Managed IT and Managed Security · Leesburg, VA

Managed Security

Security That Watches Your Systems When You Cannot.

Monitoring, testing and leadership for the people who hold sensitive data: threat detection and response around the clock, and the assessments that show where to look first.

The security half of the firm. Compliance work is delivered by our Compliance Division, Capital Cyber Compliance.

Managed security: a loop that never stopsA shield at the center of a cycle with four stages: monitor around the clock, detect a threat, respond to it, then test and retest to find where to look first, and back to monitoring.1Monitor 24/72Detect3Respond4Test and retest

What Managed Security Covers

6 SERVICES

24/7 Monitoring and Response

Threat detection and response, SOC monitoring and managed backups, with ransomware protection and phishing defense. At Limberakis Dental this contained a live phishing attempt in 30 minutes.

Security Awareness Training

Training and technical controls for staff, because the human element is part of the program. Our dental and CPA programs include unlimited employee training access.

Managed Vulnerability Assessment

Automated discovery across your network, systems and applications, then classification by severity, a plan to fix what matters most, and reports you can use for audit and insurance.

Penetration Testing

Security experts simulate real attacks against your systems, networks or applications so weaknesses are found by us first. Scoped in writing, confidential, and retested after the fix.

Virtual CSO (vCSO)

An experienced security professional who learns your goals and builds a Technology Roadmap that lines them up with the right technology, without the cost of a full-time officer.

Cyber Liability Insurance Assessments

We analyze what insurers require, such as multi-factor authentication and staff training, verify the controls are in place, and prepare the documentation.

Managed Security Services, One Page Each

6 SERVICES

Managed Security Monitoring (MDR and SOC)

Round the clock monitoring, detection and response from a security operations center.

MFA and Endpoint Protection (EDR)

Multi-factor authentication, endpoint detection and response, and application control on every device.

Vulnerability Assessment and Penetration Testing

Find the weaknesses before an attacker does, then retest every fix.

Virtual CISO (vCISO)

Senior security leadership, a roadmap and governance, without a full-time hire.

Cyber Insurance Readiness

Know what your insurer requires, prove the controls are in place, and have the documents ready.

Security Awareness Training

Training and phishing simulations that turn staff into a line of defense.

Penetration Testing

How a Test Runs, Start to Retest.

The same four steps every time, so you know what happens before it happens. Nothing starts until the scope and the Confidentiality Agreement are signed.

STEP 1

Confidentiality and Onboarding

Before testing starts, we and your company define the scope in writing and sign a Confidentiality Agreement. Both teams confirm the infrastructure, domains, servers, devices with IP addresses, and any exclusions.

STEP 2

Execute the Test

A simulated attack to find vulnerabilities and known weak points in the system under test. Results are documented in a vulnerability assessment, delivered as a PDF.

STEP 3

Actionable Remediation

An initial report with practical guidance written for business leaders and IT teams, so the biggest risks get fixed first.

STEP 4

Retest to Validate Fixes

After your team makes the fixes, we retest every finding. The final report states patched or unpatched for each one.

Internal Gray Box Testing

What a Trusted Insider Could Reach.

Gray box testing sits between black box, with no prior knowledge, and white box, with full access. It simulates someone with limited internal access, such as a trusted insider or an attacker holding stolen credentials.

We run it over a live Microsoft Teams session so your team can watch the process in real time. If we find vulnerabilities, we write a tailored Remediation Plan. After the test, a confidential 60-minute Readout Meeting reviews the findings and the plan with your key people.

Compliance

CMMC Assessments Come From Our Compliance Division.

A vulnerability assessment or a gray box test is a security measurement. A NIST SP 800-171 or CMMC gap assessment scores your controls against the framework, and that is delivered by our Compliance Division, Capital Cyber Compliance.

CMMC Gap Assessment

Talk Through Your Security.

Pick a time. Tell us what you protect and who asks about it.

Looking for CMMC? Our Compliance Division, Capital Cyber Compliance, delivers it.

Book a 30-Minute Call