Sentry CTO

Sentry Protect

A technology partner looking after the whole of it.

Security running around the clock, support for everyone who needs it, and someone thinking a year ahead about what your business will need next. New systems planned and implemented properly rather than bolted on.

Most of it is invisible on a good day. That is the point, and it is also why it is difficult to sell: you are buying the absence of problems you would otherwise have had.

New to this? Start with the plain-language overview of what managed IT services include and what cybersecurity services cover.

First, the honest part.

You cannot buy this without an assessment first. Not as a sales technique, because we would be guessing at what you need, and you would have no way to evaluate whether the number was fair.

You should also know what the support hours actually are. Security monitoring and response runs 24/7/365. The help desk is 8am to 5pm, Monday to Friday. Urgent issues outside those hours reach someone. We would rather tell you that plainly than advertise round-the-clock support and let you discover the distinction during an incident.

What is included

Eight layers, and why each one is there.

Most of these only work as a set. Endpoint protection without identity control, or backups without monitoring, produces a sense of coverage that is arguably worse than knowing you are exposed.

01

Identity and access

Multi-factor authentication everywhere, enforced rather than encouraged. Role-based access so people reach what their job requires and not the rest. Managed password vaulting. Conditional rules that challenge sign-ins which do not look like your business.

Stolen credentials are how most attacks on businesses your size actually begin.

02

Endpoint protection and control

Behavior-based protection on every computer and server, backed by application control so unapproved software cannot execute in the first place. Administrator rights removed from day-to-day accounts, with a process for the times someone genuinely needs them.

Antivirus recognises what is already known. Control decides what is allowed to run at all.

03

24/7 monitoring and response

A security operations center watching your environment continuously, with analysts who investigate and contain rather than forwarding you an alert. Cloud application activity monitored alongside the network, because that is increasingly where the incident happens.

The median attacker sits inside a network for months. Detection speed is most of the outcome.

04

Email security

Filtering that inspects inside the mailbox rather than only at the perimeter, catching internal messages from an account that has already been taken over. Encryption and archiving where you need them.

Email is the entry point for most incidents and the mechanism for nearly all payment fraud.

05

Backup and recovery

Automated backup of servers, endpoints, and cloud data including Microsoft 365, which is not backed up by Microsoft in the way most people assume. Restores tested on a schedule, with documented recovery times rather than hopeful ones.

An untested backup is a hypothesis, and ransomware specifically targets backups first.

06

Network security

Actively managed firewalls with current subscriptions, segmentation so guests and untrusted devices cannot reach business systems, and continuous monitoring rather than a device that was configured once.

A firewall with lapsed subscriptions still shows a green light.

07

People

Security awareness training with simulated phishing, tracked so you can see who is improving and who needs help. Onboarding and offboarding processes that actually run, so accounts stop existing when people leave.

Most successful attacks begin with a person, and this is the only risk that improves with practice.

08

Policy, evidence, and oversight

Written information security policies, an incident response plan naming who does what, and quarterly reviews with real reporting. The documentation an insurer, auditor, or client security questionnaire will ask for.

Security you cannot evidence does not count when someone with authority asks.

We describe our stack by capability rather than by product name. If you are evaluating us against another provider and want to compare specific tools, ask on the call and we will tell you exactly what we deploy.

The service itself

What the relationship looks like.

Unlimited means unlimited. We do not bill by the ticket, which means we have no incentive to leave problems in place and every incentive to fix root causes. When a client's queue is short, that is the model working.

Genuinely urgent issues get worked immediately rather than queued behind whatever arrived first. We keep the queue deliberately short and hire ahead of need rather than after it.

“I really, really appreciate all of the help that Sentry CTO has provided for all of my tech-related issues. I have never submitted a ticket that took longer than 15 minutes for a response, and I always receive top-notch, professional, and friendly service from everyone there. Tech issues are never fun, but Sentry CTO makes them significantly less stressful, since you know any that come your way will be solved quickly and painlessly.”
Ricardo

Included in the monthly fee

  • Unlimited remote support
  • Unlimited on-site support
  • Unlimited consulting and advice
  • Help desk, 8am–5pm Mon–Fri
  • 24/7 security monitoring and response
  • Vendor management on your behalf
  • Technology lifecycle planning
  • Quarterly security reviews
  • Documentation kept current
  • Onboarding and offboarding processes

Billed separately

  • Hardware you buy. We manage procurement, you own the equipment
  • Major projects: office moves, new locations, application migrations
  • Network equipment and business phone service, as add-ons
  • One-time onboarding, roughly one month of the service fee

The next step

It starts with the assessment.

Thirty days, a written report, and a briefing to your leadership. Then a number derived from what is actually there rather than from your headcount.

No pitch on the first call. If we are not a fit, we will say so and point you somewhere better.