SOC Service
One managed service covering the entry points attackers actually use. Email and identity, your internet-facing estate, and the accounts already exposed elsewhere account for the overwhelming majority of real-world breaches - on most estimates around 80% - so that is where we concentrate: your Microsoft 365 tenant hardened and watched, your attack surface mapped and tested, and every resulting alert triaged by an analyst rather than ignored. Delivered on platforms we build and operate ourselves - CA/CR® ReconX and CA/CR® ProDesk.
Onboarding starts with a full posture and exposure baseline within 5 working days.
An incident is rarely a single alert
Breaches are seldom announced by one obvious event. They are assembled from weak signals - each of them individually unremarkable, each of them routinely dismissed. What makes them an incident is that they line up, on the same identity, within the same few days. Correlating them in time is the entire job.
-
Resource DevelopmentCredential obtainedT1589.001 · Gather Victim Identity Information: Credentials
Infostealer malware on an unmanaged personal device harvests a saved corporate password. It reaches a stealer log days later - nothing in the customer's own estate was touched, so nothing in the customer's own estate could have noticed.
Detected · ReconX Identity -
Credential AccessPassword tried at scaleT1110.004 · Brute Force: Credential Stuffing
Repeated sign-in attempts against that same account from several countries within hours. Taken alone this is the noise every tenant sees daily - which is precisely why it is filtered out of most inboxes.
Detected · Microsoft Entra ID -
Chain broken here
ProDesk correlated both signals onto one identity and one ticket. A leaked password plus live attempts against that same account is no longer ambiguous: someone holds a working credential and is working through MFA. The customer was notified the same day - credential reset, active sessions revoked, MFA methods reviewed. Everything below is what the next four stages would have been.
-
Initial AccessA sign-in finally succeedsT1078.004 · Valid Accounts: Cloud Accounts
One attempt lands. From the logs it is a legitimate user signing in from an unfamiliar city - indistinguishable from travel, and no longer a failed-login alert at all.
Never reached -
PersistenceAttacker enrols their own MFAT1556.006 · Modify Authentication Process: Multi-Factor Authentication
A second factor the attacker controls is added to the account. Access becomes durable and self-service, and survives the password reset that would otherwise have ended it.
Never reached -
Defense EvasionMailbox rules hide the activityT1564.008 · Hide Artifacts: Email Hiding Rules
Inbox rules auto-delete or divert replies and security notifications, so the account's real owner never sees the conversations being held in their name.
Never reached -
ImpactPayment redirectionT1657 · Financial Theft
Bank details are altered mid-thread on a real invoice conversation, and internal phishing goes out from a trusted mailbox that passes every authentication check. Discovery arrives weeks later, from a supplier asking where their money is.
Never reached
Contained Alert
Two dismissible signals, correlated within hours, closed as a one-hour administrative task. No incident, no notification obligation, no forensics bill.
- Exposure detected before any successful sign-in
- Both signals joined to one identity, one ticket
- Customer notified the same day
- Credential reset and sessions revoked
- Ticket closed with a full audit trail
Actual Compromise
The same two signals, left uncorrelated. Once one attempt succeeds, every following step is designed to look legitimate.
- Sign-in succeeds from an unfamiliar location - indistinguishable from travel
- Attacker-controlled MFA makes the access durable and self-service
- Mailbox rules hide the activity from the account's real owner
- Payment details altered mid-thread on a real invoice conversation
- Internal phishing sent from a trusted, fully authenticated mailbox
- Discovered weeks later by a supplier chasing payment
The specific pair of signals varies; the shape does not. A look-alike domain registered days before a phishing wave. A new exposed service appearing shortly before it is exploited. A supplier's posture degrading right before an invoice-fraud attempt. Any one of them is dismissible. Two of them, on the same entity, in the same week, is a SOC ticket.
Four pillars. One security operation.
Most SOC offerings monitor a log stream and stop there. Ours starts one step earlier - by reducing what an attacker can reach in the first place - and ends one step later, with the remediation actually tracked to closure.
M365 Security Posture
Microsoft 365 is the front door, and attackers use it as one. A single click on a phishing link - or an AI prompt-injection attack delivered by email - is enough to put someone inside your tenant. From there they do not need malware: they browse your organisation like an employee, identify the CFO, the accounting team, the CEO and whoever approves purchases, then send internal phishing to colleagues and external partners, and issue legitimate-looking invoices with the payment details changed. Every one of those messages passes authentication, because it genuinely comes from you. Hardening the tenant is what keeps that door shut.
