Skip to content
// Industries

Regulated, deadline-bound, and allergic to downtime.

Six layers. One operator.

Endpoint, identity, email, DNS, perimeter and recovery — deployed as one engagement rather than six vendors pointing at each other. Add Sophos MDR and a staffed SOC watches it around the clock. Either way, the engineer who configured it is the one who answers.

Nobody gets breached because they lacked a product. They get breached because nobody was watching the one they bought.

Most small companies already own antivirus, a firewall and Microsoft 365 security features they’ve never turned on. The gap isn’t licensing — it’s that alerts land in an inbox nobody reads, at 2am, on a Saturday. We close that gap by owning the whole stack and putting a staffed SOC behind it.

01 · The stack

Six layers, deployed as one.

Each layer catches what the one before it missed. Run them separately and you get six dashboards and no owner; run them together and you get a chain of custody from the DNS request to the isolated laptop.

Security layers, what runs at each, and what it stops
Layer What runs What it stops
01Perimeter RunsManaged firewall — rules reviewed, firmware patched, logs retained StopsExposed services, unmanaged inbound access, stale VPN rules
02DNS RunsDNS filtering on every device, on and off the office network StopsPhishing domains and command-and-control before a connection exists
03Email RunsGateway filtering, impersonation checks, SPF / DKIM / DMARC enforced StopsInvoice fraud, credential phishing, spoofed internal senders
04Identity RunsEntra ID conditional access, MFA everywhere, privileged roles time-bound StopsToken theft, logins from impossible locations, permanent admin rights
05Endpoint RunsEDR / XDR on every endpoint — with Sophos MDR analysts behind the telemetry where you add the tier StopsRansomware execution, lateral movement, living-off-the-land tooling
06Recovery RunsImmutable, off-site backup with quarterly restore tests StopsA bad day becoming a closed business — the layer that has to work

Layers one to five reduce the chance of an incident. Layer six decides what an incident costs. Most providers sell the first five. Written up at length: what ransomware actually looks like for a Canadian SMB, what Zero Trust means once you strip the marketing, and six endpoint practices that block it. Who runs this, and how the firm is structured, is on the about page.

02 · Managed detection

A SOC you couldn’t hire on your own.

Staffing a 24/7 security operations centre needs a team no company your size can justify. Sophos already runs one, and we operate your environment inside it. Priced per endpoint, on top of the baseline stack — you see the number before you decide.

More on MDR
A column of five layers: the internet, a firewall, email filtering, staff laptops and round-the-clock monitoring, each connected by a line.
The internet
Everything arriving from outside your network — web traffic, email, remote connections. This is the side you do not control.
Firewall
The boundary at your office edge. It decides which traffic is allowed in and out and blocks the rest, and it is where remote access is terminated.
Email filtering
Mail is the most common way in. Messages are inspected before delivery so attachments and links that fail the checks never reach the mailbox.
Staff devices
Laptops and desktops each run endpoint protection that watches behaviour on the machine itself, which catches what the perimeter cannot see.
Monitoring
Alerts from every layer above are watched rather than just logged, so something acting oddly at 3am is noticed and acted on.

Click a part to see what it does

01

They investigate, not just alert

An alert on its own is homework. Analysts triage the signal, pull the process tree, and decide whether it is a false positive or an intrusion — before anyone contacts you.

02

They act without waiting for approval

Where the threat is unambiguous, analysts isolate the host and kill the process under pre-agreed authority. Asking permission at 3am is how a contained incident becomes a recovery project.

03

They hunt when nothing is happening

Threat hunting looks for the intrusion that hasn’t tripped a rule yet — anomalous sign-ins, unusual admin behaviour, tooling that shouldn’t be on a workstation.

04

We stay the point of contact

You never open a ticket with Sophos. Escalation comes to your 4UIT engineer, who already knows which server matters and who to call in your business.

03 · Incident response

What actually happens on a bad morning.

Written down before you need it, because the middle of an incident is a poor time to discover who has authority to unplug a server.

T + 0

Detect

EDR telemetry flags the behaviour. The alert lands with a Sophos analyst, not in a mailbox.

Minutes

Triage

An analyst confirms whether it is real, and how far it has travelled. False positives stop here.

89 sec automated

Contain

The host is isolated from the network. It stays powered on so evidence survives. Your engineer is called.

Same day

Eradicate

Persistence removed, credentials rotated, entry point closed. Restore from clean backup where needed.

Within 24h

Report

Written account: what happened, what was touched, what changed. Plain English, suitable for your insurer.

// Agreed in advance

Who can authorise isolating a machine, which systems must never be taken offline without a call, who we notify first, and where your cyber-insurance policy number lives. Four questions, settled at onboarding, that decide how the morning goes.

04 · Security review

Posture drifts. Someone has to keep checking.

Monthly Identity hygiene. MFA gaps, dormant accounts, guest access, admin role creep, licence drift. Each exception gets an owner and a date.
Quarterly Configuration drift. Firewall rules against what they were approved to be, conditional access policies against the documented intent, device compliance against the baseline.
Quarterly Restore proof. A real restore from a real backup, timed and documented. Recovery you haven’t tested is a plan, not a capability.
Annually Tabletop. Walk the ransomware scenario with your leadership. Who calls whom, what gets said to clients, when the insurer is notified. An hour, once a year.

If you’re starting from zero, the first review is the deliverable — a written picture of where you actually stand, with the gaps ranked by what they’d cost you. That stands on its own whether or not you engage us.

05 · Questions

The ones people actually ask.

If yours isn’t here, ask it directly — you’ll get an answer from an engineer, not a form letter.

Antivirus matches known bad files. EDR watches behaviour — a legitimate program being used illegitimately. And MDR puts a human on the end of it, which is the part that actually stops an intrusion at 3am rather than filing it for Monday.

Yes. Security is available as a standalone engagement and several clients start there. It works better alongside managed IT, because patching and identity hygiene are half of security posture, but we will not make you switch to be protected.

Analysts isolate the affected host, usually within the hour, and your engineer is called by name. From there: eradicate, rotate credentials, restore from clean backup, and a written report within 24 hours in language your insurer will accept.

Modern EDR is light, and the policies get tuned to your environment rather than shipped as a template. Where a control genuinely gets in the way — a line-of-business app that trips a rule — we document an exception rather than pretend it is not happening.

Almost certainly, and most insurers now require MFA, EDR and tested backups before they will write a policy. The controls on this page are broadly the ones the questionnaire asks about, which makes the paperwork considerably shorter.

Assume they will — the layers exist because people are busy. DNS filtering and the mail gateway stop most of it, MFA limits what a stolen password is worth, and analysts catch what gets through. We would rather engineer around the risk than run a blame exercise.

Yes. MDR is a priced tier on top of the baseline, because a staffed 24/7 SOC carries a real per-endpoint cost we pay Sophos. EDR, mail filtering, DNS filtering and firewall management sit in the base engagement; MDR is quoted separately so you can see exactly what the human coverage costs and decide with the number in front of you.

Deployed and watched across the National Capital Region — Ottawa, Kanata, Nepean, Barrhaven, Orléans, Stittsville, Manotick and Gatineau. Monitoring runs wherever the endpoints are; on-site work is the NCR.

The quiet years are the deliverable.

Start with a security review. You get a written picture of where you stand and what to fix first — useful whether or not you hire us.