Frequently asked questions.
What each service includes, how it works, who does what and how it is priced. If your question is not here, ask us.
Getting started
What does Elmfort do?
Elmfort provides a complete, outsourced cybersecurity and operational resilience function. We monitor threats, manage vulnerabilities, maintain security governance and compliance evidence, coordinate incident response and verify that you can recover from disruption.
We also offer AI Enablement & Transformation, Managed Workplace IT, Managed Cloud and Software Engineering.
Who is Elmfort for?
UK organisations with fewer than 250 employees with sensitive data, compliance obligations or critical technology dependencies. Our service is particularly well suited for financial services, professional services and B2B technology companies.
How do we get started?
Request a proposal. We arrange a discovery call to understand your organisation, technology and obligations. Then we recommend the right services and send you a fixed proposal.
Cyber Resilience
What does Managed Cyber Resilience include?
Five capabilities: Security Operations, Governance & Compliance, Operational Resilience, AI Security & Governance and Security Leadership. Every plan includes all five. Higher plans add more governance, assurance, testing and security leadership.
Is your monitoring really 24/7?
Yes. Our contracted security operations centre (SOC) partner monitors and investigates security events 24 hours a day, 7 days a week. The SOC can take agreed containment actions, for example to isolate a compromised device.
Standard plans do not include unlimited 24/7 incident command, forensic investigation or production engineering. Your agreement states which containment actions the SOC can take and who responds to critical escalations. Enhanced incident response retainers are available.
Which technology do you cover?
Your entire relevant technology estate: employees, devices, identities, email, SaaS applications, networks, servers, cloud infrastructure, applications, development environments, AI systems and critical suppliers.
Coverage is not identical for every system. Some SaaS providers expose few security logs, while cloud platforms can expose many. During onboarding, we set the monitoring for each material system, document its limitations and record any gap that remains.
What happens during onboarding?
Onboarding has seven stages:
- Discovery: we identify your users, devices, applications, infrastructure, AI systems and critical suppliers.
- Risk assessment: we identify the material security and resilience risks.
- Security architecture: we set the security requirements, access and monitoring design.
- Platform integration: we deploy sensors, connect security telemetry and configure the governance platform.
- Resilience assessment: we identify critical services, recovery requirements and dependencies.
- Operational integration: we agree remediation workflows and a responsibility matrix.
- Service acceptance: we verify monitoring, escalation and the required controls, and we both sign.
The service acceptance records what we monitor, how we escalate and which gaps remain open. Onboarding is a separately priced engagement.
Can you guarantee Cyber Essentials or ISO 27001 certification?
No. We prepare you for assessment and manage the evidence. The certification body makes the certification decision. Every plan includes Cyber Essentials certification. Sentinel also includes Cyber Essentials Plus, which is optional on other plans. Sentinel includes an ISO 27001-aligned ISMS too.
What reports do we receive?
The Cyber Resilience Assurance Report. It tells you what is protected, what risks remain, what we fixed, whether recovery works and which decisions need your approval. You receive it quarterly on Foundation and monthly on Assured and Sentinel.
How is the price calculated?
Each plan has a monthly organisational fee, a rate for each staff member and a minimum monthly subscription: Foundation £3,500, Assured £5,500, Sentinel £9,500. Prices exclude VAT. The security software we need to deliver the service is included.
Our standard prices are based on a set of assumptions about your technology estate. They fit most small and medium-sized organisations.
Some estates need more monitoring, licensing or specialist work than the standard price allows. Examples are production servers and cloud environments, Kubernetes, custom AI applications and agents, high volumes of security logs or long retention periods, specialist compliance requirements and complex recovery dependencies.
We absolutely still cover these systems, but pricing may increase beyond our standard prices.
What is not included in the price?
Onboarding, additional estate complexity, major remediation, significant projects, third-party business application licences and cloud hosting consumption. We quote these separately.
We run AWS, Kubernetes or custom applications. Can you still cover us?
Yes. Complex infrastructure is part of the service. It only falls outside the standard published price. We include its security and resilience requirements in a tailored fixed-price proposal.
AI
Is AI governance included in our security plan?
Yes. Every Managed Cyber Resilience plan includes baseline AI security and governance: an acceptable-use policy, an AI inventory and risk register, awareness training and baseline assurance of custom AI and agents. Custom AI applications and agents with material business permissions need extra technical assessment.
Can you help us adopt or build AI?
Yes. AI Enablement & Transformation covers strategy, workplace AI rollout, workflow automation, agents and managed AI services.
