24/7 Managed Security
Security operations that never go home.
24/7 managed detection and response for US small and midsized businesses. CrowdStrike Falcon monitoring, a human analyst on every alert, and reports written for business owners.
Built on CrowdStrike Falcon
- CrowdStrike Falcon monitoring
- 24/7 human alert triage
- Monthly briefing you can actually read
- Insurance-ready evidence
Services
Seven services, delivered by one accountable team.
Managed SOC (MDR)
24/7 monitoring of your endpoints on CrowdStrike Falcon. Every alert is reviewed by a human analyst before it reaches you.
You get: alerts verified by an analyst within the hour
HuntingThreat Hunting
Scheduled, proactive hunts across your environment for attacker activity that automated tools do not detect.
You get: findings with specific remediation steps
ResponseIncident Response
Containment, recovery coordination, and full documentation for your insurer when an incident occurs.
You get: containment plus insurer-ready documentation
SIEMSIEM Assessment
Evaluation and tuning of your SIEM so that alerts are accurate, actionable, and complete.
You get: alerts that are accurate and actionable
PostureSecurity Assessment
A structured review of your security controls, mapped to insurance requirements and applicable compliance frameworks.
You get: a prioritized 90 day remediation roadmap
VulnVulnerability Assessment
Continuous scanning with analyst-prioritized remediation guidance, focused on the vulnerabilities that matter.
You get: a short, prioritized remediation list
OffensivePenetration Testing
Manual testing of your external perimeter, internal network, and business applications. We exploit what we find, then show you the full path an attacker would take.
You get: a tested report of real, proven attack paths
Getting started
How onboarding works.
01
Day 1
Deploy
We roll out the CrowdStrike Falcon agent across your endpoints. It is a single lightweight install that does not disrupt your team’s work.
02
Weeks 1 to 2
Tune
We baseline normal activity in your environment, tune detections to cut noise, and agree escalation contacts and procedures with you.
03
Ongoing
Operate
24/7 coverage begins. You receive verified alerts, a monthly briefing written for business owners, and a named analyst who knows your environment.
Your local time
DefendGen SOC. Analyst on shift.
Overnight in the US is the middle of our working day.
Our operations center runs a full staffed shift during US overnight hours. Alerts that arrive at 2 a.m. are handled by a trained analyst within the hour, every night of the year.
What actually happens
From detection to your inbox.
The question every prospect asks is what happens the moment we find something. This is the sequence, with the timings we hold ourselves to on every plan.
- 01T + 0
Detect
Falcon blocks the behaviour on the endpoint and raises an alert. Nothing has reached you yet, and nothing needs to.
- 02Minutes
Triage
An analyst on shift picks it up and decides whether it is real. Most alerts end here, which is the point of paying for people.
- 03Minutes
Contain
If it is real we isolate the endpoint or disable the account before waking anyone. Containment does not wait for your approval at 3 a.m.
- 04Within the hour
Notify
We call and email your escalation contact with what happened, what we already did, and the one thing we need from you.
- 05Next day
Report
By the next business day a written record lands with you: timeline, evidence, and the change that stops it recurring. It is built to satisfy your insurer.
Why DefendGen
What clients get here that they do not get elsewhere.
01
Human alert triage
An analyst reviews every alert before escalation. You receive fewer notifications, and each one is verified and actionable.
02
A named analyst
Each client is assigned a dedicated analyst who knows their environment, joins a monthly review call, and owns the relationship.
03
Reporting you can read
Monthly briefings state what was blocked, what was found, and what to fix next, in language your leadership and your insurer both understand.
Industries
Industries we serve.
Healthcare
Clinics, dental and behavioral health practices, and medical billing companies subject to HIPAA.
How we work with healthcare clients
Financial services
Tax preparers, CPA firms, auto dealers, and advisors covered by the FTC Safeguards Rule.
How we work with financial clients
SaaS and technology
Software companies that need SOC 2 level controls to close enterprise contracts.
How we work with saas clients
Professional services
Law, accounting, and consulting firms that handle confidential client data.
How we work with professional clients
Pricing
Straightforward pricing.
Every plan includes CrowdStrike Falcon, 24/7 human monitoring, and monthly reporting. Plans start at 15 endpoints on month-to-month terms. Final pricing depends on endpoint count and environment complexity. Penetration testing is scoped and quoted as a separate engagement.
Essential
$800/mo starting
15 to 30 endpoints
- CrowdStrike Falcon endpoint monitoring
- 24/7 SOC alert triage
- Monthly security briefing in plain English
- MFA enforcement audit
- Cyber insurance evidence package
Most popular
Professional
$1,200/mo starting
30 to 75 endpoints
- Everything in Essential
- Control monitoring and audit-ready evidence mapped to HIPAA, PCI DSS, and SOC 2
- Named dedicated analyst
- Quarterly security review call
- Incident response coordination
- Patch compliance reporting
Premier
$2,000/mo starting
75 to 200 endpoints
- Everything in Professional
- vCISO advisory hours
- Annual penetration test
- Board-level security reporting
- Annual incident response exercise
- Direct analyst phone line
Fewer than 15 endpoints?
We support small offices at the $800 per month minimum. Many dental practices, law firms, and accounting offices sit here.
More than 200 endpoints or multiple sites?
Pricing is built per environment at that size. Talk to us and we will scope it with you.
Why this costs more than a tool
You are buying analysts, not software.
Endpoint tools start around $9 per endpoint. They send alerts to you. We employ the people who read those alerts at 3 a.m., decide which ones are real, and act on them. That is the difference you are comparing.
| What you get | Tool only | DefendGen |
|---|---|---|
| CrowdStrike Falcon licensing and management | ✓ | ✓ |
| Alerts reviewed by a human before they reach you | ✕ | ✓ |
| A named analyst who knows your environment | ✕ | ✓ |
| Scheduled proactive threat hunting | ✕ | ✓ |
| Monthly briefing written for business owners | ✕ | ✓ |
| Evidence package for cyber insurance renewal | ✕ | ✓ |
| Incident response coordination included | ✕ | ✓ |
Response commitment
Every plan carries the same response target: a verified alert reaches you within one hour of detection, at any hour, on every day of the year. Premier adds a direct analyst phone line. The target does not improve with the price of your plan, because an alert at 3 a.m. is equally urgent for a fifteen person office.
Ready when you are
The DefendGen Risk Assessment.
A 45 minute review of your identity, endpoint, email, and backup controls against the requirements cyber insurers check. You receive a written scorecard and a 90 day roadmap within five business days. It is yours to keep whether or not you engage us.
- 45 minute call
- Written scorecard
- 90 day roadmap
- No obligation