Proactive Monitoring, Threat Detection and Response
Most ransomware gets deployed while the building is empty. Someone has to be awake for that, and Monday morning should not be when you first hear about it.
The pattern is consistent. They get in quietly with a working login, move fast toward the systems that matter, wait, and then detonate when the building is empty.
0%
of ransomware encryption is deployed outside business hours, when nobody is at a desk to notice.
3.4 hrs
median time from breaking in to reaching Active Directory, which holds the keys to everything else.
3 days
median time an intruder sits in the environment first. That gap is the whole reason monitoring exists.
0%
of investigated incidents were rooted in an identity attack. Somebody signed in as your people.
Figures from the Sophos Active Adversary Report 2026, drawn from its incident response and managed detection casework.
The coverage
What we are actually watching
Continuous monitoring is an easy phrase to put on a page. Here is the actual list, so you can compare it with whatever you have now and find the gaps.
Every endpoint, all the time
Workstations and servers report in continuously through NinjaOne: disk and hardware health, services that stopped, patches that failed, and software that appeared without anyone asking for it. Most of what this catches is dull, which is the point. A failing drive caught on a Tuesday is a scheduled swap. The same drive caught on Saturday is an outage.
Sign-ins and identity
Who signed in, from where, and whether that makes sense. A login from two countries an hour apart, a burst of repeated multifactor prompts, a new administrator role granted at midnight, a mailbox rule created to hide replies. Identity is where most attacks now start, so it gets watched like a perimeter.
Email, and the people reading it
Phishing is still the most common way in, and the ones that work are written to look routine. What gets reported, what gets clicked, and anyone spoofing your domain are all watched. Filtering runs on Microsoft Defender for Office 365, which is already inside your Business Premium licenses. Phin runs the simulations and the short training that follows, so you can see who is improving and who needs another pass.
What holds administrator rights, and what changed
Standing local admin lets an intruder spread out from the machine they landed on, so Evo takes it away and grants elevation for the task that needs it instead. New administrator roles, changes to privileged groups and every elevation request get logged, which leaves a record of who could reach what and when.
Network and DNS traffic
Outbound requests to known command and control infrastructure, newly registered domains, and the traffic patterns that come before data leaves. Cloudflare blocks a good deal of it at the DNS layer, before anything reaches the endpoint at all.
Patch state and configuration drift
What is missing, what failed to install, and what changed. Firewalls, VPN appliances and hypervisors are included, because those are the ones that get missed, and an unpatched edge device is visible to anybody scanning for it within days of the advisory.
Disk encryption, and whether it is still switched on
BitLocker on Windows and FileVault on Mac, checked continuously, because encryption that quietly suspended itself after a firmware update protects nothing, and nobody notices until it matters. A laptop left in a car or lifted from a job site trailer is a hardware replacement when the disk is encrypted. The same laptop unencrypted is a reportable breach, with client notifications and a carrier conversation attached. We also check that the recovery keys are escrowed somewhere you can reach them, because an encrypted disk you cannot unlock is its own kind of loss.
Whether the backups would hold up
A green tick on last night's job is not the thing worth watching. We watch the retention and the immutable copy, and we watch how long it has been since anybody completed a test restore. When one of those drifts we raise it. Cove covers the servers and workstations, Dropsuite covers the Microsoft 365 or Google Workspace tenant. Why that tenant needs a backup of its own is set out on the recovery page.
What happens next
When an alert fires at 2 AM
Detection on its own changes nothing. The outcome gets decided in the first minutes after something fires, and by whether anybody is awake to act.
What we sign up to
Every night
a critical security alert reaches a Huntress analyst who is on shift at that hour, not a voicemail box. That coverage does not stop when our office does.
15 minutes
before one of our own people picks up a support ticket you raise, weekdays from 5 AM to 6 PM Pacific. That is the clock written into the agreement, and it stops when the help desk closes.
Both are written into the agreement rather than described on a web page. Ask any provider quoting you a response time whether theirs is in the contract or in the brochure.
1
The alert reaches a person on shift
Alerts go to Huntress, a security operations center staffed around the clock, every day of the year. A Huntress analyst triages it, decides whether it is real, then starts acting. Nothing waits in a mailbox for anyone to open at nine.
2
Anything dangerous gets contained first
A compromised endpoint is isolated from the network while the rest of the environment keeps running, and a compromised account is disabled and its sessions revoked. Containment happens before the conversation about what it was, because the alternative is arguing while it spreads.
3
You get a phone call
For anything that touches your data or your accounts, we call. Named people, agreed in advance, with a second and third name for when the first does not answer. Nothing that matters travels by email alone, because email is frequently the thing that got compromised.