- 100+ CIS-aligned controls checked continuously, scored and prioritised
- MFA coverage across every account - including service and break-glass admins
- Conditional Access design, review and enforcement
- Licence-to-usage mapping: dormant and over-privileged accounts
- SaaS discovery and Shadow IT - every OAuth-connected app
- Configuration drift caught as it happens, not at the next audit
M365 Security Alerts
Posture tells you the door is locked. Alerting tells you someone is trying the handle. We monitor Entra ID risk signals and tenant activity continuously, and the events that matter most are precisely the ones that look administrative rather than dramatic - a new authentication method, a new inbox rule, a consent grant. Each one is raised as a ticket with an owner and a clock, not left glowing in a portal nobody has open.
- Risky sign-ins, impossible travel and anomalous behaviour
- Failed sign-in bursts and password-spray patterns
- MFA method registration and authentication changes
- Inbox rule creation, forwarding and auto-delete rules
- Suspicious OAuth consent grants and app registrations
- Privileged role assignment and admin activity
Attack Surface Management
Everything an attacker can see from outside - domains, hosts, ports, vulnerabilities, exposed credentials, impersonating domains and the posture of your suppliers - plus the inside view from a signed agent on your Linux servers. Nine modules run continuously against your estate, and because the platform is ours rather than a reseller licence, findings flow straight into the ticket queue instead of into another dashboard.
- Domain Mapping, Discovery and Vulnerability testing
- Web Audit - around 44 configuration and content checks
- Reputation - blocklists, DMARC, look-alike domains
- Identity - breach and stealer-log credential exposure
- 3rd-Party Risk - independent supplier scorecards
- Internal Posture - vulnerability scanning and Linux health checks
Alerting & Incident Response
ProDesk is the desk our analysts actually work in. Every security signal we receive for you arrives here, is assessed by a human, and becomes tracked work with an owner and a deadline - or is closed as noise before it ever reaches you. We connect to the tools already watching your environment, and to anything that can send an email alert; connecting a source takes minutes and needs no agent on your estate. Whatever the source, alerts arrive in one consistent shape - what happened, what it affects, how serious it is, and which of your locations it belongs to - so nothing is lost in translation between vendors.
- A single queue across all your sites, with each client's data strictly separated
- Response times you can hold us to - every ticket carries a target, and we report against them
- No new accounts for your team: a secure personal link opens exactly the item in question
- A complete, permanent audit trail of every change, note and decision - exportable
- Reports on demand or on a schedule: volumes, response times and the trend across your estate
- Full desktop console, mobile, and push alerts for the things that cannot wait
Know your attack surface before attackers do
Attack Surface Management is delivered on CA/CR® ReconX - our own platform, not a reseller licence. It maps what you expose to the internet, tests it the way an attacker would, and tracks every finding through to a verified fix. Multi-entity by design: a group, its subsidiaries and its suppliers are scored separately and roll up together.
Domain Mapping
The authoritative picture of your namespace, established before anything is scanned. Ownership, registrar and expiry tracking - including the domains you depend on but never registered. DNS resolved against every authoritative nameserver rather than a recursive one, so you see what the internet sees. Certificate Transparency monitoring, ASN attribution, and email security posture - SPF, DKIM, DMARC, DNSSEC and STARTTLS - each carrying a failing since date rather than just a red mark.
Discovery
Names turned into a live asset inventory. Host resolution across the full namespace, structural subdomain discovery, and tiered port scanning with a slower full-port pass behind it. Web applications are fingerprinted per hostname, and shared SaaS or CDN infrastructure is excluded from your score - a finding on a Microsoft or Cloudflare front end describes their posture, not yours. Inventory is kept separate from scan eligibility, so everything resolved stays visible even where scanning is out of scope.
Vulnerability
The core testing engine: template-driven active scanning across web, network and service surfaces, rate-governed so testing never disrupts the target. Every finding is enriched with CVSS, EPSS, CISA KEV status, CWE and SSVC decision priority, so the queue is ordered by what is actually being exploited. Findings carry a full lifecycle - new, active, disappeared, regressed - so a fix that silently reverts is flagged rather than lost, and each triage decision leaves an audit trail.
