Cybersecurity & Secure Access
Endpoint Protection
Detection and response on workstations and servers, with enough visibility to say what a device actually did rather than only that something was blocked.
Signature-based antivirus stops known malware and is close to useless against anything tailored or living off legitimate tools. That is why endpoint work has moved toward detection and response: recording what processes ran, what they touched and what they connected to, so behaviour that is individually unremarkable can be recognised as a pattern.
The practical difference shows up during an incident. A blocking-only product tells you it stopped something on one machine. A recording product tells you when it arrived, which account ran it, what it wrote and which other machines it reached — which is the difference between cleaning one laptop and knowing whether the problem is contained.
Coverage is the limiting factor. Servers, contractor laptops and unmanaged devices are routinely outside the estate the tooling can see, and an incident tends to start on exactly one of those.
What this covers
Detection and response
Process, file and network telemetry retained long enough to reconstruct what happened, not only to block what was recognised.
Ransomware containment
Behavioural detection of mass encryption with automatic isolation of the affected host from the network.
Application and device control
Restricting what may execute and what removable media may be used, which removes a large share of routine infections.
Patch and configuration visibility
Reporting on missing patches and weak configuration, so exposure is a tracked number rather than an assumption.
Server and workload coverage
Protection extended to servers and virtual workloads, which is where the valuable data actually is.
What we will ask you
These are the questions that decide the specification. Having the answers ready is what turns a first conversation into a real quotation.
- 01
What is not covered?
Contractor machines, unmanaged devices and legacy servers. Incidents start where visibility ends.
- 02
Who responds to a detection?
A tool that alerts into an unwatched console is expensive logging. The response path has to exist before the tool does.
- 03
How long is telemetry kept?
Intrusions are often found weeks after they start. Short retention means the beginning is gone.
