, and we can be the reseller, the managed partner, or neither if you would rather own it.
Most managed security is sold by companies with a quota on one vendor’s product. The recommendation arrives before the assessment does.
We carry partnerships with several vendors specifically so the answer can depend on your situation. Sometimes that means the cheaper product. Sometimes it means telling you the tool you already own is fine and the problem is that nobody is watching it.
Three ways to buy
We resell and manage. One relationship, one invoice, we own the outcome.
You buy, we manage. You hold the vendor relationship and the licenses. We run it. Useful when procurement has opinions or you already have pricing.
We set it up and hand you the keys. Deployment, tuning, documentation, then it is yours. No lock-in, and we will say when this is the right answer.
What we cover
Detection and response
Monitoring that produces something a person acts on. The failure mode of MDR is volume: alerts nobody triages, tuned by nobody, until the console is ignored. We tune first and alert second.
Still where most intrusions start. Filtering, authentication (SPF, DKIM, DMARC actually enforcing rather than set to none), and the impersonation attempts that get past filters because they contain no attachment and no link.
Cloud
Posture management across AWS, Azure and Google Cloud. Identity, exposure, drift from whatever you agreed the baseline was, and the account someone opened on a personal card.
Network
Firewalls, segmentation, and remote access. Mostly this is about the difference between a rule set that was correct when it was written and one that is correct now.
Endpoint
EDR deployment and management, with attention to the machines that are not in the inventory. Coverage numbers are usually reported against known assets, which is not the same as against all assets.
What you get
A named person who knows your environment. Not a ticket queue. The failure mode of managed security is that the people watching your alerts have never seen your network and cannot tell a scheduled job from an intrusion.
Tuning, written down. Every suppression and every threshold change is recorded with the reason. A year later, when an alert did not fire, the question is always why, and “it was tuned out at some point” is not an answer.
Monthly reporting aimed at a decision. What fired, what was noise, what changed, and what we think you should do next. If a month produced nothing worth acting on, the report says that rather than padding.
Your configuration, exportable. Rules, policies and documentation belong to you. That matters most on the day you decide to take it in-house or move to someone else, which is exactly when a lock-in vendor becomes unhelpful.
What this gives an assessor
Most frameworks do not ask whether you bought a tool. They ask whether you can show it worked.
NIST SP 800-171 has families for audit and accountability, incident response, and system monitoring. SOC 2 asks for evidence of monitoring and a response process that was actually followed. Cyber insurance renewals increasingly ask for EDR coverage and MFA enforcement as a condition rather than a discount.
Managed security produces that evidence as a side effect of doing the work: coverage reports, alert history, tuning records, and incident timelines. If you are working toward CMMC or you are a defense contractor handling CUI, that evidence is the thing an assessor asks for and the thing most organizations scramble to reconstruct afterwards.
Questions worth asking any managed provider
Including us. If the answers are unsatisfying, that is useful information.
- Which vendors do you have a quota on, and does that change what you recommend?
- Who tunes the alerts, and do I get to see what was suppressed and why?
- If I leave, what do I take with me and what stops working?
- What happens on a Saturday, and how is that different from a Tuesday?
- When you find something, do I get an alert or an explanation?
The last one separates a monitoring service from a security partner. An alert tells you a thing happened. An explanation tells you whether it matters and what to do, and it is the part that requires someone who understands your business rather than your log format.
Being straight about this one
Managed security is delivered today through vendor partnerships and our own people. The agentic engineering platform that will let us manage environments at larger scale is in development and is not doing this work yet.
We would rather say that than imply a capability we are still building.
The failure mode of managed detection is volume. Tuning comes before alerting, so what reaches a person is worth their attention.
