Dealing with an active security incident? Call 737-305-5448 now.

Managed Detection and Response

Every protected computer runs the Huntress agent, monitored 24/7 by the Huntress Security Operations Center. When they confirm a real threat, the machine can be isolated within minutes, the threat is removed, and we follow up to close the hole it came through.

Good for: every business. This is the foundation of every plan.

What's included

  • Huntress EDR on Windows, macOS and Linux
  • 24/7 threat review by Huntress security analysts
  • Host isolation and guided removal of threats
  • Follow-up by us on every confirmed incident
  • Management of Microsoft Defender antivirus on Windows
  • Monthly summary of what was detected and handled

Identity Threat Detection and Response

Most break-ins today start with a stolen login, not malware. Huntress watches every Microsoft 365 and Google Workspace account around the clock for the signs of a takeover: logins from places that make no sense, a session token reused from another device, new inbox rules that hide mail, an MFA method added by someone else. When their analysts confirm an attack, the session is ended and the account locked before mail goes out in your name.

Price: included in Protect + Identity and up.

Good for: any business that runs its email in Microsoft 365 or Google Workspace. It pairs with endpoint protection: one covers the machines, the other the accounts.

What's included

  • Huntress ITDR on every Microsoft 365 or Google Workspace account
  • 24/7 review of sign-ins, sessions and mailbox changes by Huntress analysts
  • Sessions ended and accounts locked on a confirmed takeover
  • Follow-up by us: what was accessed, what to reset, how they got in
  • Monthly summary alongside your endpoint report

Security Hardening

Most breaches use settings that were never changed from the default. We check your accounts, devices and network against the baselines published by CISA, the U.S. Cybersecurity and Infrastructure Security Agency, then fix what matters most first.

Good for: businesses that have never had a security review, or that just had an incident.

What's included

  • Microsoft 365: MFA for everyone, legacy sign-in blocked, Conditional Access, admin roles cleaned up, external forwarding blocked, audit logging on
  • Google Workspace: 2-Step Verification enforced, security keys for admins, third-party app access controlled, Drive sharing limits, Gmail forwarding controls
  • Email authentication: SPF, DKIM and DMARC so attackers cannot easily send mail as you
  • Endpoints: disk encryption (BitLocker and FileVault), local admin rights removed, firewall and attack surface reduction settings
  • Network: firewall rule review, exposed remote access closed, guest and device Wi-Fi separated
  • Before and after report showing every change

Vulnerability and Patch Management

Unpatched software is one of the most common ways in. We patch operating systems and third-party apps on a schedule tied to risk, and scan monthly to catch what patching misses.

Price: included in Protect + Harden and up.

Good for: businesses without someone who keeps every machine up to date.

What's included

  • Automated patching for Windows, macOS and common third-party apps (browsers, Adobe, Zoom, Java and more)
  • Monthly vulnerability scan of every protected device
  • Deadlines by risk: actively exploited vulnerabilities within 72 hours, other critical ones within 14 days, everything else within 30 days
  • Rollback if a patch causes a problem
  • Monthly report of patch status and open risks

If a patch breaks an application, we roll the patch back and work with your software vendor or IT provider. We do not provide general application support.

Security Awareness Training

Your people are the other half of security. Short monthly lessons and realistic phishing tests, run through Huntress, teach your team to spot the messages that get past the filters. You see who finished what and who clicked, and nobody gets shamed for it.

Price: included in Protect + Identity and up.

Good for: every business with email. Many cyber insurance applications ask for it.

What's included

  • Short video lessons every month, a few minutes each
  • Phishing simulations with results by person
  • Reports you can hand to your insurer or auditor
  • Enrollment and reminders handled by us, not you

Incident Response

Hacked email, malware or ransomware. We contain it, clean it up, find out how it got in, and help you recover. Clients on a plan get priority response at a reduced rate.

Active incident? Call 737-305-5448

While you wait for us

  1. Don't turn off affected computers. Unplug their network cable or turn off their Wi-Fi instead.
  2. Don't delete anything or contact the attacker. Don't pay any ransom.
  3. Use a phone or an unaffected device to reach us.

Security Assessment

A fixed-price review that shows exactly where you stand. It is the best starting point if you are not sure what you need.

Timeline: about two weeks from kickoff to report.
Price: from $2,500, depending on the number of users and devices.

What's included

  • Review of Microsoft 365 or Google Workspace against CISA baselines
  • Review of endpoints: encryption, admin rights, patch levels, security software
  • External scan of what your business exposes to the internet
  • Email authentication check (SPF, DKIM, DMARC)
  • Backup check: what is backed up, and whether it could survive ransomware
  • Written report ranked by risk, with cost estimates for each fix
  • 45-minute walkthrough call with you and your team

What we don't do

To stay focused on security, we don't provide help desk support, everyday password help, printer or hardware repair, new employee setup, or line-of-business software support. We are happy to work alongside the provider who does.