Managed Detection and Response Service (SOC, MDR, XDR)
Our Managed Detection and Response (MDR) service offers a comprehensive solution to strengthen your organisation's cybersecurity defences, protect against ever-evolving threats, and improve your operational resilience. We constantly monitor the data necessary to identify threats to your networks or devices, and prioritise action according to potential severity of impact.
Features
- Cyber Threat Intelligence (CTI) led service
- Real time reporting and analysis
- 24/7/365 UK based service provision
- CREST Accredited SOC
- Full team of expert intrusion analysis
- Incident Response team support
- Governance Risk and Compliance (GRC) team support
- Technology agnostic
- Network traffic capture and analysis
- Threat hunting and containment specialists (FIRST and CIR accredited)
Benefits
- Real time availability of security data
- Cyber Incident Exercising (CIE)
- 24/7/365 visibility and analysis of security data
- Advice to Board and senior stakeholders
- Engineering team to tune out "noise" driving efficiency
- Access to world-leading innovative technologies through our partnerships
- Security partnership approach continually matures cyber posture over time
- Threat led service tailors service to your sector, organisation, people
- Threat hunting means proactive security mitigation
- Digital forensics expertise
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 1 5 9 9 5 7 8 8 4 4 0 8 9 9
Contact
CYSIAM LIMITED
Rupert Ryan
Telephone: 07376019394
Email: tenders@cysiam.com
About your service
- Service categories
-
Systems Infrastructure Software
Security
- Cloud native application protection platform
- Endpoint security
- Security analytics
- Governance, risk and compliance
Network security
- Trusted network access and protection
- Active application security
Data security
- Information protection
- Digital trust
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- No constraints. We work with clients to manage changes throughout the life of the service. Service operates 24/7/365
- System requirements
- No mandatory system requirements
User support
- Email or online ticketing support
- Yes
- Support response times
- Acknowledgement of tickets varies with priority of event but usually within max 1hr
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- All MDR/XDR service clients are allocated a Customer Success Manager who will be their PoC during the service term. Frequency and quality of engagement can be determined by the client.
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
- We prepare detailed plans for service onboarding with an associated RAID log and training requirements for client staff. This ensures that all aspects of the required services are put in place according to the given timescale, and that there is a seamless non-service affecting transition from the client’s current security tooling and operations to the CYSIAM MDR service.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- An exit plan is agreed with each client describing all aspects of service off boarding, including data extraction/migration if required.
- End-of-contract process
- The processes described in the agreed exit plan will be implemented. Depending on the technology ownership model adopted by the client, this can be a relatively straightforward process.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- PDF documents, plans, designs and reports are shared with the client either via email, Slack, a shared data environment or any other platform the client requires.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
- Dashboards and reporting can be customised to meet client requirements as well as other aspects of the service.
Scaling
- Independence of resources
- Operations management keep a close watch on internal measures of SOC utilisation. If the measures breach 75% of maximum capacity then mitigation measures are introduced which include, changed shift patterns, and other efficiency methods. Resilience is underpinned by more strategic decisions including procurement of new tooling and recruitment of SOC staff.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Metrics presented by the real-time dashboard can be tailored to client requirements. Typical metrics include number of current open alerts, resolved alerts, number of P1 alerts, Response time, mean time to resolution, major incident log etc
- Reporting types
- Real-time dashboards
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- We can resell global technology leaders including CrowdStrike, Splunk, Cribl
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- This is rarely a requirement in an MDR service but most data sets can be exported if needed.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- N/A
- Approach to resilience
- N/A
- Outage reporting
- N/A
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
- All remote verification is done using 2FA
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- We have a comprehensive information security policy supported by processes all of which are compliant to ISO27001. All staff are briefed on joining with an annual refresh.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Service components and approach are continually tracked by the service lead and overseen by the CTO.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We use Qualys tool for vulnerability scanning and our extensive open source intelligence knowledge to continuously assess and prepare for threats to the organisation and the cyber security industry at large.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We continually monitor our systems for signs of compromise and respond immediately to any concerns.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We are a small enterprise. All events are evaluated and shared with all employees and systems updates accordingly. The process is managed by the CTO/CISO.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 20%
- Between £2,500,001 and £5,000,000
- 25%
- Over £5,000,001
- 30%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- NQA
- ISO/IEC 27001 accreditation date
- Thursday 3 November 2022
- What the ISO/IEC 27001 doesn’t cover
- The whole business except the SOC is covered (SOC coverage is underway)
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Citation ISO Certification Limited
- ISO 9001 accreditation date
- Wednesday 3 April 2024
- What the ISO 9001 doesn’t cover
- Whole business is covered
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 419afc90-a5b0-4586-ba19-994a82cdcdd0
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- C4748965-2508-4394-b10a-8e837badcfa4
- Other security certifications
- Yes
- Any other security certifications
-
- IASME Cyber Assurance Level One
- CREST Accredited for Penetration Testing
- CREST Accredited for Vulnerability Assessment
- CREST Accredited for Cyber Incident Response
- CREST Accredited for Security Operations Centre (SOC)
- NCSC Accredited for Cyber Incident Response (CIR) Standard Level
- NCSC Accredited for Cyber Incident Exercising (CIE)
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
-