Web Audit
Around 44 distinct checks on everything you publish. Security headers and CORS, cookie flags, exposed .git and .env files, framework debug modes and source maps, hardcoded secrets in served content, and RFC 9116 security.txt. Each check knows whether it describes the server or the published site, so an auth wall is still assessed for headers and secrets without being told it is missing a sitemap - and audits deduplicate by response, so twenty names on one server produce one set of findings, not twenty.
Reputation
How the outside world sees you, and who is pretending to be you. Blocklist and DNSBL monitoring across 16 sources through a dedicated resolver, with a test-point probe on every run so a list that is quietly refusing queries is never reported as "clean". Look-alike and typosquat detection is backed by Certificate Transparency, so an impersonating domain resurfaces the moment a certificate is issued for it - with automated screenshots flagging any use of your brand.
3rd-Party Risk
Independent, evidence-based supplier scorecards. Vendor domains are scanned in an isolated sandbox, separately from your own estate, with host-weighted scoring so a large vendor's scale cannot dilute one serious finding. Crucially, the platform refuses to publish a grade it cannot evidence - a vendor with no measurable surface is reported as exactly that, never as an "A" - and stale scorecards say so instead of repeating the last good result forever.
Identity
Credential exposure intelligence, and the signal behind the incident described above. Breach and combolist exposure per domain, stealer-log intelligence that carries infected-host context rather than just an email address, VIP and executive correlation, and detection of corporate credentials reused on external services. Severity decays with the age of the compromise, dated from the theft rather than the day we found it - and no password, masked or clear, ever leaves the platform in an alert or a ticket.
Internal Posture
The inside view, from a lightweight signed agent on your Linux servers. Distribution-aware patch status, so a backported fix is correctly recognised as a fix. Reboot-required and failed-service detection, resource thresholds with trend history, watched services and open-port baselines, file integrity monitoring by hash, and security log review. Restraint is built in: process names without command lines, no raw log line ever leaving the host, and "cannot check" treated as a finding in its own right rather than silently passing as clean.
Reports
On-demand and scheduled PDF reporting per entity, with distribution lists and time-limited external sharing for stakeholders who should not need an account. Weekly posture snapshots give auditors, boards and insurers the thing they actually ask for: not a point-in-time score, but evidence that the surface is measurably shrinking.
Scanning from both sides of the perimeter
External scanning tells you what an attacker can reach. It cannot tell you whether the server behind it is patched. Combining both is what turns a list of findings into an accurate picture of risk.
External Scanning
Unauthenticated, attacker's-eye reconnaissance of everything reachable from the internet - run continuously, with no access to your network required to get started.
- Continuous host, port and technology discovery
- CVE identification with CVSS + EPSS prioritisation
- Web application and TLS configuration auditing
- Domain, DNS, certificate and reputation monitoring
- Credential exposure from breach corpora
- Supplier and third-party posture monitoring
Internal ReconX Agent
A lightweight, signed host agent for your Linux servers. It reports authenticated posture from inside the perimeter and pairs each external finding with the real state of the machine behind it.
- Authenticated internal vulnerability scanning
- Linux server health and patch-level checks
- Exposed service and listening-port inventory
- Configuration hardening verification
- Security log review and anomalous-event reporting
- Signed installer with fingerprint-verified enrolment
One monthly fee. The whole operation.
Posture management, attack surface management and alert response in a single subscription - priced on the number of entities, users and assets in scope.
- M365 security posture - 100+ CIS-aligned controls
- MFA coverage reporting & Conditional Access enforcement
- Risky sign-in & identity threat alerting
- CA/CR® ReconX attack surface management - 9 modules
- Internal vulnerability scanning & Linux health checks
- CA/CR® ProDesk alert triage, ticketing & SLA tracking
- Remediation tracked in the CA/CR® CISO Console
- Monthly posture, exposure & incident report
Indicative starting price for a single entity. Multi-entity groups, larger estates and 24/7 coverage are quoted individually - and the ReconX and ProDesk platforms can also be licensed on their own.
Microsoft AI Cloud Partner
Pro CISO® holds Microsoft AI Cloud Partner and CSP Partner status - giving you access to the latest Microsoft security tooling and expert guidance on AI risk management within Microsoft 365 Copilot.
See your exposure before someone else does
Book a SOC review and we will walk you through your M365 posture score and your external attack surface - using your own domains, not a demo tenant.
Book a SOC Review