Guardian professional services

Expert hours, on your side of the console

Technology closes part of the gap. The rest is people who have run this before — 1,180 practitioners across managed detection, incident response, offensive testing, compliance and security architecture, delivering in 31 languages from nine regional hubs.

Average time from engagement to containment: 47 minutes

1,180 Practitioners across six service practices
3,400+ Engagements delivered in the last 12 months
9 Delivery hubs on a follow-the-sun rotation
96% Engagements delivered on or ahead of the agreed date
4.8 / 5 Average post-engagement customer rating

The catalogue

Six practices, one delivery standard

Every service below is delivered by Guardian badged staff against a published statement of work, a named engagement lead and a defined acceptance test. No unnamed subcontractors, no open-ended time and materials.

Managed detection & response

A 24 / 7 / 365 SOC that watches your Sentinel tenant, triages every alert, and takes pre-authorised containment action on your behalf inside a three-minute acknowledgement SLA.

  • Full-service or co-managed night and weekend cover
  • Named shift leads and a monthly service review
Explore MDR

Incident response

Retained and emergency breach response. Forensics, containment, eradication, recovery and the written record your regulator, insurer and board will each want in a different format.

  • 15-minute callback on a declared major incident
  • Retainer hours convert to proactive work if unused
Explore incident response

Security consulting

Programme-level advice: maturity assessment, security architecture review, zero-trust roadmap and cloud migration security — costed, sequenced and defensible to your board.

  • Benchmarked against 6,800 peer organisations
  • Deliverables you own outright, in editable source
Explore consulting

Penetration testing & red team

Adversary simulation graded to your maturity: scoped application and infrastructure tests, full-scope red team, and purple-team exercises run shoulder to shoulder with your defenders.

  • CREST and OSCP-certified operators only
  • Free retest of every finding within 90 days
Explore offensive testing

Compliance advisory

Readiness, evidence and audit support for PCI DSS 4.0, HIPAA, DORA, NIS2, ISO 27001, SOC 2 and FedRAMP — mapped once to a single control set instead of five times over.

  • Gap analysis, remediation plan and evidence pack
  • Auditor liaison through certification
Explore compliance advisory

Security training

Analyst certification on the Sentinel platform, hands-on detection engineering labs, incident-commander drills and workforce awareness programmes that measure behaviour change.

  • Four certification tracks, live or self-paced
  • Private cyber-range instances for team exercises
Explore training
Deployment and onboarding are included, not sold Every Guardian subscription includes a funded deployment engagement sized to your estate: architecture design, phased rollout plan, policy baseline, integration build and analyst enablement. Professional services begin where that ends. See what onboarding covers.

Engagement models

Buy the shape of help you actually need

The same practitioners are available four ways. Most enterprises run two or three models simultaneously — a retainer for the unexpected, a project for the planned, and a residency for the continuous.

Contracted hours, held in reserve

You buy a block of practitioner hours and a contracted response time. Legal terms, data-handling agreements, evidence-handling protocol and escalation contacts are all signed in advance, so the first hour of a real incident is spent on the incident rather than on procurement.

Unused hours do not expire silently. They convert to proactive work — threat hunts, tabletop exercises, detection engineering or playbook development — at the quarter boundary, with your approval on how they are spent.

  • Annual commitment from 40 to 2,000 hours
  • 15-minute callback on a declared major incident
  • Pre-approved by 14 major cyber-insurance carriers

Best fit

Organisations with an internal security function that need surge capacity and a rehearsed path to expert help.


Typical shape

12-month term · quarterly true-up · named engagement lead · two rehearsals per year included.

See retainer tiers

A defined outcome, a fixed price

Scope, deliverables, acceptance criteria and price agreed before work starts. Change requests are priced and approved in writing rather than absorbed quietly into the timeline. If we mis-scope it, that is our commercial risk, not yours.

Projects run against a published delivery method with a mid-point checkpoint, so you see draft findings while there is still time to act on them rather than receiving a surprise on the final day.

  • Two to sixteen weeks, typical duration
  • Written acceptance test agreed at kick-off
  • All deliverables in editable source, owned by you

Best fit

Assessments, penetration tests, architecture reviews, compliance readiness and zero-trust roadmaps.


Typical shape

Fixed fee · 3 milestones · mid-point findings readout · 90-day free retest on offensive work.

See consulting scopes

We take a shift, you keep the mandate

Guardian's SOC covers the hours your team cannot — overnight, weekends, public holidays, or the eight weeks of the year your senior analysts are on leave. Handover is structured: a written shift report, open investigation state and any action taken under your pre-authorised playbooks.

Authority is explicit. You decide, per asset group, whether we may isolate a host, disable an account or roll back a change without waking someone up — and that boundary is enforced by the platform, not by convention.

  • Shift patterns from nights-only to full 24 / 7
  • Your analysts see every action we take, in real time
  • Monthly service review with tuning recommendations

Best fit

Established security teams that cannot economically staff three shifts, or that need coverage across new time zones after an acquisition.


Typical shape

12- or 36-month term · per-endpoint pricing · 6-week onboarding · quarterly purple-team validation.

See MDR coverage

A Guardian engineer inside your team

A named practitioner works within your organisation two to five days a week for six months or more — attending your stand-ups, sitting in your change advisory board, and building detections against your applications rather than generic ones.

Residents are deliberately rotated out with a documented handover. The goal is a capability your team keeps, not a dependency you rent indefinitely.

  • Detection engineering, threat hunting or architecture profiles
  • Backed by the full Guardian practice behind them
  • Knowledge-transfer plan agreed in month one

Best fit

Enterprises building an internal capability under time pressure, or standing up a new regional SOC.


Typical shape

6–24 months · 2–5 days per week · on-site or embedded remote · named deputy for continuity.

