Managed Security Service by Selected Cyber
Advanced managed security services, delivered via their 24x7x365 UK-based Cyber Security Operations Centre (CSOC) and powered by Microsoft’s cloud native MXDR and SIEM/SOAR technologies, Microsoft Defender XDR and Microsoft Sentinel.
Why Chorus?
Cyber security attacks are increasing in frequency and sophistication, which is why cyber security is a key business priority. Today, organisations need to reduce the likelihood of an attack, proactively detect threats, and rapidly respond to reduce potential business impact.
To achieve this, organisations need the right processes and technology in place with a team of highly skilled security experts, however for many, this is uneconomical to build and maintain internally.
Modern 24/7 UK-based CSOC
They have built a 24/7 CSOC to make best use of technical innovations and cutting-edge cloud security technologies to deliver an advanced managed service. Underpinned by a team of highly skilled and experienced CSOC analysts, our team protect your organisation around-the-clock.
Leading technical architecture
Built on Microsoft Defender XDR and Microsoft Sentinel, their CSOC architecture is built to best-practice to benefit from cutting-edge automation, machine learning, AI and integration to reduce alert noise, automate common tasks and accelerate threat detection and response times.
Proactive and preventative protection
They take their managed security services a step further by building in pre-emptive protection through advanced threat hunting and cyber threat intelligence to proactively block emerging and unknown threats before they occur.
Rapid threat detection and response
Through their skilled SecOps team, advanced technology and use of automation, we ensure cyber threats are quickly identified, investigated and remediated – reducing the likelihood and potential impact of successful attacks, to keep your organisation ahead of evolving threats.
< 5 Mins - Mean Time to Acknowledgement
< 15 Mins Mean Time to Close
50% - Incidents closed by automation
187 days - on average to detect a security breach
£720,000 - Saved if breach contained within 30 days
Source: IBM, Cost of a Data Breach Report 2021
Managed Security Services
The Chorus managed security services leverage Microsoft technologies to help organisations detect, investigate, hunt and respond to cyber security threats. We provide flexible managed security services, allowing organisations to choose the right level of protection to meet their security requirements and internal capabilities.
Advanced threat detection and containment services to protect all of your endpoints
(Defender for Endpoints & Sentinel).
Extended threat detection and containment across your Microsoft E5 Security tooling.
(Defender stack & Sentinel).
Extended threat detection & containment across your environment.
(Defender stack, Sentinel, 3rd party logs, etc).
What's Included in the Chorus Managed Security Service
The Chorus MDR & MXDR services are built on Microsoft Defender XDR and Microsoft Sentinel - Microsoft’s integrated XDR and SIEM/SOAR technologies.
By using these advanced cloud technologies, we can rapidly detect sophisticated threats across any data source. Through Sentinel’s SOAR capabilities and our security playbooks, common threats are automatically remediated while sophisticated attacks are investigated by our team of highly skilled CSOC analysts to ensure rapid response.
Which level of service is right for you?
MDR Endpoints
The MDR Endpoints service delivered by the 24/7 UK-based CSOC, helps organisations rapidly identify, investigate, proactively hunt, and remediate cyber security threats across their endpoints.
With an estimated 70% of cyber security threats starting on endpoints and the continuing rise of remote working and BYOD, devices are a common attack surface that need to be actively monitored and protected. Chorus leverages the power of advanced automation, AI and proactive cyber threat intelligence, using Microsoft Defender for Endpoint and Microsoft Sentinel to rapidly detect and remediate threats across your devices.
SERVICE FEATURES
- 24x7x365 UK-based CSOC – Our highly skilled SecOps team are available 24/7 to offer round the clock protection and support.
- Endpoint Threat Detection & Investigation – Our MDR service proactively monitors, identifies and responds to threats across your endpoint environment by using Microsoft Defender for Endpoint to analyse, contain and remediate threats.
- Automated Response – We provide automated threat containment and remediation through agreed security playbooks and SOAR capabilities to rapidly isolate devices, contain threats and reduce their impact.
- Cyber Threat Intelligence (CTI) – We continually integrate threat intelligence from external sources, as well as CTI from our CSOC team. Taking this a step further, we automatically feed emerging Indicators of Compromise (IOC) into our playbooks to block malicious content, so that you stay ahead of continually evolving adversarial tactics and techniques.
- Proactive Threat Hunting – Through manual and automated threat hunting we identify early indicators of emerging threats, tactics or procedures (TTPs), to stay ahead of emerging cyber threats.
- Reporting & Analytics – Weekly digestible email reports that highlight security metrics so you have a frequent, high-level overview.
- Service Governance – Through quarterly operational security reviews and annual security reviews, we evaluate key service metrics, such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), review security trends and discuss strategic goals.
