Managed Cyber Security

Managed Cyber Security: the tools exist in most environments. The operating layer around them often does not.

Continuous monitoring, alert triage, configuration-drift control, identity hygiene, recovery verification and a response process that works at 3am, not just in business hours — that is the operating layer most environments lack. Inlight IT delivers managed cyber security with the depth matched to your environment and risk.

  • Tiered to the environment
  • Works with existing tooling
  • Australian oversight throughout
  • Recovery is part of the model
What the service covers
Endpoint detection
Process, network and persistence telemetry with analyst oversight
Identity and Microsoft 365
Anomalous sign-in, privilege escalation and consent abuse
Email and BEC indicators
Forwarding rules, impersonation and rogue app consent
Backup recoverability
Immutability, restore evidence and ransomware readiness
The operating gap

The situations that make the operating gap impossible to ignore.

Cyber security risk in many Australian organisations does not sit in the absence of tools. It sits in the gap between tools being deployed and tools being actively operated. The situations below are where that gap usually becomes visible.

01
Alerts are generating but nobody is reviewing them properly after hours
Endpoint tools are working. Alerts are going to an inbox. They get reviewed the next morning, or the next week. An incident that starts at 9pm on a Friday is a significant event by Monday.
02
A cyber insurer is asking about 24/7 monitoring and the answer is not credible
Insurers are asking specific questions: is the environment monitored around the clock, who triages alerts, what is the incident response process, how is recovery evidenced. "We have antivirus and backups" does not answer any of them.
03
The IT team manages infrastructure competently but is not a security operations function
General IT and security operations are different disciplines. A capable IT team can manage patching, helpdesk and projects. Continuous detection, identity governance and response coordination are a different capability set, one most internal IT teams are not resourced to build.
04
An incident revealed the gap between detection and response was measured in days
Ransomware staging behaviour present for 72 hours before discovery. A compromised account active for two weeks. A BEC attempt that nearly worked. The incident does not have to be severe to make the gap visible.
05
Essential Eight uplift has improved prevention but detection is still missing
ML2 controls address prevention and recovery. They do not tell the organisation whether prevention is failing or being actively bypassed. A strong prevention posture without an operating detection layer is half the picture.
06
Microsoft 365 has become business-critical but is not actively governed
Identity, conditional access, admin role hygiene, risky app consent and legacy authentication drift over time. The tenant looks configured. The operating reality has moved on.
07
A key person is leaving and the informal security knowledge goes with them
One person reviews alerts informally, knows the environment, handles incidents without a defined process. When they leave, the knowledge leaves and the operating capability disappears overnight.
08
Customer or government due diligence is asking for evidence the organisation cannot produce
A customer, a partner or a procurement process is asking for documented evidence of monitoring, response capability and recovery readiness. The controls largely exist. The defensible evidence does not.
Where the service fits

Managed IT covers the security baseline. Managed cyber security is the deeper operating layer above it.

Inlight IT's managed IT service already includes security at the operational baseline. Patching, MFA, endpoint deployment, backup configuration, Microsoft 365 administration and routine monitoring are part of how the IT environment is managed. For many organisations, that baseline is enough.

Managed cyber security is the deeper operating layer for environments that need more than baseline. Continuous detection across identity and endpoints. Analyst-led alert triage with response coordination. Microsoft 365 security posture managed actively, not just administered. Backup recoverability verified, not just configured. SOC-backed operating depth where the risk profile requires it. Insurer-grade evidence produced as part of operations, not assembled at renewal.

The two services are designed to work together. Most organisations engage both: Inlight IT delivers managed IT with managed cyber security operating as the security layer on top of it. Some organisations engage managed cyber security alongside an existing internal IT team, or alongside a separate MSP that handles general IT. The service is shaped to either model.

The question is not whether security belongs in IT operations. It does. The question is how much operating depth the environment requires.
How cover scales

Two operating tiers. The right depth depends on the environment.

Not every environment requires the same depth of security operations. Some need a leaner continuous-monitoring model with guided response. Others need a SOC-backed operating layer with deeper investigation capability, after-hours response authority and broader telemetry. The service is scoped around the environment: which tier fits, what coverage is required and how much operating depth the risk profile justifies.

Tier 1

Standard operating tier

Continuous monitoring and guided response across identity, endpoints and Microsoft 365.

  • Continuous monitoring across endpoint and identity signals
  • Alert triage with real threats escalated and noise filtered before it reaches the client team
  • Guided containment and response coordination on confirmed incidents
  • Microsoft 365 and Entra ID identity coverage included
  • Tenant security review, conditional access hygiene and risky app consent monitoring
  • Backup recoverability oversight and Microsoft 365 backup where required
  • Monthly reporting suitable for management, insurer questionnaires and Essential Eight governance

Best suited to environments where identity, endpoint and Microsoft 365 are the primary control surfaces, and the internal IT team can execute remediation with guidance.

Tier 2 · SOC-backed

SOC-backed operating tier

Full security operations depth for environments that require deeper investigation, broader telemetry and after-hours response authority.

