Services

Security Monitoring and Managed Detection for UK SMEs

Security tools generate thousands of alerts. Almost all of them are noise. We take on the job of separating the two, and contacting you only when something real is happening.

SOURCES
Microsoft 365, Endpoints, Firewall, Cloud
COVERAGE
Business Hours, with Out-of-Hours Escalation
ALERTING
Human-Verified — No Automated Spam
REPORTING
Monthly Review with Your Named Consultant
In short

What is managed security monitoring?

Managed security monitoring is an outsourced service that collects security signals from your endpoints, email and cloud accounts, filters out the noise, and alerts you when something genuinely suspicious happens — such as a sign-in from an unexpected country or ransomware behaviour on a laptop.

Making sense of what you already own

Most small businesses already generate more security data than they realise. Microsoft 365 records every sign-in, every mailbox rule, every file share. Endpoint protection records every blocked file and every suspicious process. Your firewall logs every connection. Almost none of it is ever looked at.

We start there rather than by selling you a new platform. In the majority of cases the licences you already pay for contain the signals needed to catch a business email compromise or an early ransomware stage — they simply need configuring, tuning and, crucially, watching.

  • Microsoft 365 and Entra ID sign-in, audit and mailbox-rule telemetry
  • Endpoint detection and response alerts from your existing agent
  • Firewall, VPN and remote access logs
  • Cloud platform audit logs from Azure, AWS or Google Workspace

The attacks we are actually watching for

The threat model for a 30-person UK business is not a nation-state. It is business email compromise, credential theft through phishing, and commodity ransomware delivered through an unpatched remote access service. Our detection rules are built around those, because that is what turns into a real incident.

The highest-value detections are unglamorous: a mailbox forwarding rule silently created to divert invoices, a sign-in that succeeds from an impossible location, a sudden mass file rename on a file server, a new global administrator appearing at two in the morning.

  • Business email compromise — malicious inbox rules, invoice redirection, impersonation
  • Credential abuse — impossible-travel sign-ins, MFA fatigue attacks, token theft
  • Ransomware precursors — mass encryption behaviour, shadow copy deletion, tooling drops
  • Privilege abuse — new admin accounts, unexpected role assignments
  • Data exfiltration — abnormal download volumes and unusual external sharing

Honest coverage, honestly described

We are an eight-person firm in Leicester and we describe our service accordingly. Monitoring and analyst review run during UK business hours, with an out-of-hours escalation path for critical alerts and a documented response time we commit to in the service agreement.

If you need a genuine follow-the-sun 24/7 security operations centre with contractual minute-level response, we will tell you so and help you select one — we would rather refer that work than oversell it. For most SMEs, tuned detection with real human review during the day and a clear escalation route at night is both sufficient and affordable.

What you receive

Included in every engagement

Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.

Agreement Ready

Service Level Agreement (SLA) — Managed Security & IT Support

Response and resolution targets, service hours, escalation path, maintenance windows, service credits and reporting for managed support.

UK Electronic Communications Act 2000 · eIDAS (EU) No 910/2014 · SHA-256 Verified

Request This Agreement →
Frequently asked questions

Security Monitoring — your questions answered

Do we need to buy new software for security monitoring?
Usually not. Most SMEs already have the necessary telemetry in their Microsoft 365 licence and endpoint protection. We assess what you have first and only recommend additional tooling where there is a genuine blind spot.
Is your monitoring 24/7?
Analyst review runs during UK business hours, Monday to Friday, with an out-of-hours escalation route for critical alerts. We state the exact coverage and response times in the service agreement rather than implying round-the-clock staffing we do not have.
What happens when you detect something?
An analyst verifies the alert first. If it is genuine we contact your named escalation contact by phone, explain what we are seeing, and — under playbooks you have pre-approved — take containment action such as revoking sessions, disabling an account or isolating a device.
How is this different from antivirus?
Antivirus blocks known-bad files on one device. Monitoring correlates activity across your email, identity, endpoints and network to spot an attacker who is using legitimate credentials and legitimate tools — which is how most modern breaches actually unfold.
Can you monitor if we already have an IT support company?
Yes, and it is a common arrangement. We handle detection and analysis, and escalate to your IT provider for remediation under an agreed process, or take action directly if you prefer.

Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.

Ready to talk about security monitoring?

Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.