Antivirus stops what's known,
EDR and ITDR catch the rest.

Proactive, monitored protection across your devices and your logins, managed antivirus, endpoint detection and response, and identity threat detection and response, watched around the clock and acted on by our engineers.

24/7

Monitoring & alerting

3 layers

Device, behaviour, identity

Minutes

To isolate a device

UK

Engineers, in-house

Security console · last 24 hours

No active compromise
Trojan quarantined · downloads folderManaged antivirus · signature match, file removed
AVQuarantined
Encoded PowerShell spawned by WordEDR · process chain halted, device isolated from network
EDRIsolated
Sign-in from unfamiliar countryITDR · impossible travel, session revoked, password reset forced
ITDRBlocked
MFA fatigue attempt · 22 push requestsITDR · account locked, user contacted by phone
ITDRContained
Phishing mail filtered · 214 messagesMail security · quarantined before delivery
mailFiltered
Critical patches deployed · 31 devicesPatch management · reboots scheduled out of hours
patchApplied
Monitored by ACSMean time to isolate · under 15 min

Traditional antivirus alone
is no longer enough.

Attacks have moved on. Modern intrusions arrive through a stolen password rather than a virus, run using tools already on the machine, and are over in minutes. Detection has to move with them.

What antivirus on its own misses

Threats with no signature yet

Brand-new ransomware and one-off variants don’t match a known pattern, so a signature-based scanner has nothing to compare.

Attacks that use legitimate tools

PowerShell, remote desktop and admin utilities are all trusted software, used maliciously, most scanners never blink.

Stolen logins, no malware at all

If someone signs in with a real password from a real browser, there is nothing on the device to detect.

An alert nobody reads

The software popped a warning on a machine in the back office at 2am. Detection without response is just a log file.

One infected device becoming twenty

Without the ability to isolate a machine instantly, it spreads across the network while you work out what happened.

What managed security does instead

Behaviour, not just signatures

EDR watches what processes actually do, so a document launching a script chain is caught even when the file itself is unknown.

Your identities watched too

ITDR monitors sign-ins and mailbox rules, impossible travel, MFA fatigue, token theft and quiet forwarding rules.

Containment in minutes

A suspect device is isolated from the network and a compromised session revoked while the investigation is still running.

Everything patched on a rhythm

Operating system and third-party updates deployed centrally, out of hours, with the estate reported on monthly.

Humans on the end of the alert

Our engineers triage every detection and ring you. You never have to interpret a security console yourself.

Antivirus, EDR and ITDR,
and why you want all three.

Each layer sees something the others can’t. Together they cover the file, the behaviour and the person signing in.

Layer 01
AntivirusManaged, next-generation AV

Real-time scanning that blocks the enormous volume of known malware, viruses and ransomware before it ever runs, kept permanently current and centrally managed by us, not left to each user.

What it stops
  • Known malware, viruses and worms
  • Malicious downloads and USB payloads
  • Ransomware with a known signature
  • Unwanted and risky applications
How we run it
  • Definitions and agents always up to date
  • Central policy across every device
  • Scan results reviewed, not just logged
Layer 02
EDREndpoint Detection & Response

Continuous recording of what happens on each device. EDR spots the behaviour of an attack, a macro spawning a script, credential dumping, mass file encryption, then contains it and lets us rewind exactly what happened.

What it stops
  • Zero-day and fileless attacks
  • Living-off-the-land tooling abuse
  • Ransomware mid-encryption, with rollback
  • Lateral movement across the network
How we run it
  • Device isolated on detection, in minutes
  • Full process timeline for investigation
  • Root cause found, not just cleaned up
Layer 03
ITDRIdentity Threat Detection & Response

Most breaches now start with a login, not a virus. ITDR watches Microsoft 365 and Entra ID for the signs an account has been taken over, and shuts the session down before the mailbox is used against your customers.

What it stops
  • Account takeover and stolen passwords
  • Impossible-travel and unfamiliar sign-ins
  • MFA fatigue and push-bombing
  • Session and token theft
  • Hidden mailbox forwarding rules
How we run it
  • Sessions revoked, credentials reset
  • Conditional access policies maintained
  • User contacted directly by our team

Recovery is the fourth layer, pair this with managed backup services so even a worst case is a restore rather than a rebuild.

Everything that sits
behind the three layers.

Tools are only half of it. The rest is deployment, tuning, monitoring, patching and someone answering when something fires.

Managed antivirus

Next-generation AV deployed, policy-managed and kept current across every endpoint, with results reviewed by us daily.

EDR & device isolation

Behavioural detection with the ability to cut a compromised machine off the network in minutes and roll back encrypted files.

ITDR for Microsoft 365

Sign-in and identity monitoring across Entra ID, with automatic session revocation and forced password resets on takeover.

24/7 monitoring & alerting

Detections are watched continuously and triaged by our engineers, real threats acted on, noise filtered out before it reaches you.

Patch management

Operating system and third-party updates tested and deployed centrally, scheduled out of hours, reported on monthly.

Email & phishing protection

Mail filtering plus SPF, DKIM and DMARC configured properly, so nobody can convincingly send mail as your business.

