Skip to content
DefendGen

FAQ

Questions we get before the first invoice.

These are the questions prospective clients actually ask us, answered directly. If yours is not here, email contact@defendgen.com and we will answer it and add it.

Do you replace my IT company or MSP?

No. We work alongside them. Your IT provider keeps your systems running; we watch them for attacks and handle what we find. Most of our work with an existing MSP is a short weekly exchange: we tell them what needs patching or reconfiguring, they do it, and we verify it closed. If you do not have an IT provider we will still deliver the service, but we will not become your help desk.

What happens the moment you detect something?

An analyst picks it up and verifies it before you hear from us, so you are not woken for a false positive. If it is real we contain it, which usually means isolating the endpoint or disabling the account, then we call your escalation contact. You get a written summary of what happened, what we did, and what you need to do next. Verified alerts reach you within one hour of detection, at any hour of the day.

How long does onboarding take?

The Falcon agent is deployed on day one and is a single lightweight install that does not interrupt anyone. Weeks one and two are tuning: we learn what normal looks like in your environment, cut the noise, and agree escalation contacts and procedures with you. Full 24/7 coverage begins from there. Most clients are fully operational inside three weeks.

What are the contract terms?

Month to month. There is no annual lock-in and no cancellation penalty. Penetration testing is scoped and quoted separately as a fixed-fee engagement rather than billed monthly.

How small is too small?

Our plans are built from fifteen endpoints upward, and $800 per month is the floor. If you have fewer than fifteen endpoints we will still take you on at that minimum. Many dental practices, law firms, and accounting offices sit exactly there. Above two hundred endpoints or across multiple sites, we price per environment.

Will hiring you make my business HIPAA or SOC 2 compliant?

No provider can do that, and you should be cautious of any who says otherwise. What we do is monitor the controls those frameworks require and produce the evidence an auditor asks for. The certification itself is issued by your auditor or assessor. What we remove is the scramble to assemble evidence at renewal time.

Do I get a real person, or a ticket queue?

From the Professional plan upward you are assigned a named analyst who knows your environment, joins your review calls, and owns the relationship. On Essential you reach the same SOC team, and every alert is still reviewed by a human before it reaches you. There are no account managers between you and the analysts.

Where is your security operations centre?

In Pakistan, nine to ten hours ahead of US time zones. That is deliberate. US overnight hours, when a large share of attacks land, fall in the middle of our staffed working day, so a 2 a.m. alert on your side is handled by an analyst who is awake and on shift rather than paged out of bed. Client calls and reviews are scheduled during US business hours.

Is penetration testing included in a monthly plan?

It is scoped and quoted as a separate engagement, because the work and the price depend entirely on what is in scope. The Premier plan includes one annual test. Any client can commission a test at any time whether or not they are on a monthly plan.

What does the free risk assessment actually involve?

A 45 minute call in which we review your identity, endpoint, email, and backup controls against the requirements cyber insurers check. Within five business days you receive a written scorecard and a 90 day roadmap. It is yours to keep and act on whether or not you engage us, including if you hand it to another provider.

What reporting do I get?

A monthly briefing written for business owners rather than security engineers: what was blocked, what was found, what it means, and what to fix next. It is built to be readable by your leadership and acceptable to your insurer at renewal. You can see the format on our sample report page before you commit to anything.

Compliance and vendor review questions

If you are running a vendor security review, or you need to know how we handle data before you can take the next call, see the trust and security page or email contact@defendgen.com and ask directly. We answer these in writing.

Still deciding?

The risk assessment costs nothing and the report is yours to keep. It is the cheapest way to find out whether you need us.

Get Your Free Risk Assessment