SECURE · CONNECT · PERFORM
The full managed-protection layer

Security Plus.

Pro, plus continuous network scanning, vulnerability remediation help, endpoint protection, phishing simulation, dark web monitoring, and a quarterly posture review with a US-based senior engineer.

WHO
Insurance agencies, financial-services SMBs, healthcare-adjacent businesses, and any company whose customers, carriers, or regulators expect a serious security posture.
INCLUDES
Everything in Pro, plus continuous network-wide vulnerability scanning, remediation assistance, endpoint and workstation protection, phishing simulation and training, dark web monitoring, optional dual-firewall/DMZ configurations, and quarterly posture review.
TERMS
Annual, 3-year, or 5-year. Multi-year terms include rate locks against the year-over-year tightening of cyber-insurance requirements.
PRICING
Roughly 60–70% of comparable enterprise-class coverage at this tier. Quoted per network after we know what we are protecting.

What’s included

  • Everything in Pro
  • Continuous internal-to-external vulnerability scanning
  • Active assistance remediating vulnerabilities found in scans
  • Endpoint and workstation protection layer
  • Phishing simulation and end-user training
  • Dark web monitoring for credentials tied to your domain
  • Optional dual-firewall / DMZ-style configuration
  • Quarterly security posture review with a US-based senior engineer
  • Compliance-aware reporting (carrier renewals, NAIC, GLBA, SOC 2-readiness)

What Security Plus does NOT include

  • Active incident response engagements. Same boundary as the other tiers — incidents are unpredictable and expensive, and we scope and quote them separately so the cost is visible.
  • Penetration testing as a primary engagement. We can coordinate with a third-party pen test or recommend a partner.
  • Forensic investigation post-incident. That is its own discipline, scoped separately.
  • 24/7 SOC services. Security Plus is continuous monitoring with quarterly review — not a SOC, and we do not pretend to be one.
Right fit

Who Security Plus is right for.

Hero 1

Insurance agencies

Selling or holding cyber-insurance policies. Carrier requirements tighten every renewal cycle — Security Plus is the posture that answers them.

Hero 2

Financial & healthcare-adjacent SMBs

Handling sensitive customer or patient data. Auditors and customers want documented controls; Security Plus produces them as a normal part of the work.

Hero 3

Companies preparing for SOC 2 or enterprise procurement

Vendor-security questionnaires. Owners who want to sleep at night and have an answer when a customer asks “what are you doing about security?”

CORE FIREWALL ENDPOINT PHISHING TRAINING DARK WEB

Defense in depth, in writing

Layered protection — firewall, vulnerability scanning, endpoint, phishing training, dark web monitoring — documented in a quarterly report your insurer or auditor can read.

Q1 POSTURE REVIEW
Vulnerability scan results SIGNED
Endpoint protection coverage SIGNED
Phishing test — click rate 4% SIGNED
Carrier questionnaire ready SIGNED

Quarterly posture review

A US-based engineer reviews your full security posture every quarter. The report is plain English. You can hand it to your carrier, your auditor, or your board.

Common questions

The five questions we get most.

How is Security Plus different from a SOC?
A SOC (Security Operations Center) is a dedicated 24/7 team of incident responders who actively chase and contain attacks in progress. Security Plus is continuous monitoring + quarterly engineering review + active remediation help — not 24/7 incident chasing. For most SMBs, a SOC is overkill and over budget; Security Plus is the right shape. If you genuinely need a SOC, we will tell you and refer you.
Will Security Plus help us pass a cyber-insurance renewal questionnaire?
Yes, in most cases. The included monitoring, scanning, training, and reporting cover most line items on a typical cyber renewal questionnaire from Coalition, Travelers, Chubb, AIG, Hiscox, and the major insurance industry carriers. Where a specific control we do not provide is required, we will say so and recommend the cleanest path.
Can you handle our compliance audit directly?
We support compliance audits and produce the network-and-firewall-side documentation. Full audit handling typically involves your accountant or a compliance consultant — we partner with both, and the documentation we provide is designed to plug into their workflow.
What is the dual-firewall / DMZ option?
An older, well-proven design where two firewalls in series create a “demilitarized zone” between your network and the public internet — what banks have used for decades. It used to be expensive; with VectorLogic hardware it is no longer. For higher-trust environments (insurance, finance, healthcare-adjacent) it can be a quietly powerful brand answer to “show your work” questions on insurance renewals.
Does the AI make any decisions on its own?
No. No automated decision changes a customer’s production firewall configuration without a human engineer reviewing it. The AI handles speed and volume — flagging anomalies, prioritizing what humans should look at, drafting recommended actions. The engineer is always the one who acts. That separation is brand-critical and we will not relax it.

Talk to us about Security Plus.

A short conversation. We learn what your customers, carriers, and regulators expect of you — and tell you straight whether Security Plus is the right answer or whether Pro is enough today.