- Security Recommendations – We share recommended security improvements as part of our continual service improvement, to eliminate risks and reduce your attack surface.
- Phishing Attack Simulation – Subject to Microsoft licensing, we can provide attack simulation using Microsoft Defender for Office 365 to conduct periodic phishing and password attacks to train employees and reduce threat risk.
MDR Endpoints
Advanced threat detection and containment services to protect all of your endpoints (Defender for Endpoints & Sentinel)-
24x7x365 UK-based CSOC
-
CSOC Analysts available by phone 24x7
-
30 minute high severity SLA
-
Chorus proprietary analytic rules
-
Microsoft Security Suite Coverage - Defender for Endpoint
-
Microsoft Sentinel Custom Integration - Endpoints
-
Microsoft Sentinel Custom Integration - Entra ID Identities
-
Microsoft Sentinel Custom Integration - Servers
-
Weekly Security Service Report
-
Cyber Essentials aligned TVM Report
-
Cyber Threat Intelligence
-
Standard Security Playbooks
-
Security recommendations & guidance
-
Service Governance
-
MITRE ATT&CK Framework mapping
MXDR Advanced
A cloud-first approach requires a modern Zero Trust framework to adapt to the complexities of modern working. The MXDR Advanced service ensures 24/7 threat detection and response to keep your cloud environments secure.
Chorus provide integrated protection across your endpoints, identities, Microsoft 365, SaaS apps and email to rapidly detect and respond to threats, making best use of automated response capabilities to support long-term success in the cloud.
SERVICE FEATURES
- 24/7 CSOC & Expertise – Our Security Analysts are available 24/7/365 offering continuous monitoring and protection from our UK-based Cyber Security Operations Centre.
- Extensive Cloud Security Coverage – 24/7 threat detection and response across your cloud environment using advanced XDR – covering your endpoints, identities, Microsoft 365, SaaS apps and email.
- Cyber Threat Intelligence – Continuous cyber threat intelligence (CTI) integration from wide-ranging sources is used to take proactive action and block emerging threats to better defend your organisation.
- Custom Threat Detection Rules – Creation and management of bespoke threat detection rules above out-of-the-box and Chorus detection rules to meet your unique cyber security requirements and expand threat coverage.
- Rapid Threat Response – Automated security playbooks instantly respond to common tasks and threats, while sophisticated attacks are rapidly investigated and mitigated by our CSOC analysts, reducing the time to detect and respond to threats and minimising their potential impact.
- Custom Security Playbooks – We expand upon our library of built-in and Chorus-developed security playbooks with custom playbooks to automate investigation or response actions in-line with your security policies.
- Extended Threat Hunting – Advanced threat hunting and vulnerability management across your cloud estate to proactively identify and protect against new and emerging threats.
- Service Governance & Reporting – Regular service governance, account management and reporting ensure optimal service delivery and drive continuous service and security improvement.
- Security Strategy – We continuously feed security recommendations and guidance into your teams and security strategy, based on the metrics we track, so you benefit from a proactive and forward-thinking roadmap.
- Smooth Service Transition – Through our standardised service transition and a rapid technical onboarding using Azure Lighthouse, we ensure all key information is captured and you can be up and running quickly.
- Phishing Attack Simulation – Periodic phishing attack simulation to train employees and reduce risk.
MXDR Advanced
Extended threat detection and containment across your Microsoft E5 Security tooling. (Defender stack & Sentinel).-
24x7x365 UK-based CSOC
-
CSOC Analysts available by phone 24x7
-
30 minute high severity SLA
-
Chorus proprietary analytic rules
-
Microsoft Security Suite Coverage - Defender for Endpoint
-
Microsoft Security Suite Coverage - Defender for Identity
-
Microsoft Security Suite Coverage - Defender for Cloud Apps
-
Microsoft Security Suite Coverage - Defender for Office
-
Microsoft Security Suite Coverage - Defender for Cloud
-
Microsoft Security Suite Coverage - Defender for Azure Service
-
Microsoft Sentinel Custom Integration - Endpoints
-
Microsoft Sentinel Custom Integration - Entra ID Identities
-
Microsoft Sentinel Custom Integration - Servers
-
Weekly Security Service Report
-
Cyber Essentials aligned TVM Report
-
Cyber Threat Intelligence
-
Standard Security Playbooks
-
Security recommendations & guidance
-
Service Governance
-
MITRE ATT&CK Framework mapping
-
Custom security playbooks
-
Extended threat Hunting
MXDR Premium
For many organisations, the transition to the cloud is a phased approach and results in having a mixed estate across cloud and on-premises.
This MXDR Premium offering brings greater visibility, integration and automation capabilities to detect, investigate and rapidly respond to security threats across all your environments for end-to-end visibility and faster remediation.
