Security Hardening Retainer
Monthly hardening programme: patch cadence, policy upkeep, re-scans and a monthly report.
HARDEN-01Duration: monthly, 1-month noticeSecurity
Outcome
An asset portfolio that is hardened month after month, with evidence records instead of point checks.
Who it is for
Teams that completed a PTaaS pilot or gap audit.
Deliverables
- Monthly re-scan (in-scope apps)
- Patch/mitigation tracking with deadline report
- Policy and configuration updates per finding
- Retests of fixed findings within the agreed scope (included)
- Monthly report: delta, risk, priorities
- Quarterly control review
- Emergency spot help (2 hrs/month)
In scope
- Up to 5 in-scope apps/domains
- monthly cycle
Out of scope
- 24/7 SOC (not a SOC replacement)
- Full incident forensics
Prerequisites
- Read-only or scoped fix access
- DPA
Acceptance
- Acceptance via monthly report with delta metrics and a maintained priority list.
Human approvals
- Owner confirms monthly priorities
- Human reviews all config changes before rollout
Frequently asked questions
SOC replacement?
No. The retainer hardens and documents; SIEM/SOC operation is a separate offer.