  • Everything in the standard tier
  • Deeper investigation capability: scope, cause and affected systems determined before escalation
  • Proactive threat hunting for activity that has not yet triggered a detection rule
  • Under 8-minute mean time to respond on high-severity confirmed incidents
  • Broader telemetry coverage across network and cloud where required
  • Pre-authorised containment actions executed without waiting for client authorisation at 2am
  • 100+ threat experts in the SOC layer, including Australian hunt and response presence

Best suited to environments with regulated or sensitive data, higher complexity, multi-site exposure, or a risk profile that requires the service to carry full response authority, not just guidance.

The numbers behind the SOC

Performance indicators for the SOC-backed operating tier.

The metrics below describe the SOC-backed tier, the deeper operating model available where the environment requires full security operations depth. They are indicative of typical performance in the SOC layer and do not apply to every managed cyber security scenario; the standard tier is operated at a different cadence. The point is that the right level of response is matched to the environment, rather than every organisation paying for depth they do not need.

<1%
False positive rate
Analysts investigate real threats. Noise is filtered before it reaches the client team.
8min
Mean time to respond
On high-severity confirmed incidents in the SOC-backed tier.
100+
Threat experts in the SOC layer
Including Australian hunt and response presence.
24/7
Continuous analyst coverage
Not an inbox. Not on-call. Not business hours only.
Where threats actually enter

Detection and response coverage across the full environment.

Most incidents in Australian environments do not start at the endpoint. They start with a compromised credential, a misconfigured identity permission, a risky app consent or an email that bypassed standard controls. Coverage needs to match where threats actually enter, not where it is easiest to deploy a sensor.

01
EndpointDevice-level telemetry and detection.
Process execution, network connections, file activity and persistence mechanisms. EDR-layer detection with analyst oversight. Works with existing Microsoft Defender for Endpoint, SentinelOne or Sophos deployments where supported, or deploys a new agent where required.
02
Identity and Microsoft 365Credential and account compromise detection.
Microsoft 365 and Entra ID monitoring for anomalous authentication, impossible travel, privilege escalation, consent grant abuse and legacy authentication exceptions still active. Credential compromise is the most common initial access vector for ransomware and BEC in Australian environments; identity is monitored as the primary attack surface, not as a secondary check.
03
Email and business email compromise indicatorsThe vector behind most fraudulent payment events.
Detection of forwarding rules, impersonation patterns, rogue app consent, unusual send behaviour and tenant-level email exposure. Email remains the consistent initial vector for BEC attacks that result in fraudulent payment, data exfiltration and supply-chain compromise.
04
Backup recoverability and ransomware readinessRecovery treated as part of the security model.
Backup coverage including Microsoft 365 data, immutable backup posture, restore evidence and ransomware recovery sequencing. Detection and response is connected to recovery capability, not treated as a separate problem. Where a defensible recovery position is the primary need, the Recovery Readiness Assessment is the deeper engagement.
05
Security evidence and reportingOperationally usable, not a raw dashboard dump.
Monthly reporting on detection activity, incidents handled, response times, identity hygiene, Microsoft 365 posture changes and backup recoverability. Structured for board reporting, insurer submissions, customer due diligence and Essential Eight governance.
How we run it

From scope to operational coverage in four steps.

Managed cyber security is shaped around the environment. The four steps below describe how the engagement moves from scoping to ongoing operating cadence.

1
Scope and onboard

The scoping work establishes the current state across identity, endpoints, Microsoft 365, backup and existing tools. Tier is confirmed. Platforms are onboarded or operationalised. Baselines are established so detection rules and identity policies are tuned to the environment from day one.

2
Stabilise the priority controls

Before continuous operation begins, Inlight IT strengthens the areas that create immediate operational risk: typically identity hygiene, Microsoft 365 hardening, endpoint coverage, backup recoverability and privileged access. The first weeks reduce the highest-probability exposures rather than waiting for the steady state to surface them.

3
Monitor, triage and respond

Continuous telemetry review and alert triage, 24/7 across identity, endpoint and Microsoft 365. False positives filtered before reaching the client team. Genuine threats escalated immediately with clear investigation findings, not raw alert data. Confirmed incidents are investigated to determine scope, affected systems and likely cause. Containment actions within the agreed pre-authorised scope are executed. Inlight IT coordinates client communication and remediation through to closure.

4
Report, improve and govern

Monthly reporting on detection activity, incidents handled, response times, identity and Microsoft 365 posture changes, backup recoverability and remediation progress. Structured for board reporting, insurer submissions and Essential Eight governance. Findings feed into the next cycle of posture improvement.

Why Inlight IT

Security operated by the team that understands the environment around it.

Cyber security is stronger when it is connected to the environment being protected. Identity, endpoints, Microsoft 365, networks, backups, infrastructure and user support all shape the security outcome. Inlight IT brings those layers together through an engineering-led operating model. The first question is not which logo is already installed. It is whether the environment is actually being monitored and acted on with enough coverage and clarity for the risk profile.

01

Tiered to the environment

Not one-size-fits-all. The service is scoped around the environment to determine whether the standard operating tier or the SOC-backed tier is the right fit. Service depth is matched to the risk profile and complexity, not priced against a user count.

