24x7 Staffed SOC
Endpoints, Users, and Microsoft 365
200+ Tenant Hardening Practices
Works With Your Current IT

Cybersecurity Services
in Minneapolis

Cyber criminals work 24x7. So does the team watching your network. McNallan managed security is a complete program for your users, endpoints, and Microsoft 365 tenant. Threats are investigated by a 24x7 staffed security operations center that isolates an attacked device before it spreads, applications run only when approved, and your tenant is hardened against a list of 200+ best practices that grows every quarter. Sold on its own or as part of McNallan managed IT, and it runs alongside the IT provider you already have. Need CMMC Level 2? That is a separate engagement.

Security Software Is Not Security. People Watching It Around the Clock Is.

Managed security is a security program run by people, not just software installed on your computers. Detection and response tooling goes on every endpoint and in your Microsoft 365 tenant, and it reports to a staffed security operations center that reads what it sees around the clock. A monitor going off is not protection. Someone has to be watching it, reading it, and deciding what it means, at 2 a.m. as much as 2 p.m. And when a real compromise is detected, the next few minutes decide how bad it gets: the attacked device is isolated at the kernel level, the account is locked, and the goal is to stop the spread before it turns into a rebuild. That is the job. McNallan takes responsibility for the endpoints, the tenant, and the backups, and the program is sold on its own or inside managed IT.
McNallan security engineer reviewing endpoint alerts for a Minnesota client

Already Have an IT Provider? This Still Applies.

Managed IT and managed security are not the same job. A good IT provider keeps things running. Security is a separate discipline with its own tooling, its own people, and its own response process, and many IT providers cannot add a security practice to what they already do.

McNallan runs managed security for organizations that keep their current IT provider. We take control of endpoint detection and response, the Microsoft 365 tenant, and the backups, because with those three in hand we can protect an environment even when everyday IT is not ours to manage.

If McNallan already manages your IT, this is the security layer inside it. If someone else does, it runs alongside them.

This Is for You If One of These Is True

Business owner reviewing what their IT provider actually covers for security

Security Is an Afterthought at Your Current Provider

Managed security runs alongside your current provider. They keep IT running; we take responsibility for security.
Cyber insurance questionnaire being completed with McNallan security controls in place

Your Insurance Renewal or a Customer Is Asking Questions

Every control in the program is one those forms ask about. You answer yes, with evidence.
McNallan technician isolating a compromised endpoint before ransomware spreads

You Would Rather Prevent an Incident Than Recover From One

McNallan has remediated ransomware events where entire networks were compromised, and has never had a client lose data or pay a ransom. Prevention costs less than the rebuild.

What’s Included in Managed Security

We pick each security tool for your endpoints, users, and Microsoft 365 tenant on its own merits, not as part of one vendor's bundle, then deploy it, manage it, and watch it around the clock, whether you have 20 computers or 300.

Managed Endpoint Detection and Response

A lightweight agent on Windows, Mac, and Linux backed by a 24x7 staffed security operations center. An active attack is investigated by people, and the device is isolated at the kernel level before it spreads.

Application Whitelisting and Ringfencing

Only approved applications run. Unapproved software is denied automatically, employee requests go through vetting, and applications can be fenced so they see the local network but not the internet, or the reverse.

Managed Detection for Microsoft 365

Active threat detection and immediate remediation inside your tenant, including identity protection and the ability to detect session theft, from the same 24x7 staffed SOC.

Managed Log Monitoring

AI-backed evaluation of logs from Active Directory, most firewalls, and most network gear, with 365 days of retention and built-in red flags for early alerting and remediation.

Managed Patching

Windows, Mac, and most third-party applications, patched on a weekly schedule for stability. Critical zero-day fixes are pushed immediately, with notice.

Security Awareness Training and Phish Testing

Short monthly video lessons with test questions employees have to pass, plus simulated phishing so you know who clicks. Clients who moved to it from their previous training platform recommend it every time.

Microsoft 365 Tenant Hardening

A list of 200+ best practices enforced in your tenant and improved every quarter, with a management portal that handles password resets, group changes, and mailbox sharing without handing out global admin rights.

