Managed Security Services Provider

Nine platforms.
One accountable
security team.

Most organisations do not have a tooling problem. They have an ownership problem — consoles nobody watches, alerts nobody triages, and a patch cycle that slipped two quarters ago. Iron Grid runs the whole stack as a single service, with named engineers and a SOC that is staffed at three in the morning.

Microsoft CSP / Huntress / Carbon Black / Wazuh / WatchGate.io / Meraki

9
Platforms managed
24/7
SOC coverage, staffed
12 mo
Hot log retention
5
Integrated service lines
The Stack

Every platform, named.
Every one of them, ours to run.

We publish the whole toolchain because the alternative — "proprietary next-generation platform" — is usually a reseller agreement someone would rather you did not price-check.

Full stack detail

Microsoft CSP

Cloud licensing & tenant security

Microsoft 365 and Azure licensing bought through Iron Grid as your Cloud Solution Provider, with the security baseline configured, monitored, and reported on rather than left at defaults.

DeploymentTenant-level
CoverageM365 · Azure · Entra ID
TelemetrySign-in & audit logs

Huntress

Managed detection & response

Persistent-foothold hunting and identity threat detection backed by a human analyst team — the layer that catches what silently survived the initial compromise.

DeploymentLightweight agent
CoverageWindows · macOS · M365
TelemetryPersistence & ITDR

Carbon Black

Endpoint protection & EDR

Next-generation antivirus with continuous endpoint recording, so an investigation can replay exactly what a process did instead of guessing from what survived.

DeploymentManaged sensor
CoverageWindows · macOS · Linux
TelemetryFull process lineage

Wazuh

SIEM, log retention & file integrity

The open-source SIEM where every other layer's telemetry lands — correlated, retained for the period your auditor asks about, and mapped to MITRE ATT&CK.

DeploymentManaged cluster + agent
CoverageServers · endpoints · cloud · firewall
Telemetry12-month hot retention

WatchGate.io

Perimeter & edge security

Managed firewall, secure remote access, and egress inspection at every site boundary — with rule changes handled through documented change control rather than ad hoc console edits.

DeploymentPer site / gateway
CoveragePerimeter · VPN · egress
TelemetryFlow & policy logs

Meraki

Cloud-managed network infrastructure

Cloud-managed switching, wireless, SD-WAN, and security appliances — one dashboard across every site, monitored by the same team that watches the endpoints hanging off it.

DeploymentPer device / per site
CoverageMX · MS · MR · MV
TelemetryEvent & security streams

Kaseya

RMM, patching & automation

Remote monitoring and management for the unglamorous work that prevents most incidents: asset inventory, patch deployment, and configuration drift correction.

DeploymentManaged agent
CoverageWindows · macOS · servers
TelemetryPatch & asset state

Autotask

PSA, ticketing & SLA tracking

The professional services automation platform behind every ticket, escalation, and SLA clock — so response time is a measured number rather than an impression.

DeploymentIron Grid platform
CoverageTickets · SLA · assets
TelemetryResponse & resolution

IT Glue

Documentation & credential vaulting

Structured, versioned documentation of your environment with audited credential storage — the difference between a fast recovery and a scavenger hunt at 3am.

DeploymentIron Grid platform
CoverageRunbooks · configs · secrets
TelemetryAccess audit trail
Defence in depth

Six layers, and what fails through each one.

Every control has a failure mode. The useful question is not whether a layer can be bypassed — it can — but what catches the attacker on the way past it.

Layer 01
Perimeter & network

Firewall policy under change control, segmentation that keeps a compromised camera away from a domain controller, and egress inspection — because outbound command-and-control is often the first honest signal you get.

WatchGate.ioMeraki
Layer 02
Identity

Conditional Access, MFA enforcement, privileged role review, and sign-in monitoring. Identity is the boundary most incidents actually cross, and credentials do not trigger antivirus.

Microsoft CSP
Layer 03
Endpoint prevention

Next-generation antivirus and managed Defender policy across the fleet, tuned per role rather than one permissive ruleset stretched across servers and laptops alike.

Carbon BlackHuntress
Layer 04
Detection & hunting

Continuous process recording, persistence-foothold hunting, and human analysts working a queue. Prevention is the layer that fails quietly; detection is what makes the failure visible.

HuntressCarbon BlackWazuh
Layer 05
Correlation & retention

One searchable dataset across endpoint, identity, network, and cloud, retained twelve months hot. Without retention, an incident discovered in month four is an incident you cannot scope.

Wazuh
Layer 06
Operations & recovery

Patching, asset reconciliation, ticketing with SLA clocks, and documentation good enough to recover from. Detection tells you something is wrong; documentation decides how long it stays wrong.

KaseyaAutotaskIT Glue
Onboarding

Thirty days from signature to steady state.

Nothing here requires you to rip anything out on day one. Existing tooling stays until its replacement is verified working — a coverage gap during migration is exactly the window an attacker wants.

STEP 01

Discovery

We inventory what exists, not what the documentation claims exists. Asset discovery, identity review, firewall ruleset export, and an honest map of the gaps.

Week 1
STEP 02

Deploy & baseline

Agents rolled out in rings, log sources connected, tenant baseline applied. We measure normal before we start alerting on abnormal.

Weeks 1–2
STEP 03

Tune & document

Alert thresholds tuned against your actual traffic, escalation paths agreed by name, runbooks written. A noisy SOC gets ignored, so tuning is not optional.

Weeks 2–4
STEP 04

Steady state

Monitoring live, monthly reporting begins, quarterly review scheduled. You get the coverage gap list by hostname from the first report onward.

Week 4+
About Iron Grid

The provider you can audit.

A security provider holds privileged access to everything you own. That is a serious thing to hand over, and it deserves more scrutiny than a capability matrix and a reference call.

So we publish the toolchain, log every credential retrieval and hand you the audit trail on request, and hand back your full documentation set if you leave — whether the parting is amicable or not.

Our security posture
Background-screened staff Role-based client access Documented exit process Cyber liability insured

Named engineers

You know who owns your account and who answers a severity-one at three in the morning. Escalation paths list people, not queues.

MITRE ATT&CK mapped detections

Coverage reported as a technique matrix with the gaps visible, rather than a vendor score with no arithmetic behind it.

Auditable access

Every credential retrieval and every session against your environment is logged, attributed, and available to you on request.

Portable documentation

Runbooks, diagrams, configurations, and credentials exported in full at no charge if you leave. No hostage-taking.

Active incident

If something is happening right now, do not fill in a form. Call the hotline — it reaches an analyst, at any hour, whether or not you are a client.

(888) 555-0199

Ready to find out what your current stack is actually missing?