Co-managed security

The security layer, without taking over your IT.

You have an IT person, or a small internal team, and they are good. What they do not have is somebody watching security alerts at three in the morning, and they should not have to. We run the security stack alongside them, and they carry on doing what they already do well.

Talk to us 029 2111 1202

24/7security operations centre reading the alerts

Your teamkeeps the helpdesk and the relationships

Same stackas our Secure level, without the support layer

Start here

What is co-managed security?

An arrangement where an external security provider runs the security tooling and monitoring, and your own IT people keep everything else. You are not outsourcing IT. You are adding the one part that a single internal person genuinely cannot cover, which is somebody awake and watching when they are not.

The thing an internal IT person cannot do, however good they are, is be on duty continuously. Attacks do not respect working hours. A compromised account at two in the morning gets six hours of quiet before anybody opens a laptop, and six hours is a long time.

It is also not reasonable to expect one person to be the helpdesk, the projects, the strategy, the supplier management and the security operations centre.

The other half of it is tooling. Endpoint detection and response, email security that sits inside Microsoft 365, DNS and browser protection, vulnerability management: buying those individually at the scale of one business is expensive, and running them properly is a specialism rather than an afternoon. We already run them across a hundred businesses, so you get the tooling and the people watching it without either being your problem to build.

The important part

Who does what?

This is the question that decides whether co-managed works, and the honest answer is that the line moves depending on what your team already covers. This is the usual shape of it.

What we run

The security layer, and the watching.

  • Bitdefender endpoint protection and Advanced Threat Security
  • Managed detection and response, with a security operations centre reading alerts around the clock
  • Check Point Advanced email security, inside Microsoft 365
  • DefensX DNS and browser protection
  • Vulnerability scanning and management
  • DMARC domain protection
  • Security awareness training and simulated phishing

What stays yours

Everything you already do.

  • The helpdesk and day to day support
  • Your users, and knowing what they actually need
  • Projects, changes and the roadmap
  • Your line manager relationships and your budget
  • The decisions. We escalate and advise, you choose
  • Anything else your team is already covering well

Worth saying out loud

If your team already runs some of this, we are not going to charge you to duplicate it. Plenty of internal teams have endpoint protection sorted and want the monitoring and the email layer only. Working out what you genuinely need is the first conversation, and it is a conversation rather than a package.

The elephant in the room

We are not after your IT person’s job

If you are the internal IT person reading this, you already know how this normally goes. A managed provider gets a foot in the door on something narrow, spends a year finding fault with how things are run, and eventually the conversation with your director is about whether they need you at all.

That is not the arrangement, and it would be a poor business model anyway. Co-managed clients stay for years precisely because their internal person makes the relationship work.

In practice we usually make the internal person’s life better, because the tickets they hate are the security alerts they cannot interpret and the vulnerability reports nobody has time to work through. Those become ours. What they keep is the part they are actually good at, which is knowing the business and the people in it, and we are not going to be better at that than somebody who sits there every day.

It also works the other way round. Your IT person gets somebody to think out loud with, a second opinion on a decision at four in the afternoon, and cover when they are on holiday or off sick, which for a team of one is usually the real problem.

You should be able to go away for a fortnight without the business being less secure than it was when you left.

Talk to us

Tell us what your team already covers

How many people, what your internal team looks like, and what you are already running. We will tell you what is genuinely missing, what you should keep doing yourselves, and where the line would sensibly fall.

Why there is no price on this page

How much does co-managed security cost?

We publish our support prices in full, so it is worth explaining why this one is different. Co-managed is the only thing we sell where the scope genuinely changes with every customer, because it is defined by what your team already does rather than by what we offer.

Two businesses of the same size can need completely different arrangements. One has an IT manager with endpoint protection and patching already handled properly, and wants monitoring and email security only. The other has a capable generalist who has never had the budget for security tooling and needs all of it. Putting a single per user figure against both would overcharge one and underdeliver for the other.

So it starts with a conversation about what you already have, and the number follows from that. What we can promise is that it is a fixed monthly fee once agreed, with every line itemised, and no hourly billing hiding in it.

Our published rate card is on the pricing page. This one genuinely needs the conversation first, which is not the same as being cagey about it.

See what we publish for full support

Questions

The things people ask first

Will you try to take over our IT support?

No. Co-managed security is the security layer without the helpdesk underneath it, and that is deliberate. Your team keeps the users, the projects and the day to day. If at some point you wanted us to take on more, that would be a conversation you started rather than one we engineered.

What if our internal team already runs some of this?

Then we do not charge you to duplicate it. The first conversation is about what you already have and what is genuinely missing. Plenty of co-managed arrangements are monitoring and email security only, because the rest was already handled.

Who does our IT person deal with day to day?

Us directly. There are four of us, so it is the same names every time and not a queue. That matters more in a co-managed arrangement than in a normal support one, because your internal person needs somebody they can ring and think out loud with rather than a ticket reference.

What happens when something is detected?

The security operations centre picks it up around the clock and it comes to us. What happens next is agreed in advance with your team: what we act on immediately without asking, what we ring you about, and what waits until the morning. That is worth deciding while everything is calm rather than at two in the morning.

Do we need to change the tools we already use?

Some of it, usually. The security stack we run is the one we know inside out across every client, and monitoring tools we do not run properly would be worse than useless. What we would not do is force a change to something that is working and outside the security layer, because that is your team’s call.

Is this only for businesses of a certain size?

It suits businesses that have reached the point of employing their own IT person, which in our experience starts somewhere around thirty people and is common by sixty. Below that there usually is not an internal team to co-manage with, and full support is the simpler answer.

Next step

Bring your IT person to the conversation

Genuinely. This works when the person who runs your IT is in the room, because they know what is actually covered and what keeps them awake. Tell us what you have and we will tell you where the gap is.

IT support and cyber security across Wales and beyond

Based in Cardiff, working across Wales and the West.