SOC active · 24/7/365

Managed Cybersecurity for U.S. SMBs — MDR, 24/7 SOC, SLA-backed compliance

Managed detection & response, 24/7 security operations center, compliance evidence collection, and on-site incident response for businesses across all 50 states.

SOC 2 Type II ready

No credit card. Scan finishes in about 4 minutes.

24/7
Analyst coverage
Service tiers

Three lanes. One contract. Pricing you can send to the CFO.

Every tier runs on the same stack and the same SOC. The difference is how much compliance work we take off your plate, and whether we show up on-site during an incident.

MDR Essentials
The baseline every business under 250 seats should have in 2026.
$18/endpoint/mo
Annual agreement · 50-endpoint minimum
  • SentinelOne Singularity Control EDR on every endpoint
  • 24/7 SOC monitoring
  • Huntress-managed threat hunting on Windows + M365
  • Monthly executive report + quarterly posture review
  • KnowBe4 phishing training for all staff
Start Essentials →
MDR + IR Retainer
For firms where "everyone stopped working" costs $10k+ per hour.
Custom
Scoped by endpoint count & on-site radius
  • Everything in Compliance
  • Annual tabletop exercise with your executive team
  • Dark-web credential monitoring for your domain + exec aliases
  • Quarterly external penetration test
Scope IR Retainer →
The stack we actually run · no white-label mystery boxes
SentinelOne EDR Huntress MDR Microsoft Defender Cloud KnowBe4 SAT Cisco Umbrella DNS Arctic Wolf SOC partner Wasabi Immutable backup Tenable Nessus Vuln scan Duo MFA
Compliance evidence, done for you

We don't sell "compliance." We deliver the packet your auditor actually wants.

Every quarter we drop a ready-made evidence package into your portal: control mapping, log samples, policy attestations, tested backups, and user-access reviews. Your staff stops fighting spreadsheets. Your assessor finishes in days, not weeks.

SOC 2 Type II
Security, availability, and confidentiality trust criteria. Most-requested by your B2B customers during procurement.
HIPAA
Healthcare PHI safeguards, BAA-ready stack, annual risk analysis and workforce training records.
PCI-DSS v4.0
Cardholder data environment scoping, quarterly ASV scans, segmentation validation.
CMMC Level 2
110 NIST 800-171 controls for DoD subcontractors. We're a registered RPO.
CJIS
Criminal Justice Information Services for agencies handling FBI-sourced data.
NIST CSF 2.0
The framework your cyber-insurance carrier is actually scoring you against.
ISO 27001
ISMS controls for clients doing business in the EU or with multinationals.
GLBA / FTC Safeguards
For financial services, including the 2023 FTC Safeguards Rule for tax preparers and auto dealers.
FAQ · the ones that actually block the sale

Five questions. Honest answers.

Do you replace our internal IT team, or work with them?

Whichever you prefer. If you don't have internal IT we can be both, but the two pricing tiers above are security-only.

Can we leave without getting hostage'd on our data?

Yes. Every contract includes a data exit clause: within 30 days of termination we export your logs, configs, and compliance evidence to a format you choose (S3 bucket, encrypted drive, or API handoff to your next MDR). We keep nothing after day 60. This is in writing. Ask for a sample contract and check section 8.

What happens during a breach if we're over our retainer hours?

On the IR Retainer tier, the first 40 hours of any single incident are included. Beyond that we continue working at a pre-agreed $285/hr rate, invoiced monthly. We don't pause the response mid-incident to negotiate. On Essentials and Compliance tiers there's a flat $5,000 IR activation fee when an incident moves to P1, which covers the first 20 hours. Full rate card is in every proposal.

Can we see a sample SOC report before signing?

Yes, email sales@1800officesolutions.com and ask for the redacted quarterly report. It includes the executive summary, metric trends (alerts, incidents, MTTR), top threats observed, and quarterly compliance posture. You'll get it back under an NDA we'll send first.

Do you carry cyber liability insurance?

Yes, cyber liability and E&O, both through an A+ rated carrier. We name our clients as additional insureds on request. Certificate of insurance available for procurement.

Find out what's exposed before someone else does.

Our free external risk scan looks at everything an attacker can see from the open internet: exposed services, leaked credentials, expiring certificates, misconfigured DNS, and known CVEs on your perimeter. Takes about 4 minutes.

Run my free risk scan Or call (888) 574-5120