4
Worked until it is closed, and written down
What fired, what it turned out to be, what was done, and when. Those notes answer an insurance claim or a client questionnaire later, and they tell us whether the same thing keeps happening for a reason nobody has fixed.
5
Your adviser reviews it with you afterwards
Not the alert, the pattern. Three people caught by the same style of phishing message is a training problem. The same server alerting every week is a hardware problem somebody keeps clearing and never solving.
Who you deal with
A person, not a portal
Every client gets a named adviser. Somebody who knows your environment sits down with you on a set schedule, goes through what happened since the last one and what it meant, then agrees what is worth fixing next.
Reads the pattern
One alert is an incident. The same alert three times is a decision somebody has been avoiding. The adviser notices the difference and says so.
Answers the questionnaires
When your carrier or a client sends a security questionnaire, the answers come from a person who already knows what is deployed and can show the evidence behind each yes.
Says what to fix next
A short list, in order, with what each item costs and what it buys. Nobody gets handed a two hundred item report and left to work out where to start.
What we run
The tools, by name
Naming the stack lets you check our work, hold it against what you are paying for today, and ask why anything on your invoice is missing from this list.
Detect and respond
The sensors, and the people who answer what they report.
Huntress the security operations center. Staffed detection and response at every hour, including the ones nobody wants.
Microsoft Defender for Endpoint behavioral protection on the endpoint, with isolation available on demand. Huntress analysts watch what it reports.
NinjaOne endpoint monitoring, patching and remote management across every workstation and server.
Keep them out
The controls that stop most of it before it starts.
Evo Security least privilege enforcement. Removes standing local admin and raises rights only for the job in hand.
Microsoft Defender for Office 365 mail flow filtering for phishing and spoofing. Part of Microsoft 365 Business Premium.
Cloudflare DNS and network filtering. Blocks known command and control traffic before it reaches an endpoint.
Phin Security phishing simulation and short training that repeats through the year.
Keeper password management, so credentials stop living in browsers and spreadsheets.
Protect the data
So a bad day costs you hardware instead of a breach notice.
BitLocker and FileVault full disk encryption on every Windows and Mac machine, monitored so it stays on and the recovery keys stay reachable.
Cove server, virtual machine and workstation backup, with an immutable copy.
Dropsuite backup for the Microsoft 365 and Google Workspace data the platforms do not keep for you.
V&A Consulting Engineers came down from eleven servers to two. Monitoring cost was one of the four lines the saving came off, alongside hardware, backup and downtime, because there is less running to watch. Consolidation and monitoring tend to be the same conversation.
Huntress, whose analysts are on shift at every hour of every day. We say so plainly because it matters: no firm our size can credibly staff three shifts of security analysts, and any provider claiming otherwise is worth a follow-up question. Our people own the relationship, your environment and the decisions. Huntress analysts do nothing but this, and they reach us and you when something is real.
What happens when an alert fires?
A person triages it, and if it is dangerous the endpoint or account gets contained before anything else. Then we call you, on a phone, using names agreed with you in advance. We stay on it until it is closed and write it up. Your adviser picks the pattern up at the next session.
Is this just antivirus with a new name?
No. Antivirus asks whether a file is known to be bad. This asks whether the behavior makes sense: a valid login from the wrong place, an account granting itself new rights, traffic going somewhere it has never gone before. Most incidents now involve no malware at all, so a tool that only inspects files is watching the wrong thing.
We already have Microsoft 365 Business Premium. Do we need this?
Business Premium is a good product. It includes Defender for your endpoints and your mail flow, plus Entra ID and Intune. We run those and do not sell you a replacement. A license does not include anyone configuring it properly or picking up the phone at 2 AM. Most of the tenants we take over have those tools switched on and nobody reading them. If you are already paying for the license, the first step is making it work before you buy anything else.
One of our laptops was stolen. What happens?
If the disk was encrypted and the encryption was still on, it is a hardware replacement and an insurance line item. We confirm the encryption state from the monitoring record, then wipe the device remotely if it ever checks in again. Sessions get revoked and the credentials that were on it rotated, and you get the written evidence of the encryption status at the time it went missing. Your carrier and your counsel will ask for that evidence first, and it is much easier to produce when somebody was already watching the encryption state and not assuming it.
Will this bury us in alerts we have to deal with?
The opposite is the point. Almost everything is handled without you hearing about it, and the tuning work exists so that anything reaching you needs a decision from you. If you are being paged about routine noise, the monitoring is configured wrong.