Your complete cybersecurity and resilience function.

Protect your business, meet security requirements and prove that you can recover from disruption. We combine continuous threat monitoring, vulnerability management, security governance, compliance and recovery assurance into one managed service.

Standing guard

Security that lets you switch off.

We watch for threats, close the gaps and keep you ready to recover. You get on with your day.

Detection

Threats detected, around the clock.

Our contracted security operations centre (SOC) monitors your systems 24 hours a day, 7 days a week. A SOC is a team of analysts who watch security events and investigate suspicious activity.

The SOC collects security events from your devices, identities, email and cloud services. It investigates each suspicious event and escalates confirmed threats.

  • Managed detection and response on laptops and supported servers
  • Detection of suspicious sign-ins and privilege changes
  • Email and Microsoft 365 threat detection
  • Cloud security events and audit logs
  • Collection and correlation of security logs (SIEM)

Monitoring by plan

Foundation Standard
Monitoring of devices, identities and Microsoft 365, with agreed containment actions.
Assured Enhanced
Adds more log sources and detections tuned to your critical systems.
Sentinel Advanced
Adds custom detection engineering and the widest monitoring of your estate.
What 24/7 monitoring includes

Every plan includes 24/7 SOC monitoring and investigation. The SOC can take agreed containment actions, for example to isolate a compromised device.

Standard plans do not include unlimited 24/7 incident command, forensic investigation or production engineering. Your service agreement states which containment actions the SOC can take and who responds to critical escalations. If you need guaranteed specialist mobilisation, we offer enhanced incident response retainers.

Response

Threats contained. Incidents resolved.

When the SOC confirms a threat, it takes the containment actions agreed in your service agreement. It escalates to Elmfort and to the contacts you nominate.

Elmfort coordinates the wider response. We work with the operator of each affected system, track the incident through remediation and verification, and report what happened and what changed.

  • Agreed containment actions, such as isolating a compromised device
  • Incident triage, escalation and coordinated response
  • Remediation tracked through to verified closure
  • An incident report with causes, actions and improvements
  • Incident response exercises, so your team knows what to do

Incident response by plan

Foundation Standard
Coordination of containment, remediation and an incident report.
Assured Enhanced
Adds a named incident lead and faster coordination for critical incidents.
Sentinel Enhanced crisis coordination
Adds crisis management support for your leadership team during a major incident.

Security Assurance

Find the weaknesses. Make sure they get fixed.

Our vulnerability platform finds weaknesses in your devices, servers, cloud services and internet-facing systems. Elmfort evaluates the business impact of each finding and sets a priority.

We assign each action to the team that operates the system. Then we monitor the agreed deadline and verify the fix. If a fix does not happen, we escalate the risk through the agreed management process.

  • Continuous internal and external vulnerability scanning
  • Security posture management for Microsoft 365 and cloud platforms
  • Exposure management for internet-facing services
  • Security architecture review against agreed standards
  • Verification that controls work as intended
  • Penetration testing, included annually in Sentinel

Vulnerability management by plan

Foundation Continuous
Continuous scanning of devices and internet-facing systems, with remediation tracking.
Assured Enhanced
Adds authenticated internal scanning, cloud configuration checks and shorter targets for critical fixes.
Sentinel Enhanced
As Assured, with findings reviewed in your monthly management review.

Governance, Risk & Compliance

Compliance without the complexity.

We keep your security policies, risk register and controls up to date. We collect the evidence that shows each control works. When a client, auditor or insurer asks how you protect data, you have a current answer.

An ISMS (information security management system) is the set of policies, processes and records that you use to manage security. We build and operate yours at the depth that your plan sets.

  • Security policies with a managed review cycle
  • Risk register with named owners and treatment plans
  • Control framework and continuously maintained evidence
  • Cyber Essentials certification in every plan
  • Supplier risk management
  • Security awareness training for employees

Management system by plan

Foundation Baseline
The foundations of a management system.
Assured Structured
A structured system with defined processes and reviews.
Sentinel Formal ISO 27001-aligned
A formal system aligned to ISO 27001, ready for certification.

Operational Resilience

Know you can recover.

A backup is only useful if you can restore from it. We identify the services your business depends on and agree how quickly each one must recover. Then we test whether recovery works.

