Small & mid-sized business

Enterprise-grade defence, without an enterprise security team

Attackers do not scale their tooling down for smaller companies — they scale their targeting up, because you run the same cloud services with a fraction of the staff. Guardian Sentinel Essentials gives you the detection engine that protects the Fortune 100, the SOC that watches it around the clock, and a single per-endpoint price with nothing bolted on afterwards.

  • Deploys in an afternoon
  • 24/7 managed response included
  • No SIEM required
  • Cyber-insurance ready
46% Of all breaches now hit organisations with fewer than 1,000 employees And the share has risen for six consecutive years
1.7 Median size of the security team at a 400-person company Usually one person, part-time, also running IT
$180k Median direct cost of a ransomware incident at a mid-sized firm Before downtime, legal fees and customer attrition
3 hrs Median time from contract to full Guardian Essentials coverage Across 2,400 deployments under 500 endpoints

The honest position

You are not under-protected because you are careless

You are under-protected because the security market sells you eleven products that each assume you have someone to operate them. The cost is never the licence. The cost is the person who has to read what it produces at 2 a.m.

See how managed response works
TYPICAL STACK Antivirus Email filtering Firewall management Patch tool Backup console Password manager audit Awareness training vendor 1 vendor 2 vendor 3 vendor 4 vendor 5 vendor 6 vendor 7 ≈ 22 hrs / week Administration, alert review, chasing renewals. Nothing correlated. SENTINEL ESSENTIALS One agent Prevention, EDR, rollback, device control One console Endpoints, identity, email, cloud, network One contract Per endpoint, per month, everything included One team watching Guardian MDR holds the queue, 24/7/365 One number to call Named engineer, not a ticket carousel Backup and awareness training integrate rather than duplicate — keep what works. ≈ 2 hrs / week Reviewing what Guardian already investigated and decided.
Reported administration time before and after consolidation, averaged across 180 Essentials customers between 50 and 500 endpoints.

Bundled essentials

Everything in one licence, because unbundling is how gaps happen

Guardian Sentinel Essentials is not a cut-down engine. It is the same detection platform enterprise customers run, with the operational complexity removed and sensible defaults applied on your behalf.

Endpoint protection & EDR

Behavioural prevention for Windows, macOS, Linux, iOS and Android — including ransomware rollback that restores encrypted files from a local shadow store without touching your backup. One agent, no separate antivirus, no exclusion spreadsheet to maintain.

Endpoint security

Identity & email protection

Guardian connects to Microsoft 365 or Google Workspace in minutes and watches the things that actually cause small-business breaches: impossible-travel logins, mailbox rules that quietly forward invoices, MFA fatigue attacks, and the finance mailbox that just received a very convincing bank-detail change.

Identity protection

24/7 managed detection

Guardian's SOC watches your environment continuously with a 3-minute response SLA. They contain what needs containing, and they call you — a named engineer, on the phone — when something requires a decision only you can make. Included, not an upsell.

Managed detection & response

Cloud & SaaS posture

Connect your AWS, Azure or Google Cloud account read-only and Guardian tells you what is exposed to the internet, which storage bucket is public, which key has not been rotated since 2021, and which OAuth app a departing employee left holding access to your CRM.

Cloud security

Network & device discovery

A lightweight discovery role on one existing machine per site inventories everything on the network — including the printer with a web interface on the internet and the NAS running firmware from 2018 — and flags what should not be there. No appliance to buy or rack.

Network security

Reporting & insurance evidence

A monthly one-page summary written for a board or an owner, plus the specific control evidence cyber insurers ask for: MFA coverage, EDR deployment percentage, backup verification, patch currency and mean time to respond. Generated, not assembled.

See the datasheet

Fast time-to-value

Protected the same day, not the same quarter

The median Guardian Essentials deployment reaches full coverage in three hours. There is no appliance, no professional-services engagement, and no six-week tuning phase — the defaults are the ones Guardian's own SOC would set.

DAY ONE 00:00 00:20 00:50 01:30 02:20 03:00 Tenant created Agents deployed Email connected Cloud connected Estate visible MDR live SSO linked, admins invited, policy defaults applied Pushed by Intune, Jamf or a script. No reboot needed. Microsoft 365 or Google Workspace, read plus respond. AWS, Azure or GCP read-only role via a supplied template. Assets, identities, exposures and the first risk summary. Guardian SOC takes the watch with a 3-minute SLA. No appliance · no professional services fee · no tuning phase · migration from an existing agent is handled in place, with no coverage gap.
The onboarding sequence Guardian runs with you on a single shared call.

Migration without a gap

Guardian installs alongside your current antivirus, verifies coverage, and removes the old agent afterwards using the vendor's own uninstall routine. Nobody is ever unprotected during a cutover, including the machines that were switched off that week.

Sensible defaults, editable later

Policies ship in a prevention-first configuration that Guardian's SOC maintains centrally. You can override anything, but you do not have to decide anything on day one to be protected.

Remote and hybrid by default

Protection follows the device, not the office. There is no VPN requirement, no on-premise management server, and a laptop on hotel Wi-Fi is exactly as covered as one at a desk.

Managed options

Choose how much of this you want to touch

Three ways to run Guardian, with the same platform underneath. Move between them without migrating anything — the difference is who holds the console and who answers the phone at 3 a.m.