02

Works with existing tooling

Microsoft Defender for Endpoint, SentinelOne, Sophos, Microsoft 365 security tooling, backup platforms and firewall systems. Where existing tools are supported, they become the operational layer rather than being replaced. Tool replacement is a deliberate decision, not a default starting position.

03

Inlight IT remains the accountable operating layer

Where the SOC-backed tier is in scope, the SOC detection layer operates behind the service. Inlight IT remains the client-facing accountable layer for escalation, coordination and remediation. The relationship does not get handed off to a global SOC inbox.

04

Australian oversight throughout

Hunt and response presence in Australia. Inlight IT manages the client relationship, escalation and remediation locally. The SOC detection layer operates globally with Australian engineering oversight at the point of response.

05

Reporting that is operationally usable

Monthly reporting structured for board, insurer, customer due diligence and Essential Eight governance use. Not a raw dashboard dump. Designed to be referenced by people who need to make decisions, not just received.

06

Recovery is part of the model

Detection and response is connected to backup, restore capability and ransomware recovery readiness. The recovery question is not deferred to a separate conversation or a separate provider.

When to act: a cyber insurance renewal asking for 24/7 monitoring and response evidence the current model cannot produce cleanly; an incident that revealed detection-to-response measured in days; Essential Eight ML2 controls in place but no operating detection layer alongside them; a key person with informal security awareness leaving; a co-managed or MSP arrangement with no security operations above the helpdesk layer; Microsoft 365 drifting without active governance; customer or government due diligence requesting evidence of continuous monitoring; or an organisation that has outgrown reactive security support but does not need to build an internal security operations function.

Common questions

Questions that come up before this conversation starts.

What happens in a scoping conversation?

A scoped review of the current state of security operations in the environment. It covers what is already in place, where the operating gaps are, which tier fits, and what onboarding would look like. It is not a sales presentation. The outcome is a clear picture of where the security operating layer currently sits and what the right service model looks like.

How is managed cyber security different from what's already in managed IT?

Managed IT includes security at the operational baseline: patching, MFA, endpoint deployment, backup configuration, Microsoft 365 administration and routine monitoring. Managed cyber security is the deeper security operating layer: continuous detection, analyst-led alert triage, SOC-backed depth where required, Microsoft 365 security posture management, backup recoverability verification and insurer-grade evidence. Most organisations engage both. Some engage managed cyber security alongside an existing internal IT team or a separate MSP.

Is this the same as MDR?

Managed detection and response is the detection-and-response component of managed cyber security. The broader service also covers identity governance, Microsoft 365 security operation, backup recoverability oversight, evidence production and escalation coordination across the full posture. For background on what MDR is and how it compares to EDR, SIEM and an internal SOC, the Managed Detection and Response explainer covers it. This page is where the broader service is scoped.

Do we need to replace our existing security tools?

Usually not. In most environments the better outcome is operating what is already in place properly. Microsoft Defender for Endpoint deployed through M365 Business Premium or E5, SentinelOne, Sophos and existing backup or firewall platforms can often serve as the operational layer rather than being replaced. Tool replacement, where it makes sense, is a deliberate decision.

What is the difference between the standard tier and the SOC-backed tier?

The standard tier provides continuous identity, endpoint and Microsoft 365 monitoring, alert triage, guided containment and monthly reporting. It covers the most common operating requirements for organisations without a dedicated security team. The SOC-backed tier adds deeper investigation, threat hunting, under 8-minute mean time to respond on high-severity incidents, broader telemetry and pre-authorised containment authority. The scoping work determines which tier fits.

Can this work alongside our internal IT team?

Yes. Inlight IT operates as the managed security layer alongside an internal IT team. The internal team retains business context and day-to-day control. Inlight IT provides the security operations depth, escalation pathways, reporting and specialist remediation capability that the internal team does not have the scale to build or sustain on its own.

Does this help with cyber insurance?

Yes. Insurers are increasingly asking for specific evidence of 24/7 monitoring, MFA coverage, alert triage process, incident response capability, backup testing and recovery readiness. Managed cyber security produces defensible evidence and reduces reliance on assurances that no longer satisfy underwriters at renewal.

Is managed cyber security the same as a SOC?

Not exactly. A SOC is a capability: the people, processes and tooling used to monitor, detect and respond. It can be internal, managed or hybrid. The SOC-backed tier of managed cyber security has a full security operations centre operating behind the detection layer. The standard tier provides continuous detection and response without full SOC depth. The right model depends on the environment and how much response authority the organisation needs the service to carry.

How quickly can the service be operational?

Initial coverage on the priority controls typically begins within two to four weeks of scope agreement. Broader operating cadence is established over the first sixty to ninety days. Building an equivalent internal capability typically takes twelve to twenty-four months to hire, tool and reach operational maturity.

Does this replace an Essential Eight Assessment or a Recovery Readiness Assessment?

No. Those assessments establish a position at a point in time: a maturity baseline or a defensible recovery position. Managed cyber security operates, evidences and improves the controls that support a defensible posture continuously. The two work together: assessment establishes the position, managed cyber security holds it and improves it.

Practical next step

Build the right security operating layer around your environment.

Discuss Managed Cyber Security