Elmfort runs the resilience programme and independently reviews the recovery evidence. The operator of each platform performs the actual restoration.

  • Business impact analysis and recovery objectives
  • Backup assurance across critical systems
  • Scheduled recovery testing with evidence
  • Business continuity planning
  • Incident response exercises

Recovery testing by plan

Foundation Annual
One recovery test each year.
Assured Quarterly
A recovery test each quarter.
Sentinel Critical-service programme
A testing programme that covers each critical service on its own schedule.

AI Security & Governance

Embrace AI without losing control.

Every plan includes AI security and governance. It covers workplace AI tools such as ChatGPT and Copilot, and custom AI systems, including autonomous agents. An agent is AI software that can take actions in other systems.

We find the AI tools and agents that your organisation uses and keep an approved inventory. We set clear rules for safe use, control what data AI can see and what agents can do, and check AI systems for security weaknesses. Your staff learn to use AI safely, and your incident procedures cover AI too.

  • An inventory of the AI tools, models and agents you use
  • Acceptable-use policy and approval process
  • Review of the data AI tools can see and keep
  • Controls on agent permissions and tool access
  • Testing for prompt injection and unsafe integrations
  • AI incident procedures and staff awareness

Custom AI assurance by plan

Foundation Baseline risk assessment
A risk assessment of each custom AI system.
Assured Managed technical assurance
Ongoing technical review of permissions, integrations and data handling.
Sentinel Enhanced assurance programme
A full assurance programme, including regular testing.
All managed AI capabilities
AI discovery
An inventory of known and approved AI applications, models, providers and agents.
AI policy management
Acceptable-use policies and approval processes.
AI risk management
Assessment of security, privacy, reliability and operational risks.
AI data governance
Review of sensitive data exposure, retention, training-data use and provider terms.
AI identity governance
Requirements for API keys, service accounts, agent identities and delegated permissions.
AI application security
Assessment of prompt injection, insecure integrations, excessive permissions and unsafe tool execution.
Agentic AI controls
Requirements for agent autonomy, approval gates, tool access and auditability.
AI supplier assurance
Assessment of model and platform providers, contractual safeguards and dependencies.
AI operational resilience
Review of provider outages, model changes, fallback procedures and critical AI dependencies.
AI incident preparedness
Procedures for security incidents that involve AI applications and agents.
AI compliance
Mapping of controls to applicable AI governance and data-protection requirements.
AI awareness
Education for employees about approved tools, safe use and limitations.

Security Leadership

Expert guidance when it matters.

A CISO (chief information security officer) leads an organisation's security programme. A fractional CISO does that work part-time. We give your leadership team that senior oversight and clear reports that support decisions.

  • A security strategy and improvement roadmap
  • Senior oversight of your security programme
  • Security architecture guidance
  • Executive reporting and management decisions
  • Leadership support during major incidents

Leadership by plan

Foundation
Shared oversight. Quarterly executive report. Annual leadership review.
Assured
Quarterly senior review. Monthly executive report.
Sentinel
8 hours a month of fractional CISO time. Monthly report and management review.

The Cyber Resilience Assurance Report tells you what is protected, what risks remain, what we fixed, whether recovery works and which decisions need your approval. See an example

Plans and pricing

Protection that grows with your business.

Every plan includes all core capabilities and covers your full technology estate. Prices include all licensing and exclude VAT.

Foundation

Protected & Recoverable

A credible minimum standard of cybersecurity and resilience across your whole organisation.

From £3,500 per month, excluding VAT

£1,500 organisational fee + £35 per staff member, subject to the minimum.

  • 24/7 threat monitoring
  • Continuous vulnerability management
  • Essential security governance
  • Annual recovery testing
  • Baseline AI governance
Get a quote

Sentinel

Advanced Governance & Resilience

Formal management systems, specialist testing and more extensive security leadership.

From £9,500 per month, excluding VAT

£5,000 organisational fee + £75 per staff member, subject to the minimum.

  • Everything in Assured
  • Formal ISMS programme
  • Advanced security leadership
  • Critical-service testing programme
  • Advanced AI assurance
Get a quote

These prices are indicative and based on a standard technology estate. Your fixed price may differ. How we calculate your price

Price estimator

Estimate your monthly subscription.

