Cybersecurity Services Definitions
Cybersecurity Plans
The following cybersecurity plans are available. Each plan is a combination of services defined in this document.
- SOCWatch YYYY.version
- ProT3ct Core YYYY.version
- ProT3ct Guard YYYY.version
- ProT3ct Max YYYY.version
- ProT3ct 365 YYYY.version
- ProT3ct Site YYYY.version
- ProT3ct Site + XDR YYYY.version
- ProT3ct Server YYYY.version
- ProT3ct Server + XDR YYYY.version
Plan 1 is billed per device. Plans 2, 3, 4, and 5 are billed per user. Plans 6 and 7 are billed per location or per organization. Plans 8 and 9 are billed per server.
Service Definitions
3.1 SOC – Endpoint Detect and Respond (EDR)
Endpoint Detection and Response (EDR) is an enterprise-grade solution that includes next-generation antivirus and behavioral AI to detect and stop known and unknown threats.
The solution integrates with a certified 24x7x365 Security Operations Center (SOC) that continuously monitors endpoints for threats such as ransomware and malware. The SOC provides visibility, analysis, and remediation recommendations in coordination with the T3 Security team.
3. SOC Services
3.2 Left Intentionally Blank
3.3 SOC – Managed Detection and Response
Managed Detection and Respond (MDR) is a service that combines our EDR and the SOC’s cybersecurity experts to perform threat hunting, monitoring, and response. By leveraging the EDRs detection capabilities the SOC will have comprehensive visibility to any security events that occur on your endpoint. With MDR, the SOC can actively respond to threats or security incidents. As required, they will engage with T3 Security team to stop an active threat and to contain and remediate an attack. The SOC will review with T3 Security team relevant recommendations to fortify security protections to augment and fortify cybersecurity protections.
3.4 SOC – Email Security XDR
Extend SOC monitoring to include email security logs. This service include ingestion of these logs and monitoring for suspicious email activity, account takeover, and mass phishing campaigns. Correlation to Endpoint, Server, and Network and Email Protection for Extended Detection and Response allows for complete investigation and resolution of cyber-attacks.
3.5 SOC – Network Security XDR
Extend SOC monitoring to include firewall logs. This service include ingestion of these logs and monitoring for suspicious activity. Suspected threats are correlated for analysis. All identified incidents are triaged, providing T3 with alerts with guided resolution. SOC team is able to automatically respond to network level threats leveraging this server. Correlation to Endpoint, Server, Cloud and Email Protection for Extended Detection and Response allows for complete investigation and resolution of cyber-attacks.
3.6 SOC – Server Security XDR
Extend SOC monitoring to include server. This service includes ingestion of these logs and monitoring for suspicious activity. Suspected threats are correlated for analysis. All identified incidents are triaged, providing T3 with alerts with guided resolution. Correlation to Endpoint, network, cloud services and Email Protection for Extended Detection and Response allows for complete investigation and resolution of cyber-attacks.
3.7 SOC – Cloud XDR
Extend SOC monitoring to include Cloud services such as Microsoft 365 and DUO. This service includes ingestion of these logs and monitoring for suspicious activity. Suspected threats are correlated for analysis. All identified incidents are triaged, providing T3 with alerts with guided resolution. Correlation to Endpoint, network, server and Email Protection for Extended Detection and Response allows for complete investigation and resolution of cyber-attacks.
4. Email Protection Services
4.1 Left Intentionally Blank
4.2 Email Protection – Gateway
Email Protection (EP) for your email (Microsoft 365). We setup the policies detecting and blocking malware, spam filtering, detecting and blocking Business Email Compromise, and suspicious website link blocking. We configure Email Protection for the entire company domain. We require 30-60 days to monitor and fine-tune policies. After review with customer, we apply control policies and help users understand and manage the controls.
4.3 Email Protection – Impersonation Protection
Automatically detect and prevent impersonation, business email compromise, and other targeted attacks. AI engine learns your organization’s unique communication patterns and leverages these patterns to identify anomalies and prevent social-engineering attacks in real time. Stop phishing attacks used to harvest credentials for account takeover. Our AI detects anomalous email behavior and alerts IT, then finds and removes all fraud emails sent from compromised accounts.
4.4 Email Protection – Domain Fraud Prevention
Prevent email domain fraud with DMARC reporting and analysis. This service provides granular visibility and analysis of DMARC reports, protects legitimate email, and prevent spoofing.
