FIG. 04 The method

Six days from contract to your first incident under watch.

Most managed-security engagements take a quarter. Ours take a week. We've factored every step of onboarding — assess, instrument, baseline, go-live — into a tight, repeatable runbook so your team can get on with running the business.

§ 01Onboarding · 6 days

A typical IronCastle onboarding, day-by-day.

No statement of work negotiations. No professional services engagement. We meet on Monday and your environment is under live monitoring by Friday — your owner's first weekly digest lands the following Tuesday.

MONTUEWEDTHUFRISATMON+1
DiscoveryYou + your CSM
90 min
Connector installCloud · identity · EDR
SaaS & cloud connectors
Endpoint deployAgent push to fleet
MDM-pushed
Baseline learningBehavioural fingerprint
14-day rolling, starts here
Tabletop exerciseSimulated incident
Live drill
Go-liveActive monitoring
24×7×365 watch begins
First weekly digestTo the owner's inbox
Tuesday, 8am
§ 02The six phases, in detail

Each phase has a clear owner, a clear deliverable, and a clear time-box.

No stage takes longer than 48 hours. Every artefact you'll need for SOC 2, ISO 27001, and cyber-insurance is generated as a by-product.

I
PHASE 01 · DAY 1 · 90 MIN

Discovery call.

OWNER: Customer Success Manager · DELIVERABLE: Risk profile + onboarding plan

A single 90-minute conversation. We learn what your business does, what data matters, what tools you already run. You leave with a written plan.

Asset inventory ~20 min

Endpoints, cloud accounts, identity provider, business-critical SaaS, where the crown-jewel data lives.

Threat model ~30 min

Industry-specific threat profile (BEC for professional services, ransomware for logistics, etc.).

Compliance scope ~20 min

What frameworks you need to meet — SOC 2, ISO 27001, HIPAA, IRAP, ADGM — and which controls we cover.

Plan + price-lock ~20 min

You leave with a one-page onboarding plan and a price locked for 24 months.

II
PHASE 02 · DAY 1–2 · ASYNC

Connector install.

OWNER: Your IT lead + IronCastle SE · DELIVERABLE: SaaS, cloud, identity telemetry flowing

Connect your identity, cloud, and SaaS sources via OAuth and read-only roles — no API keys to manage. Most customers finish this in well under a day of IT-lead time.

OAuth-based, where possible 40+ apps

No service accounts to manage. Every connector is OAuth, scoped, and revocable.

Read-only by default Least-privilege

Telemetry connectors never have write scopes. Response actions use a separate, opt-in role.

Terraform module, optional For cloud-native shops

If you prefer infrastructure-as-code, our Terraform module provisions the AWS/GCP roles in 4 lines.

Network appliance, optional For on-prem

For environments without cloud SIEM, a small forwarder VM ships logs over mTLS to our ingestion fabric.

III
PHASE 03 · DAY 2–3 · ASYNC

Endpoint deploy.

OWNER: Your IT lead via MDM · DELIVERABLE: Agent on every supported device

A signed agent package pushed via your existing MDM (Intune, Jamf, Kandji, JumpCloud). No user action. No reboot. Median deployment: 22 minutes from package upload to 100% fleet coverage on a 200-device tenant.

Lightweight, by design ≤ 90 MB RAM idle

The agent collects telemetry; detection runs server-side. Battery and CPU impact is measured in tenths of a percent.

Tamper-resistant Signed + sealed

Agent integrity verified at every check-in. Removal requires customer-portal authorisation.

Bring your own EDR

Already running an EDR you like? We layer on top — our agent becomes optional supplemental telemetry. No rip-and-replace.

Hardened OS images, opt-in For new devices

For customers who let us help with onboarding new laptops, we ship CIS-benchmark-aligned baseline images.

IV
PHASE 04 · DAY 3 ONWARD · 14 DAYS

Baseline learning.

OWNER: IronCastle correlation engine · DELIVERABLE: Per-tenant behavioural fingerprint

For 14 days, the model learns what "normal" looks like for your business — login patterns, working hours, geographies, app usage, file movement. By day 14, anomaly scoring is calibrated to your tenant. Detection sensitivity is then tuned with you, not for you.

Per-user fingerprints ~24 features

Login times, geos, devices, MFA habits, app reach, data-egress patterns.

Per-host fingerprints ~36 features

Process trees, scheduled tasks, network destinations, parent-child binary lineage, signing chains.

Per-tenant fingerprints Macro signals

Aggregate working-hours envelope, payroll cycles, M&A noise, vendor patterns. Used to score escalation context.

