Request a demo
HomeCyber Guard
Detection & response ยท managed

The night shift you do not have to hire.

Most breaches begin outside business hours because that is when nobody is looking. Cyber Guard puts named analysts on your baseline continuously, so a deviation at 03:00 gets the same judgement as one at 11:00.

24/7Cover
<15 minEscalation SLA
3Tiers of review
What you are buying

Judgement, not another dashboard licence.

The model does the noticing. Analysts do the deciding, which is the part that cannot be automated honestly.

Named analysts

You know who is on your account. Handover notes are written between shifts, not generated.

Pre-authorised action

Containment steps you have approved in advance are taken immediately, not queued for morning.

Written escalations

Every notice arrives with a trace, a timeline and a recommended action.

Out-of-hours priority

Weekends and holidays are staffed at the same level as a Tuesday.

Escalation policy

Only what needs a decision from you gets one.

Three tiers, agreed before go-live and reviewed quarterly. You decide what is worth waking up for.

  • Tier one, handledKnown-benign deviations closed by an analyst with a note on the record.
  • Tier two, notifiedActioned under your standing authorisation, then reported the same shift.
  • Tier three, escalatedCalled through, with the evidence pack already written before the phone rings.
Alerts closed without you91%
Escalations that were real96%
Out-of-hours coverage100%
Median response<15 min
Onboarding

Four weeks to a staffed watch.

Deliberately unhurried, an escalation policy written in week one is a policy nobody trusts.

Week one, baseline

Sensors in, discovery run, model learning. No alerting yet, by design.

Week two, thresholds

Analysts and your team agree what counts as noise in your environment.

Week three, authorisation

Containment permissions are written down, segment by segment.

Week four, live

Full cover begins, with a named analyst and a weekly written review.

Scope

What is covered, what is not.

Stated plainly, because ambiguity here is how managed services disappoint people.

AreaCyber GuardNotes
Network detection & triageContinuous
Containment on your authorityPre-agreed per segment
Forensic investigationIn scope to root cause
Endpoint rebuilds,Handed to your IT team
Legal / regulatory filing,We supply the evidence pack
Staff security training,Available separately
Questions

What teams ask before they switch.

Straight answers, including the ones that make a sale harder.

Does this replace our security team?
No. It removes the parts that need constant attention so your team can work on the things only they can do.
Who has access to our network?
A named analyst group, with access logged and reviewable by you at any time.
What if we disagree with an escalation?
Push back. Disagreements are logged and feed straight into threshold tuning.
Can we start with one segment?
Yes, and most engagements do. Crown jewels first is a sensible way in.
Talk to an analyst

Meet the people who would watch your network.

Not a sales call, a conversation with someone who works the floor.