Guardian delivery models for small and mid-sized organisations, and what each one expects of your team.
What you get Self-managed Guardian MDR Through a partner MSP
Best for An internal IT team that wants control and has capacity Companies with no security staff, or one person who needs to sleep Companies who already outsource IT and want one supplier
Who reviews alerts Your team, with AI triage doing the first pass Guardian's SOC, 24/7/365, escalating with a recommendation Your MSP's SOC, backed by Guardian escalation
Response SLA Yours to define 3 minutes to first analyst action Set in your MSP agreement, typically 15 minutes
Containment authority Your administrators Delegated to Guardian within limits you approve in writing Delegated to the MSP within limits you approve
Threat hunting Not included Monthly, with a written findings report Per your MSP's service tier
Incident response Retainer available separately 40 hours of IR included each year Coordinated by the MSP, escalated to Guardian IR
Typical weekly effort 6–10 hours About 2 hours Under 1 hour

Scroll the table sideways to see every column.

Guardian works with 840 managed service providers worldwide. If you already have an IT partner, ask them — there is a reasonable chance they are already certified. See partners.

Simple pricing

One price per endpoint. Everything above is in it.

Guardian Essentials is licensed per protected endpoint per month, billed annually, with identity, email, cloud posture, network discovery, managed detection and reporting included at every tier. There is no data-ingest meter, no charge for the console, no per-module uplift and no minimum seat count above ten.

  • Servers and workstations are counted the same way — no server premium
  • Cloud accounts and SaaS connections are unmetered
  • Twelve months of searchable telemetry retention as standard
  • Price is fixed for the contract term — no renewal surprises
  • 30-day trial on your real estate, not a sandbox
Included at every tier

What is never an extra line

Ransomware rollback. Threat intelligence. The mobile agent. The API. Onboarding. Support. Software updates. The monthly board report. The cyber-insurance evidence pack.

Insurance premium reductions Fourteen cyber-insurance carriers recognise Guardian MDR as a qualifying control. Customers report median premium reductions between 12% and 21% at renewal, which for many organisations covers a meaningful share of the licence.

Straight answers

The questions smaller teams actually ask

Not the ones a datasheet answers. The ones that decide whether this is realistic for a company your size.

Read the full FAQ
We have 60 people. Are we really a target?

You are not targeted by name, which is precisely the problem — you are targeted by exposure. Automated campaigns scan for the same unpatched edge device and the same unprotected mailbox regardless of company size, and ransomware affiliates explicitly prefer smaller organisations because the payment decision is faster and the defences are thinner.

Guardian's own incident data shows the median victim under 250 employees was compromised through an internet-exposed service that the company did not know was exposed. Nobody chose them; they were simply reachable.

Will this slow down our machines?

The agent uses a median of 1.1% CPU and roughly 120 MB of memory at steady state, and performs no scheduled full-disk scan — detection is behavioural and continuous rather than periodic and disruptive. Users generally do not know it is installed, which is the design goal.

If you are replacing a legacy antivirus that runs a Tuesday-morning scan, most organisations report machines feeling faster after the migration, not slower.

What happens if something bad occurs at 3 a.m. on a Sunday?

With MDR included, a Guardian analyst is looking at it within three minutes. They take the containment actions you pre-authorised — isolating a host, killing a session, disabling an account — and then they telephone your nominated contact. A written narrative of what happened and what was done is waiting when you open your laptop.

If the incident exceeds normal containment, Guardian's incident response team engages under the 40 hours included in your licence, with a median time to containment of 47 minutes.

Our IT is outsourced. Does that complicate things?

It usually simplifies them. Guardian works with 840 certified managed service providers who can run the platform on your behalf under their own agreement, and the licence is portable — if you change providers, the tenant and its history stay yours rather than belonging to the outgoing MSP.

You can also hold the contract directly and grant your provider delegated access, which is what most organisations above 200 endpoints end up preferring.

We already pay for Microsoft security features. Is this duplication?

Partly, and Guardian will tell you where. During onboarding we map what your existing licences already cover and configure Guardian to complement rather than duplicate — many customers reduce a security add-on tier as a result.

The gap Guardian fills for most smaller organisations is not raw signal; it is that nobody is watching the signal, and that the built-in tools stop at the boundary of one vendor's products while your attack surface does not.

What does it take to leave?

An uninstall command and an export. Your telemetry is exportable in open formats for the full retention period, configuration is exportable as JSON, and the agent removes itself cleanly. There is no proprietary data format holding your history hostage and no exit fee.

We would rather you stay because renewal is obvious than because leaving is painful.

I am the IT department. All of it. Guardian phoned me at 04:12 to say they had isolated a machine in our Leeds office and I did not need to do anything until morning. That call is the entire product as far as I am concerned.

Sarah Pemberton
IT Manager, 140-person engineering consultancy

We replaced four products with one and our security spend went down 18%. That was not the goal — the goal was to stop having four dashboards nobody looked at — but it made the board conversation considerably shorter.

Diego Marroquín
Operations Director, regional logistics firm

Our insurer asked for MFA coverage, EDR deployment percentage and mean time to respond. Previously that was a fortnight of screenshots. Now it is a report I generate before the meeting starts.

Keiko Nakamura
Finance Director, 320-person manufacturer
2,400+ Organisations under 500 endpoints running Guardian Essentials
3 min Managed detection response SLA, included at every tier
97% Annual gross renewal rate in the sub-500-endpoint segment
12–21% Reported cyber-insurance premium reduction at renewal

Try it on your real environment for 30 days

Full product, full managed detection, no sandbox and no credit card. If Guardian finds nothing in your estate worth acting on, you will have learned something valuable and it will have cost you an afternoon.