Security Hardening Retainer

Monthly hardening programme: patch cadence, policy upkeep, re-scans and a monthly report.

HARDEN-01Duration: monthly, 1-month noticeSecurity

Outcome

An asset portfolio that is hardened month after month, with evidence records instead of point checks.

Who it is for

Teams that completed a PTaaS pilot or gap audit.

Deliverables

  • Monthly re-scan (in-scope apps)
  • Patch/mitigation tracking with deadline report
  • Policy and configuration updates per finding
  • Retests of fixed findings within the agreed scope (included)
  • Monthly report: delta, risk, priorities
  • Quarterly control review
  • Emergency spot help (2 hrs/month)

In scope

  • Up to 5 in-scope apps/domains
  • monthly cycle

Out of scope

  • 24/7 SOC (not a SOC replacement)
  • Full incident forensics

Prerequisites

  • Read-only or scoped fix access
  • DPA

Acceptance

  • Acceptance via monthly report with delta metrics and a maintained priority list.

Human approvals

  • Owner confirms monthly priorities
  • Human reviews all config changes before rollout

Frequently asked questions

SOC replacement?

No. The retainer hardens and documents; SIEM/SOC operation is a separate offer.