Managed security (MSSP): continuous cybersecurity for your business

Cybersecurity isn't a one-off project, it's an ongoing process. We act as your outsourced security department: monitoring, detecting, responding and improving your security posture month after month.

Why do you need managed security?

Most companies can't afford an in-house CISO, SOC and incident response team. Yet attackers don't distinguish between a 20-person startup and an Ibex35 company. An MSSP service gives you access to enterprise-grade security capabilities for a fraction of the cost, with the advantage of scaling to your needs and having a single point of contact for all your cybersecurity.

What the MSSP service includes

  • Virtual CISO: monthly strategic advisory and oversight of the security program
  • Continuous vulnerability management: scanning, prioritization and remediation tracking
  • External attack surface monitoring (ASM)
  • Critical patch management and vulnerability alerts across your technology stack
  • Review of security logs and incidents (SIEM lite or integration with your SIEM)
  • Incident response: forensic analysis, containment and recovery
  • Awareness: ongoing training and quarterly phishing simulations
  • Regulatory compliance review: NIS2, DORA, ENS, ISO 27001
  • Annual pentesting included depending on the service tier

How the service works

  1. Onboarding: Asset inventory, review of existing configurations and definition of the 12-month security plan.
  2. Continuous monitoring: Attack surface surveillance, critical vulnerability alerts and anomaly detection.
  3. Monthly cycle: Incident review, vulnerability management, monthly status report and follow-up meeting.
  4. Incident response: IR protocol activated in under 4 hours for a critical incident. Forensic analysis, containment and recovery.
  5. Quarterly review: Progress assessment, security plan update and phishing simulation.

Monthly deliverables

  • Real-time security posture dashboard
  • Monthly vulnerability and program status report
  • Critical alerts with guaranteed response SLA
  • Quarterly phishing and awareness report
  • Annual regulatory compliance report
  • Annual pentesting with full technical report

Who this service is for

  • SMBs with no IT/security department that need to comply with NIS2
  • SaaS startups with investors demanding formal security controls
  • Companies that have suffered an incident and want to prevent the next one
  • Organizations subject to DORA with continuous ICT risk management requirements
  • Companies pursuing ISO 27001 certification that need ongoing technical support

Frequently asked questions

What's the difference between an MSSP and an IT maintenance contract?

An MSSP focuses exclusively on security: threat detection, vulnerability management, incident response and regulatory compliance. We don't manage infrastructure or end-user support.

What's the SLA for incident response?

For critical incidents, the initial response time is under 4 hours. For high-impact incidents, we guarantee forensic analysis begins the same day.

Does the service include the annual pentest?

Yes, mid and top-tier plans include an annual pentest with an agreed scope. It's the ideal combination: continuous monitoring plus periodic offensive assessment.