Managed Security Services Provider
Nine platforms.
One accountable
security team.
Most organisations do not have a tooling problem. They have an ownership problem — consoles nobody watches, alerts nobody triages, and a patch cycle that slipped two quarters ago. Iron Grid runs the whole stack as a single service, with named engineers and a SOC that is staffed at three in the morning.
Microsoft CSP / Huntress / Carbon Black / Wazuh / WatchGate.io / Meraki
Alerts route to an analyst, not to your inbox. Overnight and weekend coverage is people on shift with documented handover — not an on-call phone that escalates to you.
Huntress, Carbon Black, and Wazuh see different things and fail in different directions. That redundancy is the design, not an accident of procurement.
Security and IT operations under one contract, one ticket queue, one SLA. No triangulating between the network vendor and the endpoint vendor at midnight.
A monthly written report with response times, coverage gaps by hostname, and what we recommended and you declined. Including the months we missed a target.
Every platform, named.
Every one of them, ours to run.
We publish the whole toolchain because the alternative — "proprietary next-generation platform" — is usually a reseller agreement someone would rather you did not price-check.
Microsoft CSP
Cloud licensing & tenant securityMicrosoft 365 and Azure licensing bought through Iron Grid as your Cloud Solution Provider, with the security baseline configured, monitored, and reported on rather than left at defaults.
Huntress
Managed detection & responsePersistent-foothold hunting and identity threat detection backed by a human analyst team — the layer that catches what silently survived the initial compromise.
Carbon Black
Endpoint protection & EDRNext-generation antivirus with continuous endpoint recording, so an investigation can replay exactly what a process did instead of guessing from what survived.
Wazuh
SIEM, log retention & file integrityThe open-source SIEM where every other layer's telemetry lands — correlated, retained for the period your auditor asks about, and mapped to MITRE ATT&CK.
WatchGate.io
Perimeter & edge securityManaged firewall, secure remote access, and egress inspection at every site boundary — with rule changes handled through documented change control rather than ad hoc console edits.
Meraki
Cloud-managed network infrastructureCloud-managed switching, wireless, SD-WAN, and security appliances — one dashboard across every site, monitored by the same team that watches the endpoints hanging off it.
Kaseya
RMM, patching & automationRemote monitoring and management for the unglamorous work that prevents most incidents: asset inventory, patch deployment, and configuration drift correction.
Autotask
PSA, ticketing & SLA trackingThe professional services automation platform behind every ticket, escalation, and SLA clock — so response time is a measured number rather than an impression.
IT Glue
Documentation & credential vaultingStructured, versioned documentation of your environment with audited credential storage — the difference between a fast recovery and a scavenger hunt at 3am.
Six layers, and what fails through each one.
Every control has a failure mode. The useful question is not whether a layer can be bypassed — it can — but what catches the attacker on the way past it.
Firewall policy under change control, segmentation that keeps a compromised camera away from a domain controller, and egress inspection — because outbound command-and-control is often the first honest signal you get.
Conditional Access, MFA enforcement, privileged role review, and sign-in monitoring. Identity is the boundary most incidents actually cross, and credentials do not trigger antivirus.
Next-generation antivirus and managed Defender policy across the fleet, tuned per role rather than one permissive ruleset stretched across servers and laptops alike.
Continuous process recording, persistence-foothold hunting, and human analysts working a queue. Prevention is the layer that fails quietly; detection is what makes the failure visible.
One searchable dataset across endpoint, identity, network, and cloud, retained twelve months hot. Without retention, an incident discovered in month four is an incident you cannot scope.
Patching, asset reconciliation, ticketing with SLA clocks, and documentation good enough to recover from. Detection tells you something is wrong; documentation decides how long it stays wrong.
Five services.
One contract.
Take the whole thing or take the piece you are missing. Most clients start with security operations and pull the rest across at their next renewal — which is a reasonable way to do it, and we will say so rather than push a bundle.
Plans & pricingSecurity Operations
24/7 monitoring, triage, and containment across endpoint, identity, and network telemetry by a staffed analyst team.
Network Security
Managed firewall, segmentation, secure remote access, and cloud-managed switching and wireless across every site.
Microsoft Cloud
Microsoft 365 and Azure licensing as your CSP, with tenant hardening, Conditional Access, and identity monitoring.
IT Operations
Patching, monitoring, ticketing, and documentation — the operational hygiene that prevents most incidents outright.
Compliance & Risk
Continuous control evidence, log retention, and audit-ready reporting for CMMC, HIPAA, PCI DSS, and SOC 2.
Incident Response
Retained IR for managed clients, and emergency engagements for organisations we do not currently monitor.
Regulated, resource-constrained,
and out of patience with surprises.
Manufacturing & defence supply chain
OT segmentation, CMMC readiness, and a patch cycle that respects production windows instead of ignoring them.
Healthcare & clinical services
PHI-bearing systems, medical devices that cannot take an agent, and audit evidence that holds up under examination.
Financial services & insurance
Segmentation, retention, and vendor due-diligence answers that survive a client's security questionnaire.
Professional services firms
Microsoft-heavy environments, mobile staff, and client data whose exposure is an existential problem rather than a fine.
Multi-site retail & hospitality
Payment network isolation, guest wireless that cannot reach anything, and sites without local IT staff.
Not on this list?
Tell us the environment and the constraint. If we are the wrong fit we will say so on the first call, not the fourth.
Thirty days from signature to steady state.
Nothing here requires you to rip anything out on day one. Existing tooling stays until its replacement is verified working — a coverage gap during migration is exactly the window an attacker wants.
Discovery
We inventory what exists, not what the documentation claims exists. Asset discovery, identity review, firewall ruleset export, and an honest map of the gaps.
Deploy & baseline
Agents rolled out in rings, log sources connected, tenant baseline applied. We measure normal before we start alerting on abnormal.
Tune & document
Alert thresholds tuned against your actual traffic, escalation paths agreed by name, runbooks written. A noisy SOC gets ignored, so tuning is not optional.
Steady state
Monitoring live, monthly reporting begins, quarterly review scheduled. You get the coverage gap list by hostname from the first report onward.
The provider you can audit.
A security provider holds privileged access to everything you own. That is a serious thing to hand over, and it deserves more scrutiny than a capability matrix and a reference call.
So we publish the toolchain, log every credential retrieval and hand you the audit trail on request, and hand back your full documentation set if you leave — whether the parting is amicable or not.
Our security postureNamed engineers
You know who owns your account and who answers a severity-one at three in the morning. Escalation paths list people, not queues.
MITRE ATT&CK mapped detections
Coverage reported as a technique matrix with the gaps visible, rather than a vendor score with no arithmetic behind it.
Auditable access
Every credential retrieval and every session against your environment is logged, attributed, and available to you on request.
Portable documentation
Runbooks, diagrams, configurations, and credentials exported in full at no charge if you leave. No hostage-taking.