Fortellar

The Next Generation of Managed Services

Silver is the middle tier of Fortellar's Managed Security Services. Automated provisioning and imaging, endpoint security posture and vulnerability monitoring, privileged access management, and framework mapping with a governed risk register.

Why This Matters

Operations running smoothly is not the same as being defended.

Traditional providers focus on uptime. We focus on assurance. Your tools tell you when a server goes down; they don't tell you when a credential has been stolen or a workload has drifted into exposure. The essentials are covered, but detection is shallow and compliance is an annual scramble.

Silver closes that gap. Endpoint posture watched, privileged access governed, provisioning automated, controls mapped to your frameworks, and a risk register that stays current. Full SOC-backed detection and response remains an add-on, so you buy the coverage you need.

What uptime monitoring won't tell you
01

Credential theft

Your tools report a server down. They don't report a stolen identity.

02

Misconfiguration

Workloads drift into exposure without ever affecting availability.

03

Lateral movement

An attacker already inside looks like normal traffic to an uptime monitor.

04

Compliance cadence

Evidence handled as an annual scramble instead of a continuous state.

Who Silver is for

Three situations where Enhanced Protection is the right tier.

Situation 01

You have the basics, but no real detection

Monitoring tells you when a device is offline, not when you've been compromised. No one is watching telemetry for lateral movement, stolen credentials, or a misconfigured workload, and there's no defined response if something surfaces.

The outcomeEnhanced endpoint security monitoring with posture reviews, configuration audits, and vulnerability and patch risk tracking, so deviations surface as alerts instead of audit findings. Full MDR and SOC service is available as an add-on.
Situation 02

Compliance is a fire drill, not a state

Every audit means weeks of screenshots and spreadsheets pulled together at the last minute. Evidence goes stale the moment it's collected, and you can never quite prove control coverage on demand.

The outcomeContinuous evidence collection and multi-framework control mapping, so SOC 2 and HIPAA readiness is a constant state instead of an annual scramble.
Situation 03

You need automation and resilience, not just tickets

Provisioning is still manual, backups are assumed rather than tested, and there's no real disaster-recovery plan. Growth is multiplying the work, and one bad day could take the business offline.

The outcomeTemplate-driven automated workflows plus managed backup & continuity with scheduled restore tests, so recovery is proven, not hoped for.
What's included in Silver

Everything in Bronze, plus automation, security posture, and governance

Everything Bronze runs, now with the manual work automated and the environment actually watched. Managed detection and response, 24×7 coverage, and full audit support remain add-ons or a step up to Gold.

Automated provisioning and imaging pipelines

Device imaging, enrollment, and user provisioning move from manual runbook to automated workflow, with template-driven provisioning and governance enforcement on new resources.

Enhanced endpoint security configuration and monitoring

Regular security posture reviews, configuration audits, and alerting when endpoints deviate from the hardened baseline.

Privileged access management

Least-privilege enforced and the privileged access lifecycle managed, so administrative rights are granted deliberately and removed on schedule.

Vulnerability and patch risk monitoring

Known vulnerabilities and patch status tracked continuously, with the highest-risk endpoints surfaced rather than discovered during an assessment.

Multi-framework control mapping with a risk register

Controls mapped across SOC 2, ISO, and HIPAA with gap analysis, alongside an organization-wide risk register with scoring and mitigation tracking.

Audit-ready evidence mapping and control narratives

Evidence mapped per control and narratives written as operations run, so fieldwork starts from a maintained record instead of a collection exercise.

Infrastructure backup, restore, and event logging

Backup and restore for infrastructure and shared resource data, plus event logging and baseline monitoring across on-premise and cloud.

IaC deployment with drift reconciliation

Deployments automated through infrastructure-as-code, with drift detected and the baseline state enforced instead of quietly diverging.

Where Silver sits

Enhanced Protection is the middle tier. Automation, security posture, and governance on the operational floor.

Every tier runs on the same unified MASP platform, so moving between them adds or removes capability without re-onboarding. Bronze is the operational foundation; Silver adds automated provisioning, endpoint security posture and vulnerability monitoring, privileged access management, framework mapping with a risk register, and infrastructure backup; Gold delivers full lifecycle management, integrated detection telemetry, and 24×7 support.

Bronze
Core Coverage

Manual support and baseline configurations for small teams getting started with managed services.

  • End-user support, business hours
  • Device imaging and enrollment
  • User onboarding and offboarding
  • Baseline endpoint protection
  • Cloud resource provisioning
  • On-premise and shared resources
View Bronze
Gold
Full Optimization

Full lifecycle management with integrated detection telemetry, incident triage, and 24×7 support.

  • 24×7 support and major incidents
  • EDR, CSPM, and SIEM monitoring
  • Security incident triage
  • Mock audits and coordination
  • Cost cleanup and rightsizing
  • Managed backup and continuity
View Gold
How it works

Four steps that turn a working floor into a governed program.

