A Fortify 24x7 brand. Someone sits the console through the hours your doors are shut.Sign in to the portalReach an engineer
SecureOps Solutions
Position 01 / Threat console

Something is always running. Knowing which of it matters is the job.

Nobody here expects you to remember to open a screen. Detection is software with an opinion about how a program is behaving, a layer setting that opinion beside four other feeds, and a person in a chair who rules on the result at twenty past four. Every line below arrives with all three.

SentinelOneFluencyChair never empty
6 lines / 3 levels of authority / desks and nodes
Lines here6
Kit in useSentinelOne with Fluency
Billed byDesk, or cluster node
ChairFilled in every hour of the day

What the software is actually forming an opinion about

Signature lists stopped earning their keep a long while back. Conduct is what the SentinelOne agent reads instead. Parent and child. Files touched. Addresses dialled. Whether the run of it looks like a ransom note being prepared, like material being gathered up, or like a stranger working a corridor testing handles. Unplug the network and the ruling still happens, which matters for the laptop taken home and for the box behind the stock room door nobody has touched since Easter.

Whatever the agent writes then gets set alongside the rest of the afternoon by Fluency: who authenticated, what came in by mail, what went out onto the wire, plus whatever your other tooling was writing at the time. Anything reaching this chair has enough context around it for a ruling. The gap between an alert and a ruling is the gap between notification and help.

An alert tells you. A ruling helps you. Those are not the same purchase.

Choosing how much authority to hand over

Line one rules and advises. Line two widens the chair, so an implausible login and a peculiar process in the back office stop being filed as separate oddities. Line three hands over standing authority to act unaccompanied, and at three on a Sunday the alternative involves waking somebody up first.

Nodes are priced separately. A node resembles a desk in no way whatsoever, the agent behaves differently up there, and folding nodes quietly into a desk count makes an invoice untrue. Nodes are what get counted. Pods are not. If that sentence meant nothing, then these three lines do not belong on your board, and nobody here will push them.

Lines at this chair

What each line covers, and what it costs

Billing supplies each figure below as the page draws. Add a line and it sits on the board while you read further down.

Fortify-MDROn the board

Managed Detection and Response

SentinelOne at the desk, Fluency behind it, a chair that is never empty

Software on the computer forms an opinion about how a program is behaving. Somebody at this console then forms an opinion about the software. You are handed the second opinion, in a sentence, with the reasoning under it.

  • Windows, macOS and Linux, and the verdict still gets made with the network cable out.
  • Nobody parks the finding in your inbox and calls that a service.
  • Whatever we conclude is written into the callout and stays legible in your portal.
PositionThreat console, chair never empty
Watches forPrograms behaving like ransomware, like a collector, or like somebody quietly trying doors along a corridor
Log keptThe evidence, the analyst reasoning, and the action, filed under your account
Escalation pathAnalyst raises a callout, then reaches the contact you nominated by mail
Sign-offClosed by an engineer who states what it turned out to be, in plain words
Rate loadingper protected endpoint
taken monthly, ahead of the month
QTY
Fortify-XDROn the board

Extended Detection Across Layers

SentinelOne, with Fluency pulling in the neighbouring screens

Widen the chair. Sign-ins, mail and traffic get lined up beside what the computer reported, and a login from somewhere odd stops being filed separately from a peculiar program running in the back office.

  • Four feeds read side by side rather than in four separate browser tabs.
  • Sequences that not one product could have argued for from its own evidence.
  • Kept longer, since half the questions worth asking get asked in retrospect.
PositionThreat console, neighbouring feeds switched in
Watches forSequences that only become obvious once four separate feeds are laid out together
Log keptA joined timeline naming every feed that carried part of the sequence
Escalation pathAnalyst raises the callout with the assembled timeline already attached
Sign-offClosed by an engineer who names which feed carried the first useful signal
Rate loadingper protected endpoint
taken monthly, ahead of the month
QTY
Fortify-XDR+On the board

Extended Detection with Response

SentinelOne, cleared in advance to pull a machine off the wire

Same watch, plus standing authority. Past the agreed line, the box gets cut from the network and its changes wound back, while the analyst catches up on paperwork afterwards. On a Sunday at three, waiting is the expensive option.