Choose your number of staff and a plan. Add Managed Workplace IT if you want Elmfort to run your everyday IT too.

Plan

Indicative monthly price

Assured Cyber Resilience
£6,875
Total per month £6,875

Excluding VAT. Onboarding is quoted separately.

Get a quote

Every plan includes all core capabilities. The plans differ in depth of management, frequency of assurance and extent of specialist support. Select a capability to see what each level means.

Comparison of Managed Cyber Resilience plans
Capability FoundationAssuredSentinel
Security operations and assurance
IncludedIncluded

Every plan covers your full technology estate: devices, identities, email, SaaS applications, networks, servers, cloud and AI systems.

StandardAdvanced

Our contracted security operations centre monitors and investigates security events 24 hours a day, 7 days a week.

Foundation: Standard
Monitoring of devices, identities and Microsoft 365, with agreed containment actions.
Assured: Enhanced
Adds more log sources and detections tuned to your critical systems.
Sentinel: Advanced
Adds custom detection engineering and the widest monitoring of your estate.
IncludedIncluded

Managed detection and response on laptops and supported servers, and detection of suspicious sign-ins and privilege changes.

IncludedIncluded

We collect and correlate security logs from your systems, so the SOC can see activity across your estate.

ContinuousEnhanced

We find weaknesses in your systems, prioritise them and verify each fix.

Foundation: Continuous
Continuous scanning of devices and internet-facing systems, with remediation tracking.
Assured: Enhanced
Adds authenticated internal scanning, cloud configuration checks and shorter targets for critical fixes.
Sentinel: Enhanced
As Assured, with findings reviewed in your monthly management review.
IncludedIncluded

We check the security configuration of your cloud platforms and business applications against agreed standards.

BaselineAdvanced

We review how your systems are designed and connected against good security practice.

Foundation: Baseline
Review against our standard security baseline.
Assured: Enhanced
Regular review of changes and new systems.
Sentinel: Advanced
Ongoing review by senior specialists, including design input for new projects.
IncludedIncluded

The SOC investigates each alert and escalates confirmed threats to Elmfort and your nominated contacts.

StandardEnhanced crisis coordination

Elmfort coordinates the response to a confirmed incident and tracks it to resolution.

Foundation: Standard
Coordination of containment, remediation and an incident report.
Assured: Enhanced
Adds a named incident lead and faster coordination for critical incidents.
Sentinel: Enhanced crisis coordination
Adds crisis management support for your leadership team during a major incident.
OptionalAnnual scoped allowance

Independent specialists attempt to break into your systems to find weaknesses. Sentinel includes an annual test of agreed scope.

BaselineAdvanced

Controls that stop sensitive data leaving your organisation, by accident or on purpose.

Foundation: Baseline
Standard data-protection policies in Microsoft 365.
Assured: Enhanced
Policies tuned to your sensitive data, with regular review of alerts.
Sentinel: Advanced
Adds insider-risk monitoring and investigation support.
Governance, risk and compliance
BaselineEnhanced

The evidence that shows your security controls work, ready for audits and client checks.

Foundation: Baseline
Evidence for the core controls, refreshed at each review.
Assured: Continuous
Evidence collected continuously from connected systems.
Sentinel: Enhanced
Adds evidence for additional frameworks and audit preparation support.
IncludedIncluded

The UK government-backed certification for basic cyber hygiene, renewed each year.

OptionalIncluded

The higher level of Cyber Essentials, with independent technical testing.

BaselineComprehensive

The written rules for how your organisation protects information.

Foundation: Baseline
A core set of policies, customised for you.
Assured: Managed lifecycle
Policies reviewed, updated and approved on a regular cycle.
Sentinel: Comprehensive
A complete policy set for formal certification.
Essential risksComprehensive programme

A record of your security risks, their owners and how you treat them.

Foundation: Essential risks
Your most important security risks, recorded and owned.
Assured: Actively managed
Risks reviewed regularly, with treatment plans tracked.
Sentinel: Comprehensive programme
A full risk management programme with management review.
BaselineFormal ISO 27001-aligned

An information security management system: the policies, processes and records you use to manage security.

Foundation: Baseline
The foundations of a management system.
Assured: Structured
A structured system with defined processes and reviews.
Sentinel: Formal ISO 27001-aligned
A formal system aligned to ISO 27001, ready for certification.
Critical suppliersComprehensive

Assessment of the security of the suppliers your business depends on.