Step 01

Automate the floor

The manual Bronze runbooks become automated workflows. Imaging, enrollment, provisioning, and common service requests move to templates with governance enforcement, so growth stops multiplying the work.

You walk away with
  • Automated imaging, enrollment, and provisioning pipelines.
  • Template-driven resource provisioning with governance.
  • Common service requests handled without manual touch.
Step 02

Harden and watch the estate

Endpoint configuration audited against a hardened baseline, privileged access brought under management, and vulnerability and patch risk tracked continuously. Deviations become alerts rather than findings.

You walk away with
  • A hardened endpoint baseline with deviation alerting.
  • Privileged access under managed lifecycle.
  • Continuous vulnerability and patch risk tracking.
Step 03

Map controls to frameworks

Controls mapped across SOC 2, ISO, and HIPAA with gap analysis. The risk register is stood up and scored, and evidence mapping plus control narratives are produced as operations run.

You walk away with
  • A multi-framework control map with documented gaps.
  • An organization-wide risk register with mitigation tracking.
  • Evidence and control narratives maintained continuously.
Step 04

Govern the cadence

Backup and restore proven for infrastructure data, IaC drift reconciled against baseline, and a quarterly governance review that decides which add-ons the environment now justifies.

You walk away with
  • Backup and restore validated, not assumed.
  • IaC drift reconciled to a documented baseline.
  • A quarterly add-on and tier decision on record.
Cost calculator

Estimate your monthly and annual investment.

Adjust your headcount and tier to see a ballpark. Silver is priced per person, so the number scales cleanly with your team.

50 seats

Estimate only. Final pricing depends on environment complexity, compliance scope, and device count. We confirm everything in the discovery session.

Silver · Enhanced Protection
Estimated monthly
$26,300
Annual (billed yearly)
$315,600

Works out to $526 per person / month at the Silver tier.

Compare all tiers

Bronze, Silver, and Gold, side by side.

Bronze keeps the lights on. Silver is where you stop hoping nothing slipped through. Gold is where you stop thinking about it at all.

