Every laptop, watched. One number.
Device management, patching, threat detection and identity protection, bundled into a single per-device price. No parts bin, no arithmetic, no three-year contract.
- Device Management — remote monitoring, MDM enrollment, asset inventory, remote wipe and lock
- Patch Management — automated Windows, macOS and third-party app patching with compliance reporting
- EDR — behavioural threat detection with device isolation and rollback
- ITDR — identity threat detection across Microsoft 365 and your directory
- Monthly posture report, written in English rather than console screenshots
- Free external security assessment before you commit
What does endpoint protection cost?
$32 per device per month. The same four services bought individually come to $38. The bundle exists because buying them separately is worse for you and more work for us — not as a discount gimmick.
| Service | Bought separately | In the bundle |
|---|---|---|
| Device Management | $10 / device / mo | Included |
| Patch Management | $10 / device / mo | Included |
| EDR + ITDR | $18 / user / mo | Included |
| Total | $38 / mo | $32 / mo |
| You keep | — | $72 / device / year |
Pricing assumes one primary user per device. Shared workstations, kiosks and environments with several identities per machine are quoted individually — ask and we will size it properly rather than surprise you on the first invoice.
What is the difference between EDR and antivirus?
Antivirus matches files against a list of known-bad signatures. It only stops threats someone has already catalogued, which means it is structurally incapable of stopping anything new.
EDR watches behaviour instead: processes spawning other processes, a program suddenly encrypting hundreds of files, a browser reading credential stores, an account logging in from two countries an hour apart. When it sees that pattern it can isolate the machine from the network mid-attack and roll back the changes.
Ransomware written last week has no signature. That is the entire problem with relying on antivirus alone in 2026.
Do I need this if I already pay for Microsoft 365?
Microsoft 365 protects the mailbox and the identity. It does not protect the machine.
If a laptop is compromised through a malicious download, an infected USB stick or an unpatched browser, your 365 licence will not detect it, will not isolate the device, and will not roll it back. Those are different layers, and the endpoint is the one that gets people.
The two work together: hardening your 365 tenant closes the identity door, endpoint protection closes the device door. We do both — O365 tenant hardening starts at $500 for a one-time scope.
What you actually get every month
The failure mode of managed security is a provider who installs an agent, sends an invoice, and is never heard from again until something breaks. What you should expect instead:
- Patch compliance reported as a number, so you can see what percentage of your fleet is current
- Every detection that fired, what it was, and what we did about it
- Devices that have gone quiet — usually someone left, and their laptop still has your data on it
- What changed since last month, and anything we think you should fix that is outside the plan
Common questions
Is there a long-term contract?
No. Billed monthly, cancel with 30 days' notice. No multi-year agreement, no early termination fee. If the service is worth keeping you will keep it.
What is the minimum number of devices?
Five. Below that the per-device economics do not work for either of us, and prepaid support hours are usually the better fit.
Does this help with HIPAA compliance?
It covers several of the technical safeguards the HIPAA Security Rule expects — access controls, audit logging, malware protection, device encryption enforcement.
It is not the whole of HIPAA. Policies, workforce training and business associate agreements sit outside it. But it addresses the technical controls most small practices are missing, and we will tell you plainly which gaps remain.
What happens when something is actually detected?
The device is isolated from the network automatically while we investigate, so a compromise on one laptop does not become a compromise of the whole office. You get a call, not a ticket in a queue.
Do you support Macs?
Yes. Windows and macOS both, with patching and EDR coverage on each. Mobile devices are covered through MDM enrollment.
Can I start with fewer services and add the rest later?
You can — every component is available individually. Most people find the bundle cheaper and simpler within a month or two, so we would rather you start there and drop what you do not need.
Start with the free assessment
We run an external security assessment on your domain and show you what we find before you spend anything. If nothing turns up, we will tell you that too.