Foundation: Critical suppliers
Your most critical suppliers.
Assured: Risk-based
Suppliers assessed in line with the risk they carry.
Sentinel: Comprehensive
All material suppliers, with regular reassessment.
IncludedEnhanced + executive

Training that helps your staff recognise and report threats.

Foundation: Included
Regular online training for all staff.
Assured: Enhanced
Adds phishing simulations and targeted training.
Sentinel: Enhanced + executive
Adds training for your leadership team.
Operational resilience
AnnualCritical-service programme

Tests that prove your critical services can recover from disruption.

Foundation: Annual
One recovery test each year.
Assured: Quarterly
A recovery test each quarter.
Sentinel: Critical-service programme
A testing programme that covers each critical service on its own schedule.
IncludedIncluded

We check that backups of your critical systems run, are complete and can be restored.

EssentialAdvanced

Plans that keep your business running during disruption.

Foundation: Essential
A continuity plan for your most critical services.
Assured: Managed
Plans reviewed and updated as your business changes.
Sentinel: Advanced
A full continuity programme with management review.
Basic readinessTwice-yearly exercises

Practice runs that prepare your team to respond to a real incident.

Foundation: Basic readiness
A review of your incident readiness.
Assured: Annual tabletop
One tabletop exercise each year.
Sentinel: Twice-yearly exercises
Two exercises each year.
AI security and governance
IncludedIncluded

Clear rules for how your staff can use AI tools.

Baseline risk assessmentEnhanced assurance programme

Security assurance for AI systems and agents that you build or deploy.

Foundation: Baseline risk assessment
A risk assessment of each custom AI system.
Assured: Managed technical assurance
Ongoing technical review of permissions, integrations and data handling.
Sentinel: Enhanced assurance programme
A full assurance programme, including regular testing.
IncludedIncluded

A record of the AI tools, models and providers your organisation uses.

EssentialComprehensive

A record of the risks that your AI use creates, and how you treat them.

Foundation: Essential
Your most important AI risks.
Assured: Managed
AI risks reviewed regularly, with treatment tracked.
Sentinel: Comprehensive
A full AI risk programme.
BaselineAdvanced

Checks on what data AI tools can see, keep and use for training.

Foundation: Baseline
Review of approved AI tools.
Assured: Enhanced
Adds review of data flows into AI systems.
Sentinel: Advanced
Adds ongoing monitoring of AI data exposure.
BaselineAdvanced

Controls on what AI agents and integrations are allowed to access and do.

Foundation: Baseline
Standard access requirements for AI tools.
Assured: Enhanced
Reviewed permissions for each agent and integration.
Sentinel: Advanced
Adds approval gates and audit of agent actions.
Critical providersEnhanced

Assessment of the AI model and platform providers you rely on.

BaselineTested

Procedures for security incidents that involve AI tools or agents.

OptionalManaged programme

Assessments of the wider impact of high-risk AI uses.

OptionalManaged readiness programme

The international standard for AI management systems.

Leadership and reporting
Shared oversight8 hours/month vCISO

Senior security guidance for your leadership team.

Foundation: Shared oversight
Oversight from Elmfort's senior specialists.
Assured: Quarterly senior review
A quarterly review with a senior specialist.
Sentinel: 8 hours/month vCISO
8 hours a month of a virtual chief information security officer (vCISO).
QuarterlyMonthly + management review

The Cyber Resilience Assurance Report for your leadership team.

AnnualAgreed programme

A report on each recovery test, with results and actions.

Included

  • Security tooling and licences required for the agreed managed service
  • No separate SOC, GRC or vulnerability-scanning subscription from Elmfort
  • Managed Workplace IT includes Microsoft 365 licensing and the standard managed workplace software
  • Baseline AI security and governance in every plan

Quoted separately

  • Onboarding, a one-off implementation engagement
  • Additional estate complexity, such as production cloud, Kubernetes or custom AI
  • Major security remediation, significant projects and specialist services
  • Third-party business application licences and cloud hosting consumption
  • AI implementation and managed AI services

Tell us what you need to protect.

We'll review your organisation, your technology and your obligations. Then we'll recommend a plan and send you a fixed monthly proposal.