Managed Cyber Security: the tools exist in most environments. The operating layer around them often does not.
Continuous monitoring, alert triage, configuration-drift control, identity hygiene, recovery verification and a response process that works at 3am, not just in business hours — that is the operating layer most environments lack. Inlight IT delivers managed cyber security with the depth matched to your environment and risk.
- Tiered to the environment
- Works with existing tooling
- Australian oversight throughout
- Recovery is part of the model
The situations that make the operating gap impossible to ignore.
Cyber security risk in many Australian organisations does not sit in the absence of tools. It sits in the gap between tools being deployed and tools being actively operated. The situations below are where that gap usually becomes visible.
Managed IT covers the security baseline. Managed cyber security is the deeper operating layer above it.
Inlight IT's managed IT service already includes security at the operational baseline. Patching, MFA, endpoint deployment, backup configuration, Microsoft 365 administration and routine monitoring are part of how the IT environment is managed. For many organisations, that baseline is enough.
Managed cyber security is the deeper operating layer for environments that need more than baseline. Continuous detection across identity and endpoints. Analyst-led alert triage with response coordination. Microsoft 365 security posture managed actively, not just administered. Backup recoverability verified, not just configured. SOC-backed operating depth where the risk profile requires it. Insurer-grade evidence produced as part of operations, not assembled at renewal.
The two services are designed to work together. Most organisations engage both: Inlight IT delivers managed IT with managed cyber security operating as the security layer on top of it. Some organisations engage managed cyber security alongside an existing internal IT team, or alongside a separate MSP that handles general IT. The service is shaped to either model.
Two operating tiers. The right depth depends on the environment.
Not every environment requires the same depth of security operations. Some need a leaner continuous-monitoring model with guided response. Others need a SOC-backed operating layer with deeper investigation capability, after-hours response authority and broader telemetry. The service is scoped around the environment: which tier fits, what coverage is required and how much operating depth the risk profile justifies.
Standard operating tier
Continuous monitoring and guided response across identity, endpoints and Microsoft 365.
- Continuous monitoring across endpoint and identity signals
- Alert triage with real threats escalated and noise filtered before it reaches the client team
- Guided containment and response coordination on confirmed incidents
- Microsoft 365 and Entra ID identity coverage included
- Tenant security review, conditional access hygiene and risky app consent monitoring
- Backup recoverability oversight and Microsoft 365 backup where required
- Monthly reporting suitable for management, insurer questionnaires and Essential Eight governance
Best suited to environments where identity, endpoint and Microsoft 365 are the primary control surfaces, and the internal IT team can execute remediation with guidance.
SOC-backed operating tier
Full security operations depth for environments that require deeper investigation, broader telemetry and after-hours response authority.
- Everything in the standard tier
- Deeper investigation capability: scope, cause and affected systems determined before escalation
- Proactive threat hunting for activity that has not yet triggered a detection rule
- Under 8-minute mean time to respond on high-severity confirmed incidents
- Broader telemetry coverage across network and cloud where required
- Pre-authorised containment actions executed without waiting for client authorisation at 2am
- 100+ threat experts in the SOC layer, including Australian hunt and response presence
Best suited to environments with regulated or sensitive data, higher complexity, multi-site exposure, or a risk profile that requires the service to carry full response authority, not just guidance.
Performance indicators for the SOC-backed operating tier.
The metrics below describe the SOC-backed tier, the deeper operating model available where the environment requires full security operations depth. They are indicative of typical performance in the SOC layer and do not apply to every managed cyber security scenario; the standard tier is operated at a different cadence. The point is that the right level of response is matched to the environment, rather than every organisation paying for depth they do not need.
Detection and response coverage across the full environment.
Most incidents in Australian environments do not start at the endpoint. They start with a compromised credential, a misconfigured identity permission, a risky app consent or an email that bypassed standard controls. Coverage needs to match where threats actually enter, not where it is easiest to deploy a sensor.
From scope to operational coverage in four steps.
Managed cyber security is shaped around the environment. The four steps below describe how the engagement moves from scoping to ongoing operating cadence.
The scoping work establishes the current state across identity, endpoints, Microsoft 365, backup and existing tools. Tier is confirmed. Platforms are onboarded or operationalised. Baselines are established so detection rules and identity policies are tuned to the environment from day one.
Before continuous operation begins, Inlight IT strengthens the areas that create immediate operational risk: typically identity hygiene, Microsoft 365 hardening, endpoint coverage, backup recoverability and privileged access. The first weeks reduce the highest-probability exposures rather than waiting for the steady state to surface them.
Continuous telemetry review and alert triage, 24/7 across identity, endpoint and Microsoft 365. False positives filtered before reaching the client team. Genuine threats escalated immediately with clear investigation findings, not raw alert data. Confirmed incidents are investigated to determine scope, affected systems and likely cause. Containment actions within the agreed pre-authorised scope are executed. Inlight IT coordinates client communication and remediation through to closure.
Monthly reporting on detection activity, incidents handled, response times, identity and Microsoft 365 posture changes, backup recoverability and remediation progress. Structured for board reporting, insurer submissions and Essential Eight governance. Findings feed into the next cycle of posture improvement.
Security operated by the team that understands the environment around it.
Cyber security is stronger when it is connected to the environment being protected. Identity, endpoints, Microsoft 365, networks, backups, infrastructure and user support all shape the security outcome. Inlight IT brings those layers together through an engineering-led operating model. The first question is not which logo is already installed. It is whether the environment is actually being monitored and acted on with enough coverage and clarity for the risk profile.