4.5 Email Protection – Incident Response
Advanced automated email threat response service designed to safeguard your organization from sophisticated email threats upon post-delivery. Automatically detect, prevent, and remediate malicious emails via integrations into Gateway and Impersonation Protection email services.
5. Zero Trust Framework
5.1 Zero Trust Framework – Endpoint
We provide licensing to implement Zero-Trust policy endpoint including ring-fencing. We setup the Zero-Trust solution for each covered computer. We require 30-45 days for the system to learn normal user behavior and then we apply control policies. When the control policies are active, new program installations will be blocked informing the user and giving them an option to request authorization to install. We respond to user’s request to authorize a new application safely. Our Network Operations Center will live monitor these during Business Hours.
5.2 Zero Trust Framework – Elevation Control (PAM)
Privileged Access Management – provide just in time administration elevation as needed.
5.3 Zero Trust Framework – Storage Control
Define and administer storage controls to allow or restrict usage.
5.5 Zero Trust Framework – Network SASE
We provide licensing for Secure Access Service Edge (SASE). We provide SASE as Protected DNS and additional SASE services. Additional SASE services are: Always on VPN, Zero-Trust LAN, Firewall-as-a-Service, Secure RDP, and Wi-Fi Security. We set up the Zero-Trust solution for each covered computer. We require 30-60 days to set up the system with policies that balance security with normal workflow. When the control policies are active, access to network resources are protected and can quickly isolate a suspected compromised computer. We will authorize changes and/or block suspicious activities based on agreed policies.
5.6 Zero Trust Framework – Protected DNS
This sub-service provides customer with website filtering and malware blocking across the DNS layer.
5.7 Zero Trust Framework – Additional SASE Services
Adding to sub-service 2.11.a, this sub-service provides the customer with Always on VPN, Zero-Trust LAN, Firewall-as-a-Service, Secure RDP, and Wi-Fi Security. These services will provide customer with the complete Zero-Trust Framework for their network.
6. General
6. Left Intentionally Blank
7. General
7. Left Intentionally Blank
8. Secure 365 Services
8.1 Secure 365 – Environment
We continually review best practices and adjust security settings for Microsoft365 administration centers and Azure Active Directory. We maintain user accounts and groups to secure the use of email, Teams, and SharePoint.
8.2 Secure 365 – Manage MFA
We implement and manage Multi-Factor Authentication for 365.
8.3 Secure 365 – Advanced
We manage Azure Active Directory as the customers domain, apply advanced security settings to Azure Active Directory, Security, Compliance, Exchange, Team and SharePoint admin centers.
9. Secure Office Services
9.1 Secure Office – Active Directory
We continually review best practices and adjust security settings for Local Domain environment. We maintain setup local domain environment and set parameters for best practices to manage the use of Active Directory, DHCP, DNS, network segmentation and firewall. If no local domain, then setup Azure AD. Customer may be required to upgrade to Azure Active Directory P1 or a License that has this feature included such as 365 Business Premium.
9.2 Secure Office – Password Manager
This service provides licensing for an application that allows your company users to store and retrieve passwords in a secure manner. Password Manager will store all password in an encrypted solution. Licensed users will be able to use the Password Manager across devices, including mobiles seamlessly. Additional functionality is optional and is available for additional charge.
9.2.5 Secure Office – Password Manager – DarkWeb Monitor
This service provides additional functionality licensing to activate Breach Watch functionality which will report on stored passwords with breach reported on the DarkWeb.
9.3 Secure Office – MFA Application
Full service Multi-Factor Authentication that allows to add MFA to other applications including windows login. This service provides the capability to setup management of all remote and local access to sensitive or administrative systems with multi-factor authentication.
9.4 Secure Office – Encryption – Hard Disk
System level encryption setup with bitlocker, maintain keys. Requires Windows 10 Pro and above.
9.5 Secure Office – Encryption – Vaults
Create on-the-fly-encrypted-volume to store PII or PHI files securely using 256 bit key, 128 bit block, 14 rounds (AES-256).
9.6 Secure Office – AD Sync
Setup and maintain Hybrid environment and AD-Sync to sync user accounts between on-premises server and 365 AAD.
10. Data Backup Services
10.1 Left Intentionally Blank
10.2 Data Backup – Workstations
This service provides licensing for your data backup solution. This is direct to cloud backup solution that includes recovery to the cloud. This plan includes virtual machine hosting for production environment in a disaster recovery event. Backup strategy is defined jointly with customer covering appliances and cloud storage. Local storage appliances and their licensing are not included in this service.