Email Spam and Phish Filtering

Filtering for Microsoft 365 and Google Workspace with a very low false-positive rate, so nobody manages daily digests. Malicious email that slipped through is pulled from mailboxes fast.

What Customers Say About Us

How Managed Security Works

Deploy in Learning Mode

The outcome: a controlled rollout, one organization at a time, without disrupting work.

Watch and Respond, 24x7

The goal: catch an active attack early and contain it before it becomes a rebuild.

Review and Harden on a Schedule

The outcome: the gaps found each quarter are reviewed and prioritized with you.

It Is Not If. It Is When.

Every environment McNallan has evaluated for a new client had gaps: most often security defaults that were never changed, former employees still active, or admin rights spread across accounts nobody remembered. A single stolen password is usually all it takes.

The organizations that come through an incident well are the ones that had the controls, the people, and the air-gapped backups in place before it started. That is what this program is.

Need CMMC Level 2? That Is Its Own Engagement.

Managed security puts many of the controls a defense contract requires in place: endpoint detection and response, a hardened Microsoft 365 tenant, protected backups, and trained users. It does not prove them.

If a prime contractor or customer has made CMMC Level 2 a condition, McNallan runs a separate CMMC Readiness Assessment: every requirement reviewed with the people who run your systems, the gaps documented, and McNallan available to answer questions during certification.

Questions Businesses Ask Before They Call

Do we have to switch IT providers?

No. Managed security is sold on its own and runs alongside your current IT provider. McNallan takes control of endpoint detection and response, the Microsoft 365 tenant, and the backups; your provider keeps doing everyday IT.

What does it cost?

Every environment is different. On a quick call, once McNallan knows your users, sites, and endpoints, you get a ballpark. Scope is confirmed before anything is deployed.

Who is actually watching?

A 24x7 staffed security operations center receives the signals from your endpoints and tenant, investigates them, and isolates devices at the kernel level during an active attack. McNallan’s own security staff manage the program, the tooling, and the response with you.

Will application whitelisting get in the way of work?

It is deployed in learning mode first, so the applications your team already uses are approved before enforcement starts. New software requests go through a quick vetting step. Expect some alerts in the first weeks; that is the system doing its job.

We already have antivirus. Isn’t that enough?

Antivirus stops what it recognizes. Endpoint detection and response backed by people finds what it does not, and takes action. In new environments the response tooling has found active issues on day one that the previous antivirus had missed for years.

What about our VPN?

Zero-trust network access is available as an add-on and replaces the traditional VPN. Logins are allowed only from verified users and devices, which closes the most common way in.

What about CMMC or another compliance requirement?

Compliance is a separate engagement. Managed security puts many of the required controls in place; a CMMC Readiness Assessment is how a defense manufacturer finds and documents every remaining gap before the assessor arrives. If a prime contractor or customer is asking, start there.

Does this help with cyber insurance?

The controls insurers ask about, endpoint detection and response, a hardened Microsoft 365 tenant, backups an attacker cannot reach, and security training, are the program. You answer the application with what is actually in place.

Ready to Close the Gaps Before Someone Finds Them?

This is right for you if:

  • Your IT provider handles security as an afterthought, or not at all
  • Your cyber insurance renewal or a customer questionnaire is asking questions you cannot answer
  • You want people watching around the clock, not just software
  • You want one partner responsible for endpoints, the Microsoft 365 tenant, and backups

Tell Us What You Have Today

Share what prompted this: an insurance renewal, a customer questionnaire, an incident or a near miss, or a provider that is not watching. If you know roughly how many computers and users you have, include it. McNallan will follow up on what is missing, what it takes to fix it, and whether managed security should run alongside your current provider or inside managed IT.
Prefer a real conversation? Skip the form and call us directly during business hours.
Working hours
Mon–Fri
Emergency
8:00 AM – 5:00 PM
24/7 on-call support
Start with a conversation
No commitment to an assessment. We will talk through what an assessment would involve for your situation.