Modular Cyber Security

Modular security

Eleven security solutions sold on their own, to close a specific gap. Each one deploys into the environment you already have, managed by us, without moving your IT or replacing anything that already works.

The modules

Grouped by the problem they solve rather than by vendor. Everything here is deployed and managed by us, reported on, and cancellable on its own without unpicking the others.

On the endpoint

  • Endpoint detection and response SentinelOne

    Behavioural detection and automated response on every managed device, with threat hunting behind it.

  • Application whitelisting and ringfencing ThreatLocker

    Only approved software runs, and the approved software is fenced so PowerShell and browsers cannot be turned against you. Your environment is learned first to keep the disruption down.

  • Threat detection module ThreatLocker

    Detection layered onto the same agent, so policy violations and suspicious behaviour surface without a second product on the device.

Getting in

  • AI email security

    Inline filtering that blocks phishing, impersonation and business email compromise before delivery. No MX record change.

  • Password management

    A managed vault, so credentials stop living in spreadsheets and browser profiles. The cheapest control on this page and usually the one with the most immediate effect.

Detection and response

  • Extended detection and response Blumira

    Logs from across the environment correlated into detections, with alerts that arrive as something actionable rather than as noise.

  • Dark web monitoring

    Your domains watched for exposed credentials. When something surfaces a ticket is raised and the user is contacted.

Finding what is exposed

  • Vulnerability management

    Hourly scanning of endpoints and servers, prioritised by what is actually being exploited rather than by severity alone, and tracked to closure.

  • External penetration testing

    Quarterly testing of everything you expose to the internet, scored and reported with remediation advice. Available as a one-off.

  • Internal penetration testing

    Quarterly testing from inside the network, which is the test that shows how far someone gets after the first mistake.

The people

  • Awareness and simulation training

    Quarterly modules with continuous phishing simulation, difficulty that adapts per person, and risk scoring you can act on.

Onboarding is quoted per engagement. Some modules require Microsoft licensing you may already hold, and we will tell you which before you buy rather than after.

The right number of these is the smallest one

A catalogue is a list of things somebody would like to sell you. The useful version of this conversation starts with what you already have and ends with the shortest list that closes the gap, which is rarely the longest one.

You probably do not need all of it

Most organisations that come to us about security are not starting from nothing. They have an antivirus product, they have backups of some kind, somebody turned on multi-factor authentication two years ago. What they have is a gap, and usually they can name it: no visibility, nobody watching after hours, a control an auditor asked for that nobody owns.

The unhelpful answer is that closing it means moving your IT to a new provider. It usually does not.

Each of these runs in the environment you already have, alongside whoever manages it. Buy one. Buy four. Replace them later if something better turns up.

How it actually goes

No discovery phase, no transition project. The point of a module is that it is small enough to just start.

  1. Tell us the gap

    Usually one conversation. Often it turns out the gap is narrower than it looked, or that something you already own covers half of it.

  2. Onboard the module

    Agents deployed, policy set to a known baseline, and where the module learns your environment first, that runs before enforcement does.

  3. Run and report

    It is managed from then on, and it reports on a schedule. If a module turns out to be the wrong answer, it stops on its own.

Start with the gap, not the catalogue

The fastest version of this is a conversation about what you already have. If you would rather start with a measurement, an Essential Eight assessment is sold on its own.

  1. Name what worries you

    Not a product. The thing that would be bad. What we quote follows from that rather than from a tier.

  2. We tell you what you already cover

    Including where an existing licence covers something on this page, which happens more often than it should.

  3. Start with the shortest list

    One module is a perfectly good engagement. So is deciding you need none of them yet.

What a module is, and what it is not

A module is a control, deployed and managed and reported on. It is not a security programme, and buying four of them does not add up to one.

What it does

  • Deployed and managed by us

    Configured properly, tuned as it settles, and maintained. Not handed over with a licence key and a link to the vendor documentation.

  • Works alongside your current provider

    These run in the environment you have. Nobody has to be replaced and no contract has to end for one of these to start.

  • Reported

    Each module reports on itself, on a schedule, in something you can forward to someone who asked.

  • Cancellable on its own

    Modules are separate. Stopping one does not unpick the others, and none of them is a hostage for the rest.

What it does not do

  • Not incident response

    These detect and escalate. A confirmed compromise needing OAIC notification, insurance activation or forensic work is a separate engagement, and it is the wrong moment to be negotiating one.

  • Not 24x7 hands-on

    Detection and automated response run continuously. People do not, unless that is specifically what you have bought.

  • Not a compliance position

    Individual controls do not produce a maturity level. If somebody has asked you to evidence a framework, an assessment comes first and it will probably tell you to buy fewer of these than you expected.

  • Not tenant configuration

    Conditional access, multi-factor policy, Microsoft email filtering and Microsoft patching are not modules, because they only mean anything if we manage the tenant. They live in the managed service.

  • Not a replacement for what you have

    If something already works we will say so and not quote it. We would rather sell three modules that close real gaps than eleven that overlap what you own.

When you should not buy modules

Three situations where these are the wrong shape, and what to look at instead.

  • You need to evidence a framework

    If an insurer, a board or a customer has asked where you sit against the Essential Eight, start with an assessment. Buying controls first means buying the wrong ones and still not having a position to report.

  • You are counting more than four gaps

    Past a certain point modules cost more than the managed service that includes them, and they still leave the tenant controls unowned. That is the moment to look at Cyber365 rather than at a longer quote.

  • Nobody owns IT internally

    Modules assume someone is running the environment they land in. If that person does not exist, controls will drift and the reporting will go unread. The managed service exists for exactly this.

Tell us the gap

One conversation, no discovery phase. We will tell you what you already cover, what is genuinely missing, and whether a module or an assessment is the better first move.

Talk to our security team