01Tiered to the environment
Not one-size-fits-all. The service is scoped around the environment to determine whether the standard operating tier or the SOC-backed tier is the right fit. Service depth is matched to the risk profile and complexity, not priced against a user count.
02Works with existing tooling
Microsoft Defender for Endpoint, SentinelOne, Sophos, Microsoft 365 security tooling, backup platforms and firewall systems. Where existing tools are supported, they become the operational layer rather than being replaced. Tool replacement is a deliberate decision, not a default starting position.
03Inlight IT remains the accountable operating layer
Where the SOC-backed tier is in scope, the SOC detection layer operates behind the service. Inlight IT remains the client-facing accountable layer for escalation, coordination and remediation. The relationship does not get handed off to a global SOC inbox.
04Australian oversight throughout
Hunt and response presence in Australia. Inlight IT manages the client relationship, escalation and remediation locally. The SOC detection layer operates globally with Australian engineering oversight at the point of response.
05Reporting that is operationally usable
Monthly reporting structured for board, insurer, customer due diligence and Essential Eight governance use. Not a raw dashboard dump. Designed to be referenced by people who need to make decisions, not just received.
06Recovery is part of the model
Detection and response is connected to backup, restore capability and ransomware recovery readiness. The recovery question is not deferred to a separate conversation or a separate provider.
When to act: a cyber insurance renewal asking for 24/7 monitoring and response evidence the current model cannot produce cleanly; an incident that revealed detection-to-response measured in days; Essential Eight ML2 controls in place but no operating detection layer alongside them; a key person with informal security awareness leaving; a co-managed or MSP arrangement with no security operations above the helpdesk layer; Microsoft 365 drifting without active governance; customer or government due diligence requesting evidence of continuous monitoring; or an organisation that has outgrown reactive security support but does not need to build an internal security operations function.
Cybersecurity work across controls, monitoring and response
Questions that come up before this conversation starts.
What happens in a scoping conversation?
A scoped review of the current state of security operations in the environment. It covers what is already in place, where the operating gaps are, which tier fits, and what onboarding would look like. It is not a sales presentation. The outcome is a clear picture of where the security operating layer currently sits and what the right service model looks like.
How is managed cyber security different from what's already in managed IT?
Managed IT includes security at the operational baseline: patching, MFA, endpoint deployment, backup configuration, Microsoft 365 administration and routine monitoring. Managed cyber security is the deeper security operating layer: continuous detection, analyst-led alert triage, SOC-backed depth where required, Microsoft 365 security posture management, backup recoverability verification and insurer-grade evidence. Most organisations engage both. Some engage managed cyber security alongside an existing internal IT team or a separate MSP.
Is this the same as MDR?
Managed detection and response is the detection-and-response component of managed cyber security. The broader service also covers identity governance, Microsoft 365 security operation, backup recoverability oversight, evidence production and escalation coordination across the full posture. For background on what MDR is and how it compares to EDR, SIEM and an internal SOC, the Managed Detection and Response explainer covers it. This page is where the broader service is scoped.
Do we need to replace our existing security tools?
Usually not. In most environments the better outcome is operating what is already in place properly. Microsoft Defender for Endpoint deployed through M365 Business Premium or E5, SentinelOne, Sophos and existing backup or firewall platforms can often serve as the operational layer rather than being replaced. Tool replacement, where it makes sense, is a deliberate decision.
What is the difference between the standard tier and the SOC-backed tier?
The standard tier provides continuous identity, endpoint and Microsoft 365 monitoring, alert triage, guided containment and monthly reporting. It covers the most common operating requirements for organisations without a dedicated security team. The SOC-backed tier adds deeper investigation, threat hunting, under 8-minute mean time to respond on high-severity incidents, broader telemetry and pre-authorised containment authority. The scoping work determines which tier fits.
Can this work alongside our internal IT team?
Yes. Inlight IT operates as the managed security layer alongside an internal IT team. The internal team retains business context and day-to-day control. Inlight IT provides the security operations depth, escalation pathways, reporting and specialist remediation capability that the internal team does not have the scale to build or sustain on its own.
Does this help with cyber insurance?
Yes. Insurers are increasingly asking for specific evidence of 24/7 monitoring, MFA coverage, alert triage process, incident response capability, backup testing and recovery readiness. Managed cyber security produces defensible evidence and reduces reliance on assurances that no longer satisfy underwriters at renewal.
Is managed cyber security the same as a SOC?
Not exactly. A SOC is a capability: the people, processes and tooling used to monitor, detect and respond. It can be internal, managed or hybrid. The SOC-backed tier of managed cyber security has a full security operations centre operating behind the detection layer. The standard tier provides continuous detection and response without full SOC depth. The right model depends on the environment and how much response authority the organisation needs the service to carry.
How quickly can the service be operational?
Initial coverage on the priority controls typically begins within two to four weeks of scope agreement. Broader operating cadence is established over the first sixty to ninety days. Building an equivalent internal capability typically takes twelve to twenty-four months to hire, tool and reach operational maturity.
Does this replace an Essential Eight Assessment or a Recovery Readiness Assessment?
No. Those assessments establish a position at a point in time: a maturity baseline or a defensible recovery position. Managed cyber security operates, evidences and improves the controls that support a defensible posture continuously. The two work together: assessment establishes the position, managed cyber security holds it and improves it.