Day-1 detections Universal rules

While baselines learn, ~120 universally-true detections (known bad IoCs, signed-malware hashes, suspicious OAuth grants) run from minute one.

V
PHASE 05 · DAY 5 · 60 MIN

Tabletop exercise.

OWNER: IronCastle Tier 3 + your owner · DELIVERABLE: Approved response runbook

Before we go live, we run a simulated incident on your environment — a fake compromised laptop, a fake exposed credential, a fake suspicious payment. You decide who in the business gets paged for what, what we can act on automatically, and what needs a human approval.

Three scenarios BEC · ransomware · insider

Tailored to your industry. We've run thousands of these — your scenarios will feel uncomfortably familiar.

Your contact tree Locked in

Who gets paged at 3am? Who's the backup? What's the SMS vs phone-call threshold? Documented and tested.

Auto-response permissions Configurable

For each detection class, you choose: notify-only, propose-and-approve, or pre-authorised auto-action.

Insurance-ready artefact PDF for your broker

The tabletop output is exactly the artefact most cyber-insurance carriers ask for at renewal.

VI
PHASE 06 · DAY 6 · 9AM LOCAL

Go-live.

OWNER: IronCastle SOC, on-shift · DELIVERABLE: 24×7×365 active monitoring

No fanfare. The SOC takes ownership. Your customer portal lights up. The on-shift Tier 2 introduces themselves over a 5-minute call. The first weekly digest lands in the owner's inbox the following Tuesday at 8am local time.

Hand-off call ~5 min

Meet the on-shift analyst. Confirm contact tree. Get a direct phone number that's manned, always.

Portal access SSO + MFA

Owner, IT lead, finance lead — each with the right view. SAML-based for Keep and Citadel.

First incident SLA Minutes, by tier

Whatever fires first — even a low-severity policy nudge — gets human eyes inside your tier's response SLA.

30-day check-in Calendared

Your CSM books a 30-day review on day 6. We measure what we promised against what happened.

§ 03After go-live

What happens day 7 and every day after.

Onboarding is the easy part. The work is in the years that follow — staying calibrated as your business changes, your tooling drifts, and the threat landscape moves.

DAILY

24×7 watch.

Tier 1 / Tier 2 analysts on shift in Sydney and Dubai, with Tier 3 on call. Someone is always reading your alerts.

  • Coverage maintained through public holidays and weekends
  • Critical alerts triaged against your tier's response SLA
  • Auto-response actions audited each shift change
WEEKLY

Owner's digest.

Tuesday 8am local. One page. Score, three fixes, anything noteworthy. Read in three minutes between coffees.

  • Plain English — no MITRE codes, no acronyms
  • Quantified risk delta vs. previous week
  • Forwardable to your board, broker, or auditor
MONTHLY

Posture review.

A 30-minute video call with your CSM. Review fleet score, retire stale risks, queue up next month's three fixes.

  • Compliance evidence pack auto-generated
  • Detection sensitivity re-tuned per noise/signal data
  • Open feature requests reviewed and prioritised
QUARTERLY

Live tabletop.

A fresh simulated incident. Different scenario. Sharpens your contact tree. Refreshes your auto-response policy.

  • Scenarios calibrated to current threat intel
  • Insurance-renewal-ready output
  • Optional: red-team add-on for Keep / Enterprise
CONTINUOUS

Detection R&D.

Our detection engineering team ships new rules and model improvements every week. They light up across your tenant automatically — no upgrade window.

  • ~30 new detections shipped per month, fleet-wide
  • Backtested against last 90 days of telemetry before release
  • Public changelog with severity, scope, and rationale
ON DEMAND

Talk to a human.

A button in the portal. A phone number on every page. A direct Slack/Teams channel if you want one.

  • Portal "Contact analyst" routes to the on-shift SOC, not a queue
  • Phone line answered by SOC, not call centre
  • Shared channel option for Keep & Enterprise
§ 04How we operate

The three principles behind the runbook.

Method exists because we have a strong opinion about what good managed security looks like for an SMB. These are the three positions we won't compromise on.

01

Quiet by default.

If we wake you up, it's worth waking up for. We hold ourselves to a strict noise budget per tenant per month. If we exceed it, we tune ourselves before tuning your patience.

02

Plain English, always.

Every owner-facing artefact passes a readability check before it ships. If a non-technical board member can't read your monthly report in 90 seconds, we've failed.

03

Humans in the loop.

AI proposes; analysts approve. We will never auto-action high-impact responses without explicit, customer-configured pre-authorisation. The model serves the analyst, not the other way around.