Modular Cyber Security

Eleven controls, each closing one gap

Eleven security controls, each sold on its own to close a specific gap. They are managed security services: each one deploys into the environment you already have, run by us, without moving your IT or replacing anything that already works.

The modules

Grouped by the problem each one solves. Everything here is deployed and run by us, reported on, and cancellable on its own without unpicking the others. Two of the eleven are quarterly external and internal penetration testing, which run on a recurring cycle rather than as a single engagement.

On the endpoint

  • Endpoint detection and response SentinelOne

    Behavioural detection and automated response on every managed device, with threat hunting behind it.

  • Application control and ringfencing ThreatLocker

    Only approved software runs, and the approved software is fenced so PowerShell and browsers are held to what they need to reach. Your environment is learned first to keep the disruption down.

  • Threat detection module ThreatLocker

    Detection layered onto the same agent, so policy violations and suspicious behaviour surface without a second product on the device.

Getting in

  • AI email security

    Inline filtering aimed at phishing, impersonation and business email compromise, applied before delivery and without an MX record change.

  • Password management

    A managed vault, so credentials stop living in spreadsheets and browser profiles. Usually the control on this page with the most immediate effect.

Detection and response

  • Extended detection and response Blumira

    Logs from across the environment correlated into detections, with alerts that arrive carrying the context needed to act on them.

  • Dark web monitoring

    Your domains watched for exposed credentials. When something surfaces a ticket is raised and the user is contacted.

Finding what is exposed

  • Vulnerability management

    Hourly scanning of endpoints and servers, prioritised by what is being actively exploited as well as by severity, and tracked to closure.

  • External penetration testing

    Quarterly testing of everything you expose to the internet, scored and reported with remediation advice. Available as a one-off.

  • Internal penetration testing

    Quarterly testing from inside the network, which is the test that shows how far someone gets after the first mistake.

The people

  • Awareness and simulation training

    Quarterly training with continuous phishing simulation, difficulty that adapts per person, and risk scoring you can act on.

Onboarding is quoted per engagement. Some modules require Microsoft licensing you may already hold, and we will tell you which before you buy.

The right number of these is the smallest one

A catalogue is a list of things somebody would like to sell you. The useful version of this conversation starts with what you already have and ends with the shortest list that closes the gap, which is rarely the longest one.

You probably do not need all of it

Most organisations that come to us about security are not starting from nothing. What they have is a gap, and usually they can name it: no visibility, nothing watching after hours, a control an auditor asked for that has no owner.

The unhelpful answer is that closing it means moving your IT to a new provider. It usually does not.

Each of these runs in the environment you already have, alongside whoever manages it. Buy one. Buy four. Replace them later if something better turns up.

How it actually goes

No discovery phase, no transition project. The point of a module is that it is small enough to just start.

  1. Tell us the gap

    Usually one conversation. Often it turns out the gap is narrower than it looked, or that something you already own covers half of it.

  2. Onboard the module

    Agents deployed and policy set to a known baseline. Where a control can block, it observes first, so you see what it would have stopped before it stops anything.

  3. Run and report

    It is managed from then on, and it reports on a schedule. If a module turns out to be the wrong answer, it stops on its own.

Start with the gap

The fastest version of this is a conversation about what you already have. If you would rather start with a measurement, an Essential Eight assessment is sold on its own.

  1. Name what worries you

    Not a product. The thing that would be bad. What we quote follows from that, and not from a tier.

  2. We tell you what you already cover

    Including where an existing licence covers something on this page, which happens more often than it should.

  3. Start with the shortest list

    One module is a complete engagement. So is deciding you need none of them yet.

What a module is, and what it is not

A module is a control, deployed and managed and reported on. It is not a security programme, and buying four of them does not add up to one.

What it does

  • Deployed and managed by us

    Configured properly, tuned as it settles, and maintained. Not handed over with a licence key and a link to the vendor documentation.

  • Works alongside your current provider

    These run in the environment you have. Your current provider stays, and no contract has to end for one of these to start. Using Ericom as a managed security service provider for one control does not commit you to moving anything else.

  • Reported

    Each module reports on itself, on a schedule, in something you can forward to someone who asked.

  • Cancellable on its own

    Modules are separate. Stopping one does not unpick the others, and none of them is a hostage for the rest.

What it does not do

  • Not incident response

    These detect and escalate. A confirmed compromise needing OAIC notification, insurance activation or forensic work is a separate engagement, and it is the wrong moment to be negotiating one.

  • Not a 24/7 staffed response

    Detection and automated response run continuously. People do not, unless that is specifically what you have bought.

  • Not a maturity position

    Individual controls do not produce a maturity level. If somebody has asked you to evidence the Essential Eight, an assessment comes first, and it will probably tell you to buy fewer of these than you expected.

  • Not tenant configuration

    Conditional access, multi-factor policy, Microsoft email filtering and Microsoft patching are not modules, because they only mean anything if we run the tenant. They live in Managed IT.

  • Not a replacement for what you have

    If something already works we will say so and not quote it. We would rather sell three modules that close real gaps than eleven that overlap what you own.

“Some job seekers send CVs through to our emails instead of our secured portal, and we’ve always needed to work around that. Now, our staff are educated on best practices, which has improved our overall security measures.”

Sarah Lenton
Senior Business Manager, Bluefin Resources
Read the case studies

When you should not buy modules

Three situations where these are the wrong shape, and what to look at instead.

  • You need to evidence the Essential Eight

    If an insurer, a board or a customer has asked where you sit against the Essential Eight, start with an assessment. Buying controls first risks buying the wrong ones, and still leaves you without a position to report.

  • You are counting more than four gaps

    Past a certain point modules cost more than the managed service that includes them, and they still leave the tenant controls unowned. That is the moment to look at Managed IT instead of a longer quote.

  • IT has no internal owner

    Modules assume someone is running the environment they land in. If that person does not exist, controls will drift and the reporting will go unread. Managed IT exists for exactly this.

Name the gap

Tell us the control an auditor asked for, the hours when nothing is watching, or the part of the environment you cannot see. One conversation, no discovery phase. We will tell you what you already cover, what is genuinely missing, and whether a module or an assessment is the better first move.

Talk to our security team