Where should we start with AI?
With an AI opportunity assessment. It is a fixed-price engagement that gives you a prioritised list of use cases, a business case for each and a practical roadmap.
How are AI projects priced?
We scope each project against the business process, the integrations, the risk and the expected value, and send you a proposal. We do not publish standard project prices.
Managed IT
Do we need Managed Workplace IT?
It is optional, and we recommend it. With Managed Workplace IT, Elmfort runs your everyday IT to the same security standards, and one partner is responsible for both. Any other IT operator must meet our security and cooperation standards.
What does Managed Workplace IT include?
Microsoft 365 licensing, unlimited in-scope remote support, device management and patching, identity administration, Microsoft 365 backup, business password management, SaaS administration and IT service management.
When is the service desk available?
Monday to Friday, 9am–5pm UK time as standard. We can extend these hours to suit your organisation. Security monitoring continues 24/7 through your Managed Cyber Resilience plan.
How much does Managed Workplace IT cost?
£350 per month plus £99 per staff member, excluding VAT. It is added to a Managed Cyber Resilience plan.
This price applies when you use our preferred managed technology platform. Moving to the platform may involve migration work. We include that work in the initial onboarding cost.
What is not included?
Hardware purchases, connectivity, specialist business application subscriptions, major migrations and extensive on-site projects. We can quote for these separately.
Cloud
Can you run our cloud infrastructure?
Yes, through our Managed Cloud service. Managed Cyber Resilience on its own assures the security and resilience of your infrastructure, but it does not operate it.
What does Managed Cloud cover?
Cloud infrastructure, application and container hosting, databases, deployment pipelines, monitoring and cost management.
Can you host AI agents and agentic applications?
Yes. We host them in sandboxed environments, give each agent its own identity and only the permissions it needs, keep secrets in a managed vault, require human approval for consequential actions and log every action.
Is out-of-hours support included?
Your service agreement sets support hours, response times, availability targets and recovery objectives. Out-of-hours engineering is available where your services need it, and we agree it in the contract.
How is Managed Cloud priced?
We scope each environment and send you a fixed monthly proposal for its operation. Migration is a separately quoted project. Cloud provider charges are separate from our management fee.
Software
What kind of software do you build?
Business applications, integrations and APIs, internal tools, and updates to ageing applications.
How do you keep the software secure?
Each stage of development has its own security controls: threat modelling at design, peer review of every code change, automated scanning of each change, and security testing before each release.
Do you support the software after launch?
Yes. Our support service covers security updates, fixes and improvements, monitoring and long-term maintenance. We agree the scope, support hours and response times before go-live.
Can you work with our existing development team?
Yes. We can help your team build security into its development lifecycle, from threat modelling to security checks in your pipelines. We can also help your developers adopt AI coding tools and agents with the right guardrails in place.
Who owns the code?
You do. You own the source code, documentation and pipelines.
How are software projects priced?
We scope each project and deliver it in phases with agreed outcomes. We do not publish standard project prices, because scope differs for each organisation.
Working together
Who does what?
- Elmfort
- Runs your security, governance and resilience programme. Prioritises risks, coordinates remediation and incident response, verifies fixes and recovery tests, keeps the evidence and reports to your leadership team.
- Our security operations partner
- Monitors security events 24/7, investigates suspicious activity, takes agreed containment actions and escalates confirmed threats.
- Your IT operator
- Operates your systems day to day, applies fixes and configuration changes, and performs restorations. With Managed Workplace IT, Elmfort does this for your workplace technology.
- Your organisation
- Names accountable contacts, makes business decisions, accepts residual risk and approves high-risk changes and AI deployments.
We agree a responsibility matrix during onboarding.
What happens when you find a security incident?
The SOC detects and investigates the incident and takes agreed containment actions. It escalates confirmed threats to Elmfort and your nominated contacts. Elmfort coordinates the response and tracks the incident through remediation, verification and reporting.
What happens when you find a vulnerability?
We prioritise it by business impact and assign it to the operator of the system. We monitor the agreed deadline, verify the fix and record the evidence. If a fix does not happen, we escalate it to your management.
What access do you need?
Only the access that the agreed services need. For Managed Cyber Resilience, this typically means security agents on laptops and supported servers, connections to Microsoft 365 and your identity provider, read access to cloud audit logs, and integrations with supported SaaS applications. We agree each integration during onboarding.
Have a question that isn't here?
Ask us. We'll give you a straight answer.