10.3 Data Backup – 365 Users
Client may opt to have 365 backup at the tenant level (it is recommended) in addition or instead of workstation backup.
10.4 Data Backup – Servers
We provide cloud backup storage to meet backup and restore requirements tailored to customer needs. This service includes a maximum of 5TB of cloud storage for one server (additional storage space will incur additional charge). This service may be priced per server or per user as selected by Client.
10.5 Data Backup – Recovery
Data recovery services are quoted on a case by case basis. Note: In some situations (such as complete hardware failure, media failure or total data corruption) data may not be recoverable. The client is still responsible for the time-related fee. Costs for external data-recovery services are provided at additional cost.
11. General
11. Left Intentionally Blank
12. Security Awareness Services
12.1 Left Intentionally Blank
12.2 Employee Security Awareness – Cybersecurity and Phishing Training
We provide licensing for customer to engage employees with Cybersecurity training including phishing, training paths and security videos. We setup training environment and assist customer to setup training. We can provide done-for-you services at additional cost. This service can be broken down into sub-services below.
12.3 Left Intentionally Blank
12.4 Left Intentionally Blank
12.5 Security Awareness – Simulations
This sub-service provides the customer the ability to engage employees with phishing simulations. We can provide done-for-you services at additional cost.
13. Policies and Procedures
13.1 Left Intentionally Blank
13.1 Policies and Procedures – Employee Portal
We provide licensing for customer to engage employees with IT policies and procedures. We assist customer with: a) provide policy templates, b) setup and deploy policies, c) setup employees to adopt policies, d) show how to edit/update policies, e) provide portal to administer policies and procedures. Customer must decide IT policies to use and adjust to their needs. Customer must define any procedures it wants to document and follow. This license includes a Risk Assessment and Incident Management module.
13.2 Policies Management
We provide a set of startup IT Policies such as Acceptable Use Policy, Password Policy, Incident Response, Backup Policy, Multi Factor Authentication Policy, etc. Afterwards, we will work with your team to manage and implement any additional policies pertaining to your organization and IT.
14. General
14. Left Intentionally Blank
15. Remote Monitoring and Management (RMM)
15. Remote Monitoring and Management – RMM
15.1 RMM – Remote Management and Monitoring
We provide RMM licensing for covered computers and network devices. This license permits us to provide remote unattended access to servers and workstations.
15.1.1 Apple iOS MDM
Deploy, manage and maintain iOS devices. Device deployment, monitoring and device security, including remote wipe.
15.1.2 Apple macOS MDM
Deploy, manage and maintain macOS devices. Device deployment, monitoring and device security, including remote wipe. This license permits us to provide remote unattended access to servers and workstations. This solution also allows us to monitor and manage alerts 24×7 and software updates.
15.2 RMM – Alert, Asset and Software Management
Monitoring and management allow Provider to deploy patches utilizing strategic timing based on best practices. The RMM monitors and generates alerts 24×7. Specific critical alerts will notify our Network Operations Center. The following services apply: (1) our Network Operations Center will live monitor these alerts during Business Hours, (2) provide reports of all proactive and reactive RMM activities monthly, and (3) provide asset and software management with all hardware and software details.
15.3 Left Intentionally Blank
15.4 RMM – Unattended Remote Access
We provide RMM licensing for covered computers and network devices. This license permits us to provide remote unattended access to servers and workstations. Our Network Operations Center will live monitor these during Business Hours.
15.5 RMM – Windows Patch Management
Using our RMM tool we keep your Windows computers up to date to maintain your computer security. We run updates every two weeks, and we ask that you restart your computer when requested.
16. Security Testing and Vulnerability Management
16.1 Left Intentionally Blank
16.2 Left Intentionally Blank
16.3 Third-Party Penetration Testing
Perform quarterly external and internal network security scans (75% of the computers) identifying areas of improvement and remediation requirements. We provide network and computer analysis reports to identify areas of improvement or to document audit requirements. We setup scan plan according to customer requirements and perform data gathering, report preparation, report review session and remediation actions if any.
16.4 Vulnerability Management
Deploy agents to evaluate installed software vulnerabilities and facilitate remediation. Identifies Microsoft and non-Microsoft software vulnerabilities.
17. Network Security Services
17.1 Firewall – Management
Maintain and manage your firewalls keeping with current firmware and vulnerability updates. Manage Multi-Factor Authentication, Virtual Private Network and suspicious logins. Includes firewall annual licensing renewal.