Discuss a residency

Delivery methodology

The same five phases, whatever we are engaged to do

Guardian Delivery Method is the standard every practice runs against. It exists so that a red team in Frankfurt and a compliance readiness in Singapore feel like the same company — and so that you always know what happens next.

guardian delivery method › v4.2
01 02 03 04 05 Frame Discover Analyse Deliver Sustain Days 1–3 Weeks 1–3 Weeks 3–5 Weeks 5–7 Ongoing Objectives, scope and rules of engagement signed. Telemetry, interviews, config review and hands-on testing. Findings validated, risk-ranked and costed to remediate. Readout, written report and working session with owners. Retest, metrics and the next engagement recommendation. SOW + RoE Evidence set Risk register Final report Retest record Findings feed the next cycle’s scope

You always know the state

A live engagement dashboard shows phase, percentage complete, open questions and any blocker sitting on your side. No weekly-status-email archaeology.

Findings arrive early

Anything critical is reported within four hours of discovery, under an agreed out-of-band channel. Nothing severe waits for the final report.

Remediation is priced

Every recommendation carries an effort estimate, an owning function and a sequencing note, so the report becomes a plan rather than a list.

Measured outcomes

What changes after the engagement ends

Guardian measures every service against a baseline captured before work starts and re-measured 90 days after handover. The figures below are medians across 3,400 engagements delivered in the last twelve months.

Baseline first, always If we cannot measure the starting position, we say so and adjust scope. An engagement that cannot prove its own effect is an expense, not an investment.
Read the full case studies

Median performance, before engagement vs. 90 days after

Before 90 days after Mean time to detect Mean time to respond Unresolved critical findings Audit evidence preparation 74 hours 4 hours 31 hours 2 hours 118 open 19 open 26 days 4 days

Who shows up

Badged practitioners, not a bench of names

Guardian does not subcontract delivery. Every practitioner on your engagement is a Guardian employee, background-checked to the standard your sector requires, and cleared for the jurisdictions your data sits in.

340 SOC analysts across nine delivery hubs Tier 1 through threat hunting
210 Incident responders and digital forensics examiners GCFA, GCFE and EnCE certified
185 Offensive security operators CREST, OSCP, OSEP and OSWE
445 Consultants, architects and compliance specialists CISSP, CISM, CCSP and ISO 27001 LA

Clearances and vetting

Guardian maintains cleared personnel pools for US federal work (Public Trust through Top Secret), UK SC and DV, NATO Secret, and the local equivalents in Australia, Canada, Germany and Singapore. Sector-specific vetting — financial services screening, healthcare privacy training, and OT-safety certification for plant environments — is applied by default, not on request.

How we vet and secure our own people

Follow-the-sun delivery

Delivery hubs in Austin, Ottawa, São Paulo, London, Frankfurt, Dubai, Bengaluru, Singapore and Sydney provide continuous cover with local-language service in 31 languages. Engagements are anchored to a single hub for accountability, with a named deputy in the adjacent time zone so nothing stalls overnight.

See global SOC coverage

The retainer paid for itself in the first ninety minutes. We had a name, a number and a signed data-handling agreement already in place — no procurement, no NDA scramble, just responders on a bridge.

Dilan Karaca
Head of Cyber Defence, European logistics group

What I value is that the consulting report was actually costed. I could take it straight to the finance committee instead of translating twenty findings into a budget request myself.

Priya Anand
CISO, regional healthcare network · 14 hospitals

Practical questions

Before you scope anything

Do we have to be a Guardian platform customer?

No. Incident response, penetration testing, compliance advisory and consulting are all available to organisations running any security stack. Our responders and consultants work routinely with Microsoft Defender, CrowdStrike, SentinelOne, Splunk, Elastic and Chronicle environments.

Managed detection and response is the exception — it is delivered on the Sentinel platform, because the SLA depends on the response actions the platform makes possible.

How fast can an engagement start?

Emergency incident response begins immediately: a responder is on a bridge within 15 minutes of a hotline call, and remote forensics typically starts inside the first hour. Retainer holders skip the contracting step entirely.

Planned work — assessments, tests, roadmaps — normally starts two to four weeks after signature, driven mostly by your own change-window and access-provisioning timelines rather than by our availability.

Who owns the deliverables and the data?

You do. Reports, detection content, playbooks, architecture diagrams and scripts produced during an engagement are delivered in editable source and assigned to you outright. Guardian retains no exclusivity over anything written for your environment.

Evidence collected during an engagement is held in your assigned residency region, under a documented chain of custody, and destroyed or returned on a schedule you set in the statement of work.

How is pricing structured?

Retainers are priced on committed hours and response tier. Projects are fixed-fee against an agreed scope. Co-managed operations are priced per protected endpoint and identity, on a 12- or 36-month term. Residencies are priced per named practitioner per day.

Every quote itemises what is included, what is explicitly out of scope, and the rate that would apply to additional work. See platform pricing for how services combine with a subscription.

Can you work under our security clearance or regulatory constraints?

Yes. We routinely deliver under FedRAMP boundary rules, ITAR restrictions, EU-only staffing requirements, works-council agreements limiting personal-data visibility, and financial regulators' third-party oversight regimes including DORA. Constraints are captured in the rules of engagement during the Frame phase and enforced through scoped platform access.

What happens if an engagement finds something critical?

Critical findings are reported to your nominated contact within four hours of validation, over a pre-agreed out-of-band channel. If the finding indicates an active compromise, the engagement pauses and our incident response practice is offered immediately — retainer holders draw on existing hours without a new contract.

Tell us what you are trying to change

Scoping calls are run by the practitioners who would deliver the work, not by a sales engineer reading a datasheet. Thirty minutes is usually enough to tell you whether we are the right answer.