  • Standing authority to isolate, agreed with you in writing before it is ever used.
  • Undoes the alterations a convicted program made, on the systems that permit undoing.
  • Nothing acts unreviewed: a person reads back every automatic move and writes it up.
PositionThreat console, standing authority granted in advance
Watches forThe same behaviour as the two tiers above, measured against the line you agreed
Log keptEach automatic move, what tripped it, and the human read-back afterwards
Escalation pathThe machine comes off the wire first; the call to your contact follows
Sign-offAn engineer either endorses the move or undoes it and tells you which and why
Rate loadingper protected endpoint
taken monthly, ahead of the month
QTY
Fortify-MDR-K8On the board

Managed Detection, Kubernetes Node

SentinelOne, sitting on the node under your containers

Cover for containerised workloads, billed by node, a number your platform engineer could recite from memory. Never heard of Kubernetes? Then this line and the two after it are not yours, and we will say so.

  • An agent per node, covering everything the scheduler puts there on a given day.
  • Identical console, identical triage, identical callout trail to the desktop lines.
  • Judges containers while they run, which is a different exercise from scanning an image.
PositionThreat console, node watch
Watches forHow the workloads on a node behave once they are actually running
Log keptContainer evidence with the node and the workload both named in the file
Escalation pathAnalyst raises a callout and reaches whoever owns your platform
Sign-offClosed once the workload is explained, patched or taken out of the cluster
Rate loadingper Kubernetes node
taken monthly, ahead of the month
QTY
Fortify-XDR-K8On the board

Extended Detection, Kubernetes Node

SentinelOne on nodes, with Fluency joining them to everything else

Node cover with neighbouring feeds switched in. Cluster activity gets read against whichever account reached it, not off in a tab by itself.

  • Cluster activity lined up beside identity, desktop and network feeds.
  • Findings running across a workload and whoever authenticated to start it.
  • One retained timeline covering cluster and desktop together.
PositionThreat console, node watch with neighbouring feeds switched in
Watches forCluster activity measured against the identities and desktops that touched it
Log keptA single timeline across node, identity, desktop and network
Escalation pathAnalyst raises the callout to your platform contact with the timeline attached
Sign-offClosed by an engineer who names the feed that carried the first useful signal
Rate loadingper Kubernetes node
taken monthly, ahead of the month
QTY
Fortify-XDR+K8On the board

Response Tier, Kubernetes Node

SentinelOne, cleared to shut a container down without ringing first

Node cover carrying standing authority, for a cluster holding something you would sooner not leave misbehaving until somebody signs on again on Monday.

  • Standing authority to shut a workload down once it passes the agreed line.
  • The file arrives already assembled from cluster, identity and desktop evidence.
  • Every automatic move read back by a person, written up, and sent to you.
PositionThreat console, node watch with standing authority granted
Watches forWorkload behaviour measured against the line you agreed during rollout
Log keptThe move made, the evidence under it, and the read-back that followed
Escalation pathShut down first, then the call to whoever owns your platform
Sign-offAn engineer endorses the move, or reverses it and explains the judgement
Rate loadingper Kubernetes node
taken monthly, ahead of the month
QTY
Honest scope

Where this chair stops being any use

Detection is a decent control and a hopeless guarantee. The gaps are written out below, plainly, so that you can fill them knowingly.

  • Recognising it is not preventing it. Software recognising an intrusion is software telling you one has already started. The purchase is the speed and the quality of what follows. Nothing sold here, or anywhere on earth, promises that nothing ever starts.
  • A filled chair is not a stopwatch. A person sits at this console in every hour of the day, and we will be held to that. It is a claim about rotas. No response time is printed anywhere on this site: a figure nobody could stand behind for your own estate would be worth nothing to either of us.
  • No agent, no evidence. Hardware that never enrols writes nothing down, features in no file, and is reached by nothing sold on this page. The machine somebody keeps at home for Sundays included.
  • Putting changes back is not a backup. Line three winds back whatever a convicted process did, on systems that permit winding back. Dead disks and last quarter's version of a spreadsheet fall outside. Take those to the recovery chair.
  • Node lines cover the node. Your cluster design, your role bindings, where secrets sit, what admission accepts: every bit of that remains yours. Opinions are given on request. Ownership does not move.
NOTE 01

Heads up: card statements show FORTIFY 24X7 - SecureOps Solutions is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.