Charter Technology Solutions
Managed Cyber Protection

Security operations, run for you, around the clock

Managed Cyber Protection is the service where Charter Technology Solutions owns the day to day security work: watching for threats, responding when one appears, training your staff, protecting your email, backing up your cloud, and finding the weak spots before someone else does.

Charter Technology Solutions  ·  Mission Critical IT  ·  charterts.com

What the service is

Most organizations already own some security tools. What they usually do not have is someone whose job it is to watch those tools at two in the morning, decide whether an alert is real, and act on it before it spreads.

That is what Managed Cyber Protection provides. CTS deploys the stack, monitors it continuously, investigates what it sees, and takes action on your behalf. You get a security operation without having to hire, staff, or run one.

It layers onto whatever IT arrangement is already in place. Where CTS already manages your IT, this adds the security operation on top of what is running today, using the inventory and the access that already exist. Where someone else manages it, in house or another provider, Managed Cyber Protection sits alongside them without taking over the help desk.

Managed devices, network equipment and a security plan on a desk

One team, watching continuously

Security work fails quietly. An alert fires into an inbox nobody owns, a backup runs for months without a restore test, a policy is written once and never opened again.

The value of a managed program is not the tooling. It is that someone is accountable for the watching, every day, and reports on it.

What is included

Five components, delivered as one program and priced per user and per site. There are separate education and business tiers.

Managed Detection and Response

Continuous monitoring of endpoints, cloud and identity, watched 24/7 by a security operations team. When something real is found, it is investigated and contained rather than forwarded to you as an alert.

Ninety days of security log history is standard, which is what makes it possible to answer how far an incident reached and when it started.

Security awareness training

Ongoing training for staff, with simulated phishing so the training is measured against real behavior rather than completion rates. Results are reported back to leadership.

Advanced email protection

A protection layer above what your mail platform does on its own, aimed at the attacks that get through: credential harvesting, impersonation of leadership, and invoice and payment fraud.

Managed cloud backup

Independent backup of the data living in your cloud tenant, including mail, files and shared drives, so a deletion, a ransomware event or a departed account is recoverable.

Vulnerability management

Regular internal scanning for missing patches, weak configuration and exposed services, with a review that turns the findings into a short list of what to fix next.

Incident response planning

A written plan naming who decides, who is called, in what order and on what clock, so the first hour of a real incident is not spent deciding who is in charge.

How it gets stood up

The program starts with a scoped implementation, then settles into a recurring service.

  1. ScopeWe agree what is in the estate: users, sites, devices, cloud tenant, and what security tooling you already own and pay for. Anything you already have that covers a component, we configure rather than replace.
  2. DeployAgents go out to managed devices, the cloud and identity connectors are attached, mail protection is put in line, and backup is turned on. This is delivered as a defined project with a start and an end.
  3. TuneThe first weeks are spent removing noise so that an alert that reaches a human means something. Training and phishing simulation start in this window.
  4. RunCTS owns the monitoring, the response, the training cycle, the backup checks and the vulnerability reviews from that point on, and reports back to you on a regular cadence.

Protection and advisory are two different jobs

Managed Cyber Protection is the operational half. Managed Cyber Advisory is the governance half. They are sold separately and many organizations take one before the other.

Managed Cyber Protection

Runs your security operations

  • Detection and response, 24/7
  • Staff training with phishing simulation
  • Email protection above the platform default
  • Cloud backup of tenant data
  • Vulnerability scanning and review
  • Priced per user and per site
Managed Cyber Advisory

Owns your policies and risk posture

  • Twenty or more written security policies, branded to your organization, built and maintained
  • A risk register with tracked exceptions
  • A scheduled review of that register with your leadership, quarterly or monthly by tier
  • Included advisory time each year for the questions that come up
  • At the higher tier, an assigned cybersecurity advisor and an annual risk assessment
  • Priced as a flat monthly program

The two are complementary rather than sequential. Advisory produces the written record that boards, auditors and cyber insurers ask for. Protection produces the monitoring and the response that closes what the record finds.

A la carte

Every component can be bought on its own. The bundle exists because the pieces reinforce each other, not because they are locked together.

ComponentHow it is counted
Managed Detection and ResponsePer user
Managed Detection and Response, Core tierPer user
Managed security awareness trainingPer user
Managed advanced email protectionPer user
Outbound email protection and data loss preventionPer user
Managed cloud backupPer user, plus storage
SaaS managementPer user
Internal vulnerability managementPer asset
Internal vulnerability management, quarterly reviewPer quarter
Extended security log retention beyond ninety daysPer month
Incident response plan developmentOne time

Components carry their own one time implementation where one applies. Current pricing for any line above is available from your CTS team.

What the service needs from you

Worth knowing before a first conversation, because two of these decide what is deliverable.

School network switches, access points and managed laptops

Coverage follows the estate

What can be protected is decided by what can be reached: the devices under management, the cloud tenant your organization administers, and the network the two run across.

Where CTS already manages the estate, that inventory exists and scoping is quick. Where it does not, establishing it is the first piece of work.

Managed devices for endpoint coverage

Detection and response on a laptop or desktop requires an agent on that machine. Where staff work entirely on personal devices, the endpoint components cannot be delivered there, and we will say so rather than quote around it. The cloud and identity components still apply.

An administered cloud tenant

Email protection, cloud backup and log retention attach to a tenant your organization administers. Where accounts sit outside one, that has to be settled first.

An honest inventory of what you already own

Many organizations are already paying for a capability they have not turned on. Where that is the case, the right answer is configuration, not a second license, and we would rather find that in scoping than after a signature.

For an organization CTS already supports, much of this is on record and the conversation starts from what is actually deployed.

The question underneath all of this

Sachin Gujral, Chief Executive Officer, Charter Technology Solutions

Choosing between managed and professional services is really an ownership question: who owns IT after go live. A service owner closes the ticket when the user can work again, not when a response is sent.

Most security problems are ownership gaps rather than tooling gaps. An alert fired and nobody was assigned to read it. A backup existed and nobody verified it. A policy was written once and never reviewed.

Managed Cyber Protection is CTS taking ownership of that recurring work, with a named team and a reporting cadence, so the answer to who is watching is a person and not a product.