SERVICE FEATURES
- 24/7 CSOC and skilled analysts – Our Security Analysts are available 24/7/365 offering continuous monitoring and protection.
- Extended Threat Detection & Investigation – 24/7 threat detection across your entire estate using advanced XDR, including endpoints, network, infrastructure (on-premise and cloud) and the ability to ingest events from any API or source for complete coverage.
- Proactive Threat Intelligence – Continuous cyber threat intelligence (CTI) integration from wide-ranging sources is used to take proactive action and block emerging threats to better defend your organisation.
- Custom Threat Detection Rules – Creation and management of bespoke threat detection rules above out-of-the-box and Chorus detection rules to meet your unique cyber security requirements.
- Rapid Threat Response – Automated security playbooks instantly respond to common tasks and threats, while sophisticated attacks are rapidly investigated and mitigated by our CSOC analysts, reducing time to detect and respond to threats and their potential impact.
- Custom Security Playbooks – We expand upon our library of built-in and Chorus security playbooks with custom playbooks to automate investigation or response actions in-line with your security policies.
- Extended Threat Hunting – Advanced threat hunting and vulnerability management across your entire estate to proactively identify and protect against new and emerging threats.
- Service Governance and Reporting – Regular service governance, account management and reporting ensure optimal service delivery and drive continuous service and security improvement.
- Security Advisory – We continuously feed security recommendations and guidance into your teams and security strategy based on the metrics we gather so you benefit from a proactive and forward-thinking roadmap.
- Service Transition – Through our standardised service transition and a rapid technical onboarding using Azure Lighthouse, we ensure all key information is captured and you can be up and running quickly.
- Phishing Attack Simulation – Periodic phishing attack simulation to train employees and reduce risk.
MXDR Premium
Extended threat detection & containment across your environment. (Defender stack, Sentinel, 3rd party logs, etc).-
24x7x365 UK-based CSOC
-
CSOC Analysts available by phone 24x7
-
30 minute high severity SLA
-
Chorus proprietary analytic rules
-
Microsoft Security Suite Coverage - Defender for Endpoint
-
Microsoft Security Suite Coverage - Defender for Identity
-
Microsoft Security Suite Coverage - Defender for Cloud Apps
-
Microsoft Security Suite Coverage - Defender for Office
-
Microsoft Security Suite Coverage - Defender for Cloud
-
Microsoft Security Suite Coverage - Defender for Azure Service
-
Microsoft Sentinel Custom Integration - Endpoints
-
Microsoft Sentinel Custom Integration - Entra ID Identities
-
Microsoft Sentinel Custom Integration - Servers
-
Microsoft Sentinel Custom Integration - Active Directory Identities
-
Microsoft Sentinel Custom Integration - Non-Azure Cloud services
-
Microsoft Sentinel Custom Integration - Networking log sources
-
Weekly Security Service Report
-
Cyber Essentials aligned TVM Report
-
Cyber Threat Intelligence
-
Standard Security Playbooks
-
Security recommendations & guidance
-
Service Governance
-
MITRE ATT&CK Framework mapping
-
Custom security playbooks
-
Extended threat Hunting
-
External attack surface monitoring
Service Transition
Our standardised service transition model means that we can get you onboarded quickly and efficiently. Following a consistent and proven approach, we work closely with you to gain a detailed understanding of your organisation and ensure everything is setup, so you can experience great service from day one.
Our transition model is split into two key streams: service and technical onboarding. Working with a dedicated project manager and technical contact, we will guide you through the transition process to gain an in-depth understanding of your environment, processes and capabilities to ensure that our service meets your requirements and all key information is captured.
As part of our technical onboarding we carry out a Cyber Threat Assessment to feed recommendations into your ongoing security strategy and help further strengthen your security posture. Using Azure Lighthouse, we enable rapid technical onboarding whilst ensuring you retain precise control and visibility over the delegated services.
Once live, we actively monitor threats and alerts being raised and use this telemetry to fine tune any rules and playbooks before going into operational service. With regular service governance reviews, account management and reporting, we continue to work closely with you for ongoing security posture enhancements and continual service improvement.
Chorus are members of the Microsoft Security Intelligent Association (MISA) and their managed services have been awarded Microsoft-verified MXDR solution status, proving the calibre of their service and CSOC.
Lite versions of all three services available that only covers alerts classified as Medium or High in Microsoft Sentinel.
See the powerful capabilities of Microsoft Sentinel and our managed security services with a Proof of Concept.
Contact us to find out more.
Ready to learn more?
Contact us today for a free consultation. We’ll discuss your specific needs and recommend the best service for your organisation. Let’s work together to build a robust security shield and keep your business safe from evolving cyber threats.