FeaturesBronzeSilverGold
On-Prem / Shared Resource SupportMaintain company-shared infrastructure and internal resources
Shared Resource Automation & Quota GovernanceAutomate shared resource allocation, quota adjustments, permission managementAdd-On
Full Infrastructure Lifecycle SupportFull support of shared resource infrastructure including provisioning, maintenance, decommission, lifecycle trackingAdd-OnAdd-On
Concierge Infrastructure ServicesCustom infrastructure support, hybrid on-prem/cloud resource coordination, SLA-backed maintenanceAdd-OnAdd-OnAdd-On
Infrastructure Backup & RestoreEnsure recovery of infrastructure data and shared resource dataAdd-On
Full Backup & Continuity ManagementManaged backups, retention policies, quarterly restore testsAdd-OnAdd-On
Dedicated DR & BCDR Infrastructure ManagementFull DR planning, failover support, hybrid cloud/on-prem DR orchestrationAdd-OnAdd-OnAdd-On
Infrastructure Event Logging & Basic MonitoringCollect logs and resource metrics for on-prem/cloud infrastructureAdd-On
Infrastructure Performance Monitoring & DashboardsMonitor CPU, storage, network usage; render dashboards for performance, capacity, utilizationAdd-OnAdd-On
Custom Infrastructure Analytics & Capacity ForecastingCustom reports, predictive capacity planning, custom alert thresholdsAdd-OnAdd-OnAdd-On
Device Imaging & EnrollmentEnsure devices are imaged with baseline configs and enrolled
Automated Imaging & Enrollment PipelinesAutomated imaging & enrollment pipelines for rapid device rollout—
Full Automated Imaging with ComplianceFully automated imaging/enrollment with compliance/hardening baselineAdd-OnAdd-On
Concierge-Level Custom ImagingConcierge-level imaging including custom configs, user-specific buildsAdd-OnAdd-OnAdd-On
User Account Provisioning / DeprovisioningManage user lifecycle (onboard, offboard)
Automated Provisioning WorkflowsAutomated provisioning / deprovisioning workflowsAdd-On
Full JML Workflow with License ManagementFull automated JML (Joiner-Mover-Leaver) workflow with license managementAdd-OnAdd-On
Concierge-Level Identity OperationsConcierge-level JML, custom role mappings, delegated admin supportAdd-OnAdd-OnAdd-On
End-User SupportProvide day-to-day user support and access request handling
Workflow Automation for Common RequestsAutomate repetitive support requests for efficiencyAdd-On
24×7 Support + Major Incident CoordinationProvide after-hours support and handle major incidentsAdd-OnAdd-On
Concierge / VIP Support / Dedicated TAMWhite-glove, high-touch support for VIP users or critical rolesAdd-OnAdd-OnAdd-On
IaC Deployment & Drift ReconciliationAutomate deployments via IaC, detect drift, enforce baseline stateAdd-On
IaC Template Creation & StandardizationBuild standardized Infrastructure-as-Code templates for cloud deploymentsAdd-OnAdd-On
IaC + Custom Module Development & GitOpsFull IaC customization, GitOps pipelines, branching, CI/CD, multi-env deploymentsAdd-OnAdd-OnAdd-On
Cloud VM/Storage/Network ProvisioningProvide compute, storage, network resource provisioning and basic maintenance
Template-Driven Provisioning & GovernanceUse standardized templates to provision resources with governance enforcementAdd-On
Full Cloud Resource Lifecycle & GovernanceComplete cloud resource management including updates, scaling, cleanupAdd-OnAdd-On
Bespoke Infrastructure EngineeringCustom resource templates, custom configs, hybrid cloud/on-prem blendsAdd-OnAdd-OnAdd-On
Rightsizing, Cost Cleanup & Waste ReductionIdentify unused resources, recommend cleanup, enforce cost hygieneAdd-OnAdd-On
Full Cost Governance & Budgeting AdvisoryBudget forecasting, spend forecasting, environment chargeback modelingAdd-OnAdd-OnAdd-On
Multi-Framework Control Mapping & Gap AnalysisMap controls to multiple frameworks (SOC 2, ISO, HIPAA), identify gapsAdd-On
Custom Framework / Regulation OnboardingMap custom or less-common regulations to control library, build governanceAdd-OnAdd-OnAdd-On
Enterprise Risk Register & GovernanceMaintain organization-wide risk register, risk scoring, mitigation trackingAdd-On
Expanded Risk Program with Continuous ReviewMulti-category risk coverage (operational, vendor, data, cloud), continuous reviewAdd-OnAdd-On
Full Risk & Compliance Program ManagementContinuous risk monitoring, control-to-risk mapping, remediation governanceAdd-OnAdd-OnAdd-On
Audit-Ready Evidence Mapping & Control NarrativesPrepare evidence mapping per control, generate control narrativesAdd-On
Audit Coordination & Mock AuditsCoordinate mock audits, internal reviews, evidence readiness checksAdd-OnAdd-On
Full Audit Support & Auditor Liaison ServiceManage audit prep end-to-end, evidence collection, formal audit coordinationAdd-OnAdd-OnAdd-On
Baseline Endpoint Protection & HygieneProvide basic endpoint security hygiene: AV/AM, baseline configuration
Enhanced Endpoint Security Configuration & MonitoringRegular security posture reviews, configuration audits, alerting on deviationsAdd-On
EDR / CSPM / SIEM Integration & MonitoringImplement EDR or CSPM, collect telemetry, monitor for threatsAdd-OnAdd-On
Managed Detection & Response (MDR) + SOC Services24/7 threat monitoring, incident response, containment, forensic readinessAdd-OnAdd-OnAdd-On
Privileged Access Management (PAM)Enforce least-privilege, manage privileged access lifecycleAdd-On
Advanced PAM, Conditional Access & Session ManagementFull privileged access workflows, session monitoring, conditional access policiesAdd-OnAdd-On
Concierge PAM / Custom Privileged Access ProgramFully managed custom privileged access program, custom policiesAdd-OnAdd-OnAdd-On
Vulnerability & Patch Risk MonitoringMonitor known vulnerabilities and patch status, highlight high-risk endpointsAdd-On
Security Incident Management & TriageTriage alerts, assess security incidents, coordinate containment & escalationAdd-OnAdd-On
Full SOC as a Service + Advanced Threat Hunting24/7 monitoring, threat hunting, alert correlation, forensic investigation readinessAdd-OnAdd-OnAdd-On
Expertise this work draws on

The components behind Enhanced Protection.

Technology & Security Operations

Endpoint Security Posture Monitoring

Configuration audits, posture reviews, and vulnerability and patch risk monitoring, and SOC-backed triage and containment, running on the same unified toolset that scales from Bronze through Gold.

See expertise
Technology & Security Operations

Workflow Automation & Provisioning

Template-driven onboarding, offboarding, and resource provisioning with governance enforcement, cutting time-to-service and eliminating configuration drift as teams grow.

See expertise
Cybersecurity & Compliance

Continuous Compliance & Evidence

Multi-framework control mapping and always-current evidence for SOC 2 and HIPAA, so audit readiness is a maintained state rather than an annual project.

See expertise
Cybersecurity & Compliance

Backup, Continuity & DR

Managed backups, retention policy, and scheduled restore tests, with disaster-recovery planning that makes recovery provable rather than assumed.

See expertise

Not sure Silver is the right tier? That's what the session is for.

Bring your headcount, your current IT arrangement, and any compliance obligations. We'll tell you honestly whether Bronze, Silver, or Gold fits, and what it would cost.