Security tools raise alerts. Somebody has to read them.
Most small businesses already pay for Microsoft Defender and never switch half of it on. We configure it properly, and then we watch it: during the day through our own Defender Monitoring service, or around the clock through the Barracuda security operations centre. Detection, triage and a phone call at 2am if it matters.
Who this is for
Businesses with remote or hybrid staff, sensitive client data, or an insurer, customer or auditor asking about monitoring and detection. If you have Defender or similar switched on and nobody is watching it outside office hours, you have alarms but no one listening. A five-person office with no remote access may not need the 24/7 tier, and we will say so.
What is included
Defender configured, not just licensed
Defender for Business or the Defender Suite set up the way Microsoft's own baselines recommend: attack surface rules, safe links and attachments, device onboarding, and alerts routed somewhere a human sees them.
Defender Monitoring as a Service
Our engineers monitor the alerts and logs from Microsoft Defender and Microsoft 365 for your tenant, triage the noise, investigate the real ones and escalate to your nominated contacts under a procedure agreed at onboarding. Hours of cover are stated on your quotation.
Barracuda SOC, 24/7
For businesses that need cover overnight and at weekends, monitoring and investigation are delivered through Barracuda Networks' managed security operations centre, which we resell and coordinate. Same escalation to your contacts, any hour.
Pre-authorised response
Some actions are agreed in advance so they happen immediately, such as isolating a device or disabling a compromised account. Anything else waits for your instruction. Nothing happens to your systems that you did not sign off.
The basics, done
Multi-factor authentication everywhere, conditional access, email filtering, SPF, DKIM and DMARC, device encryption, and patching. These come with managed IT support and are the settings Cyber Essentials asks for.
Phishing simulation and training
Staff get realistic test emails and short training when they click. The click rate is reported to you, because people are the layer most attacks actually go through.
What is not included, and why
- Prevention guarantees. Monitoring detects and escalates; it does not stop every attack and no service can promise that every threat will be caught in time. What it does is turn a breach you find out about in three weeks into one you find out about in twenty minutes.
- Forensic investigation and full incident recovery. Escalation and the pre-authorised response actions are included. A full investigation, rebuild or breach notification exercise is quoted as a project at the time, and you will know that before it starts.
- The Microsoft licences. Monitoring depends on Microsoft 365 Business Premium or the Defender Suite for every user and device in scope, shown as a separate line so you can see what the software costs.
What it costs
Defender Monitoring as a Service is £16 per user per month, excluding VAT. Barracuda SOC, for 24/7 cover, is priced per user per month and available on request: get in touch or book a call. The base security controls (MFA, Defender configuration, email security, patching) are included in managed IT support at no extra charge. Initial term and hours of cover are stated on the quotation.
How it starts
- 1Free IT Health CheckA short online check that benchmarks your security and business risk and tells you where you stand.
- 2Discovery callAn engineer, not a salesperson. What you have, what is broken, what it would cost to fix, in writing.
- 3OnboardingEverything moves across on a plan, with no gap in cover and nothing lost.
Questions people ask before signing
What is the difference between Defender Monitoring and the Barracuda SOC?
Defender Monitoring is our own engineers watching your Microsoft Defender and Microsoft 365 alerts during the hours on your quotation. Barracuda SOC is a 24/7 security operations centre run by Barracuda Networks, which we resell and coordinate, for businesses that need someone watching overnight and at weekends. Both escalate to your contacts under the same agreed procedure.
Do we need this if we already have antivirus?
Antivirus stops known malware on a device. It does nothing about a stolen password used to log in from abroad, an inbox rule quietly forwarding invoices, or a device that has been turned off protection. Those show up as alerts in Defender, and an alert nobody reads is the same as no alert.
What licence do we need?
Microsoft 365 Business Premium for every user in scope, or the Microsoft Defender Suite added to another plan. If a licence lapses, the alerts we rely on stop being generated, so keeping licences current is part of the deal.
What happens at 2am on a Wednesday?
With the SOC tier, an analyst sees the alert within minutes, checks whether it is real, and if it is, takes any pre-authorised action (such as disabling the account) and phones your nominated contact. Our engineers pick up recovery in the morning, or sooner if the procedure says so. Our 24/7 SOC guide walks through an illustrative overnight incident.
Does this get us Cyber Essentials?
The controls it depends on are the ones Cyber Essentials asks for, so businesses on this service are most of the way there. Certification itself is a separate, fixed-price piece of work; see the Cyber Essentials page.
Do you do incident response?
Escalation and pre-authorised containment are included. A full investigation, rebuild or regulatory notification is scoped and quoted as a project when it happens, and we tell you that before starting. If you have cyber insurance, we work with the insurer's response team where the policy requires it.