Frequently Asked Questions

Common questions about onboarding, services, monitoring, compliance, and how we work with your team.

Initial onboarding typically takes 4–8 weeks depending on your environment complexity, engagement scope, and team readiness. We start with assessment and planning (week 1), then deploy monitoring or infrastructure changes (weeks 2–4), and finalize testing and documentation (weeks 5–8). We run in parallel when possible to accelerate time-to-value.

Yes, for clients with Managed Detection & Response or higher tiers. Our SOC monitors 24/7/365 with analyst coverage, with escalation to senior responders based on severity. For Foundation tier (CSPM and governance only), we operate during business hours with on-call coverage for critical alerts.

For Critical tier: under 15 minutes. For Assured tier: under 30 minutes. For Foundation tier: under 1 hour. MTTR is measured from confirmed incident report to first responder engagement. Actual containment time varies by incident scope, but we target <2 hours for most critical threats.

Yes. We support AWS, Azure, Google Cloud, and hybrid environments. Cloud Security Posture Management covers configuration auditing and compliance verification. Resilient Managed Infrastructure extends to cloud workloads for backup, segmentation, and hardening. We integrate with your existing cloud governance and DevOps workflows.

We recommend a 3-2-1 approach: 3 copies of data, 2 different media types, 1 offsite. For ransomware resilience, we design immutable backups (air-gapped or cloud-native), segment backups from production networks, and test recovery quarterly. Recovery time objectives (RTOs) vary by system, typically 2–4 hours for critical applications.

Yes. We are SOC 2 Type II certified, maintain ISO 27001 certification, and design our processes to support client HIPAA and PCI-DSS compliance. Our governance and readiness service explicitly helps clients achieve and maintain compliance certifications. We provide audit evidence and control documentation.

Pricing varies by engagement tier and scope. Foundation tier is typically monthly flat fee. Assured and Critical tiers include service bundles with pricing based on environment size and coverage needs. We customize pricing to match your asset count, team size, and geographic footprint. Contact us for a custom quote.

Absolutely. Engagements are flexible—you can expand services, upgrade tiers, or add services seasonally. We review quarterly to assess coverage and outcomes, and we adjust based on changing risks, growth, or regulatory changes. No long-term lock-in; annual agreements with quarter-by-quarter review.

Yes. We monitor and manage hybrid setups (on-premise + cloud), multi-cloud deployments, and complex OT/IT environments. Our CSPM covers all major cloud providers simultaneously. Our infrastructure management extends across your entire footprint as long as we have appropriate access and network connectivity.

We have read access to logs, configurations, and telemetry needed for monitoring and assessment. We do not access application data or customer personal data unless specifically needed for incident investigation. All data is encrypted in transit (TLS 1.2+) and at rest. We maintain SOC 2 controls, limit access to authorized personnel, and provide audit evidence of data handling.

Yes. We integrate with existing SIEMs, EDR platforms, cloud tools, and ticketing systems. We don't require you to rip-and-replace your current stack. We augment and orchestrate, connecting tools where needed and centralizing reporting. We work with what you have and recommend upgrades only when strategic.

We recommend quarterly testing minimum. Backup & Recovery service includes quarterly validation testing. Testing validates RTO/RPO assumptions, updates runbooks with lessons learned, and builds team confidence. Annual testing is bare minimum for compliance; quarterly is best practice for mission-critical systems.

We document it, classify by severity, and provide remediation guidance with timelines. Critical findings get immediate escalation and recommended containment actions. We work with your team to prioritize and track fixes, provide re-validation testing, and report closure. All findings are tracked in our platform with audit evidence.

Call +18568649833 immediately, press option 1 for incident escalation. Our on-call responder will engage within 10 minutes for Critical incidents, 30 minutes for Assured, 1 hour for Foundation. Do NOT wait for business hours if operations are at risk. Email follow-up can occur after, but phone escalation is the fastest path for active incidents.

Didn't find your answer?

Our team is ready to answer any questions about your specific situation or security needs.

Contact Us