Six layers. One operator.
Endpoint, identity, email, DNS, perimeter and recovery — deployed as one engagement rather than six vendors pointing at each other. Add Sophos MDR and a staffed SOC watches it around the clock. Either way, the engineer who configured it is the one who answers.
Nobody gets breached because they lacked a product. They get breached because nobody was watching the one they bought.
Most small companies already own antivirus, a firewall and Microsoft 365 security features they’ve never turned on. The gap isn’t licensing — it’s that alerts land in an inbox nobody reads, at 2am, on a Saturday. We close that gap by owning the whole stack and putting a staffed SOC behind it.
Six layers, deployed as one.
Each layer catches what the one before it missed. Run them separately and you get six dashboards and no owner; run them together and you get a chain of custody from the DNS request to the isolated laptop.
| Layer | What runs | What it stops |
|---|---|---|
| 01Perimeter | RunsManaged firewall — rules reviewed, firmware patched, logs retained | StopsExposed services, unmanaged inbound access, stale VPN rules |
| 02DNS | RunsDNS filtering on every device, on and off the office network | StopsPhishing domains and command-and-control before a connection exists |
| 03Email | RunsGateway filtering, impersonation checks, SPF / DKIM / DMARC enforced | StopsInvoice fraud, credential phishing, spoofed internal senders |
| 04Identity | RunsEntra ID conditional access, MFA everywhere, privileged roles time-bound | StopsToken theft, logins from impossible locations, permanent admin rights |
| 05Endpoint | RunsEDR / XDR on every endpoint — with Sophos MDR analysts behind the telemetry where you add the tier | StopsRansomware execution, lateral movement, living-off-the-land tooling |
| 06Recovery | RunsImmutable, off-site backup with quarterly restore tests | StopsA bad day becoming a closed business — the layer that has to work |
Layers one to five reduce the chance of an incident. Layer six decides what an incident costs. Most providers sell the first five. Written up at length: what ransomware actually looks like for a Canadian SMB, what Zero Trust means once you strip the marketing, and six endpoint practices that block it. Who runs this, and how the firm is structured, is on the about page.
A SOC you couldn’t hire on your own.
Staffing a 24/7 security operations centre needs a team no company your size can justify. Sophos already runs one, and we operate your environment inside it. Priced per endpoint, on top of the baseline stack — you see the number before you decide.
More on MDR
- The internet
- Everything arriving from outside your network — web traffic, email, remote connections. This is the side you do not control.
- Firewall
- The boundary at your office edge. It decides which traffic is allowed in and out and blocks the rest, and it is where remote access is terminated.
- Email filtering
- Mail is the most common way in. Messages are inspected before delivery so attachments and links that fail the checks never reach the mailbox.
- Staff devices
- Laptops and desktops each run endpoint protection that watches behaviour on the machine itself, which catches what the perimeter cannot see.
- Monitoring
- Alerts from every layer above are watched rather than just logged, so something acting oddly at 3am is noticed and acted on.
Click a part to see what it does
They investigate, not just alert
An alert on its own is homework. Analysts triage the signal, pull the process tree, and decide whether it is a false positive or an intrusion — before anyone contacts you.
They act without waiting for approval
Where the threat is unambiguous, analysts isolate the host and kill the process under pre-agreed authority. Asking permission at 3am is how a contained incident becomes a recovery project.
They hunt when nothing is happening
Threat hunting looks for the intrusion that hasn’t tripped a rule yet — anomalous sign-ins, unusual admin behaviour, tooling that shouldn’t be on a workstation.
We stay the point of contact
You never open a ticket with Sophos. Escalation comes to your 4UIT engineer, who already knows which server matters and who to call in your business.
What actually happens on a bad morning.
Written down before you need it, because the middle of an incident is a poor time to discover who has authority to unplug a server.
Detect
EDR telemetry flags the behaviour. The alert lands with a Sophos analyst, not in a mailbox.
Triage
An analyst confirms whether it is real, and how far it has travelled. False positives stop here.
Contain
The host is isolated from the network. It stays powered on so evidence survives. Your engineer is called.
Eradicate
Persistence removed, credentials rotated, entry point closed. Restore from clean backup where needed.
Report
Written account: what happened, what was touched, what changed. Plain English, suitable for your insurer.
Who can authorise isolating a machine, which systems must never be taken offline without a call, who we notify first, and where your cyber-insurance policy number lives. Four questions, settled at onboarding, that decide how the morning goes.
Posture drifts. Someone has to keep checking.
If you’re starting from zero, the first review is the deliverable — a written picture of where you actually stand, with the gaps ranked by what they’d cost you. That stands on its own whether or not you engage us.
The ones people actually ask.
If yours isn’t here, ask it directly — you’ll get an answer from an engineer, not a form letter.
Antivirus matches known bad files. EDR watches behaviour — a legitimate program being used illegitimately. And MDR puts a human on the end of it, which is the part that actually stops an intrusion at 3am rather than filing it for Monday.
Yes. Security is available as a standalone engagement and several clients start there. It works better alongside managed IT, because patching and identity hygiene are half of security posture, but we will not make you switch to be protected.
Analysts isolate the affected host, usually within the hour, and your engineer is called by name. From there: eradicate, rotate credentials, restore from clean backup, and a written report within 24 hours in language your insurer will accept.
Modern EDR is light, and the policies get tuned to your environment rather than shipped as a template. Where a control genuinely gets in the way — a line-of-business app that trips a rule — we document an exception rather than pretend it is not happening.
Almost certainly, and most insurers now require MFA, EDR and tested backups before they will write a policy. The controls on this page are broadly the ones the questionnaire asks about, which makes the paperwork considerably shorter.
Assume they will — the layers exist because people are busy. DNS filtering and the mail gateway stop most of it, MFA limits what a stolen password is worth, and analysts catch what gets through. We would rather engineer around the risk than run a blame exercise.
Yes. MDR is a priced tier on top of the baseline, because a staffed 24/7 SOC carries a real per-endpoint cost we pay Sophos. EDR, mail filtering, DNS filtering and firewall management sit in the base engagement; MDR is quoted separately so you can see exactly what the human coverage costs and decide with the number in front of you.
Next
Deployed and watched across the National Capital Region — Ottawa, Kanata, Nepean, Barrhaven, Orléans, Stittsville, Manotick and Gatineau. Monitoring runs wherever the endpoints are; on-site work is the NCR.
The quiet years are the deliverable.
Start with a security review. You get a written picture of where you stand and what to fix first — useful whether or not you hire us.