MFA & conditional access

Multi-factor enforced properly, legacy authentication closed off, and access policies built around how your people actually work.

Hardening & asset visibility

Centralised view of every managed device, its patch state and its protection status, so nothing quietly falls off the estate.

Reporting & security reviews

A monthly report of what was blocked, isolated and patched, plus a plain-English review of what to improve next.

Incident

Ransomware on screen, or an account acting on its own?

Call us straight away, client or not. We'll get the affected devices isolated, revoke compromised sessions, work out how they got in, clean the estate properly and help you deal with the reporting side. Acting in the first hour changes the outcome.

  • Ransomware & encrypted files
  • Account takeover
  • Mail sent from your domain
  • Suspicious mailbox rules
  • Fraudulent invoice requests
  • Unknown remote access
0121 798 1595Report an incidentMon-Sat 09:00-20:00 · out of hours for support clients

What happens
when something fires.

Detection is the easy part. These four stages are what turns an alert into an outcome.

01Stage 1 of 4
Stage 01 · Assess & deploy

Know the estate before defending it

We audit what you're running: devices, operating systems, licences, mailboxes and who has access to what. Then we deploy antivirus, EDR and ITDR with policies tuned to your business rather than a vendor default.

  • Device & identity audit
  • Agents deployed
  • Policies tuned
Stage 02 · Monitor

Watched continuously, triaged by people

Detections stream into our console around the clock. Every one is triaged by an engineer, the noise is filtered, the real signals are escalated, and you're contacted directly rather than sent a link to a dashboard.

  • 24/7 detection
  • Human triage
  • Named contact, not a ticket
Stage 03 · Contain

Cut it off in minutes, not meetings

A suspect device is isolated from the network, malicious processes are stopped, and compromised sessions and tokens are revoked with passwords force-reset. Containment happens first; the investigation runs alongside it.

  • Device isolation
  • Sessions revoked
  • Spread stopped
Stage 04 · Recover & harden

Close the gap it came through

Files rolled back or restored from backup, the entry point identified and closed, patches and policies tightened, and the whole thing written up in plain English with what we changed and what you should change next.

  • Rollback or restore
  • Root cause closed
  • Written review
Keep scrolling

Start with the device.
Add behaviour, then identity.

Priced per endpoint and per user, on a rolling monthly basis. Most businesses with Microsoft 365 should be on Complete, that’s where the attacks are.

Essential

Managed antivirus & patching

Quoted per endpoint, per month

Recommended

Advanced

Adds EDR and 24/7 response

Quoted per endpoint, per month

Complete

Adds ITDR for Microsoft 365

Quoted per user, per month

Rolling monthly terms · no per-incident charges · sized for 1 device or 200

Security stops the attack.
These handle the rest.

Where this overlaps with the other services, so you’re not paying for the same thing twice.

Managed backup

Immutable, encrypted, off-site copies of your data with 30-day version history, so the very worst day means a restore rather than a negotiation.

Microsoft 365

Tenant setup, licensing, migration and support. ITDR watches the sign-ins; this is the service that gets the tenant configured properly in the first place.

Website security

Firewalling, SSL, malware removal and hardening for your website and the email behind it, a different perimeter to the one your staff log into.

Common questions

Before you get in touch.

Antivirus asks “have I seen this file before?” and blocks known bad things. EDR asks “is this behaviour normal?”, it records what processes do and spots an attack by its actions, so it catches brand-new threats and attacks that use legitimate Windows tools. It can also isolate the machine and roll changes back.

Identity Threat Detection and Response. It watches your Microsoft 365 and Entra ID logins instead of your devices: unfamiliar sign-in locations, impossible travel, repeated MFA prompts, stolen session tokens, and mailbox forwarding rules quietly added. Most modern breaches start with a valid login, where there is no malware to find.

Defender is a decent engine, but on its own it’s unmanaged and unmonitored, nobody is reviewing policy, chasing failed updates, or acting on alerts at 2am. The value here is the management and response, not just the software.

If you use Microsoft 365 and hold customer data, we’d recommend all three. Smaller setups often start with antivirus and patching, then add EDR, then ITDR. We’ll tell you honestly where your biggest gap is after the free assessment.

Automated containment happens immediately, the device is isolated or the session revoked without waiting for a human. An engineer then triages the detection and contacts you, and support clients have out-of-hours escalation.

Modern agents are light, and we tune policies and scan windows around your working day. If a machine is already struggling, that’s usually a hardware or maintenance issue, and we’ll tell you which it is.

Yes. Windows and macOS are both covered, and mixed estates are normal. ITDR is tied to your Microsoft 365 identities, so it protects your people regardless of the device they use.

We review what protection you have now, patch levels across your devices, your Microsoft 365 sign-in and MFA configuration, mail records and backup position, then give you a written summary of the gaps in priority order. No obligation, and it’s yours to keep.

Find out where you're actually exposed

Tell us how many devices and Microsoft 365 users you have and what protection is in place today. We’ll run a free security assessment and come back with the gaps in priority order, plus a fixed monthly price to close them.

ACS at work