A Fortify 24x7 brand. Private client technology, managed quietly.Client accessReach us
Celebrity CloudServices
Home / The service list / Family III · The watch that does not sleep
Family III · The watch that does not sleep

A staffed watch on every machine.

One agent on each machine, with analysts sitting behind it. The three tiers differ in how much surrounding evidence we collect and how far our people go on your behalf before anybody is telephoned.

Choose from this family6 lines · billed monthly, in advance
Managed Detectionper computer · Fortify-MDR
Loading QTY
Extended Detectionper computer · Fortify-XDR
Loading QTY
Extended Detection, Fullper computer · Fortify-XDR+
Loading QTY
Managed Detection, Containersper Kubernetes agent · Fortify-MDR-K8
Loading QTY
Extended Detection, Containersper Kubernetes agent · Fortify-XDR-K8
Loading QTY
Extended Detection, Full, Containersper Kubernetes agent · Fortify-XDR+K8
Loading QTY
('
IThe position

Software that finds something at three in the morning.

Every product in this category will tell you it detects. The question that decides whether detection was worth buying is what happens in the following nine minutes, and that question is answered by staffing, not by software.

Each of these lines places a SentinelOne agent on the machine and puts our security operations centre behind it. The agent watches behaviour rather than waiting to recognise a file it has seen before, which is the only approach that has ever worked against material written specifically for one target. Ransomware, credential theft and the fileless techniques that live entirely in memory all announce themselves by what they do, in a sequence that does not resemble a person working.

', '
IIThe tiers

What separates the three.

Managed Detection is the endpoint and the desk. The agent prevents and detects on the machine, and our analysts monitor and alert around the clock. For a household where the estate is a set of laptops and a couple of servers, this is a complete and proportionate answer.

Extended Detection widens the evidence. The same agent, at its Complete tier, is joined by telemetry from beyond the endpoint: mail, servers, cloud workloads in the major providers, network activity and directory events. That evidence is correlated in Fluency, the analytics platform our desk works inside, and correlating those layers converts four dull events into a single attributed sequence. A message opened at nine, a credential used from an unfamiliar address at ten, a directory role changed at ten past, and a process on a laptop at half past are one story, and only a system holding all four can say so.

Extended Detection, Full adds our direct remediation. At the lower tiers we detect, investigate and tell you, and act on your instruction. At this tier the desk acts on identified threats on your behalf within the authority you set in writing when you join.

', '
Authority

Who is allowed to take a machine off the network.

This is the part worth reading slowly, because for our clients an unnecessary isolation can be as disruptive as an incident. Pulling a laptop off the network at eleven at night is straightforward when it belongs to an accounts clerk and a serious decision when the person holding it is on stage in ninety minutes.

So we agree the authority in advance, in writing, and it can differ by device. Isolate the business machines without asking. Never isolate the principal\'s handset or laptop without a call to a named person first. Whatever the rule is, our analysts hold it and the audit record shows what was done, when, and under whose authority.

', '
IIIContainers

Where the K8 lines apply.

The three lines ending in K8 are the same service delivered by a Kubernetes agent, billed per agent, for estates that run containerised workloads. Production companies, media platforms and application ventures reach this point without ever intending to.

If no cluster exists anywhere in your world, ignore all three; nothing else in your protection leans on them. We would sooner write that plainly than let a list imply otherwise.

', '
ComparisonFortify-MDR · Fortify-XDR · Fortify-XDR+
Built onSentinelOne on the machine, with Fluency analytics behind the desk
Agent, Managed DetectionSentinelOne agent on the endpoint
Agent, Extended tiersSentinelOne Complete on the endpoint
DeskSecurity operations centre monitoring and alerting, twenty four hours, all year
Evidence, Managed DetectionEndpoint behaviour and process activity
Evidence, Extended tiersEndpoint, mail, servers, cloud workloads in the major providers, network and directory
Analytics, Extended tiersNext generation antivirus, endpoint detection, user and entity behaviour, cloud workload protection, traffic analysis on the network, and security information management
HuntingAnalysts hunting for threats, and alerting in real time
Response, Managed and ExtendedInvestigation and alerting, with action on your instruction
Response, Extended FullDirect remediation of identified threats by the desk, within the authority you set
AuthorityAgreed in writing at onboarding and recorded per device
BilledMonthly, for each computer
', '
SpecificationFortify-MDR-K8 · Fortify-XDR-K8 · Fortify-XDR+K8
Built onThe SentinelOne Kubernetes agent, with Fluency analytics behind the desk
DeploymentKubernetes agent, for containerised workloads
TiersThe three tiers above, delivered to the cluster
DeskThe same security operations centre and the same authority model
BilledMonthly, for each Kubernetes agent
', '

Where this family stops

Detection assumes the agent is installed and reporting, which is what management is for. It watches the machine, not the phone in your pocket, which is Phone Protection.

Retention windows, the exact telemetry sources connected for your estate, and the response authority per device are confirmed with you in writing during onboarding rather than asserted on this page. Estates differ, and a number printed here would be a guess.

')