Cybersecurity Services
in Minneapolis
Cyber criminals work 24x7. So does the team watching your network. McNallan managed security is a complete program for your users, endpoints, and Microsoft 365 tenant. Threats are investigated by a 24x7 staffed security operations center that isolates an attacked device before it spreads, applications run only when approved, and your tenant is hardened against a list of 200+ best practices that grows every quarter. Sold on its own or as part of McNallan managed IT, and it runs alongside the IT provider you already have. Need CMMC Level 2? That is a separate engagement.
Security Software Is Not Security. People Watching It Around the Clock Is.
Already Have an IT Provider? This Still Applies.
Managed IT and managed security are not the same job. A good IT provider keeps things running. Security is a separate discipline with its own tooling, its own people, and its own response process, and many IT providers cannot add a security practice to what they already do.
McNallan runs managed security for organizations that keep their current IT provider. We take control of endpoint detection and response, the Microsoft 365 tenant, and the backups, because with those three in hand we can protect an environment even when everyday IT is not ours to manage.
If McNallan already manages your IT, this is the security layer inside it. If someone else does, it runs alongside them.
This Is for You If One of These Is True
Security Is an Afterthought at Your Current Provider
- Your IT provider’s security line item is antivirus and not much else
- Nobody is watching alerts overnight or on weekends
- You have been told you are covered but have never seen what that means
- You want a security partner without changing IT providers
Your Insurance Renewal or a Customer Is Asking Questions
- The cyber insurance application asks about endpoint detection, backups, and training
- A customer or partner sent a security questionnaire
- You are not sure your Microsoft 365 tenant was ever hardened
- You want the controls in place before the next renewal, not after a claim
You Would Rather Prevent an Incident Than Recover From One
- Every environment we have evaluated had gaps, usually defaults nobody changed
- A single stolen login should not be enough to reach your servers
- You want backups an attacker cannot reach
- It is not if. It is when.
What’s Included in Managed Security
Managed Endpoint Detection and Response
Application Whitelisting and Ringfencing
Managed Detection for Microsoft 365
Managed Log Monitoring
Managed Patching
Security Awareness Training and Phish Testing
Microsoft 365 Tenant Hardening
Email Spam and Phish Filtering
What Customers Say About Us
How Managed Security Works
Deploy in Learning Mode
- Whitelisting runs for a couple of weeks watching what your people actually use
- The applications your team relies on are approved before enforcement starts
- Early alerts are expected, and we plan for them
Watch and Respond, 24x7
- Signals from endpoints, the tenant, and logs go to a staffed security operations center
- Threats are investigated by people and infected devices isolated, even at 2 a.m.
- Incident response, remediation, and reporting are part of the program
Review and Harden on a Schedule
- Tenant hardening improves every quarter against a growing best-practice list
- Larger environments get scheduled tenant, directory, firewall, and network reviews, active-user reviews, and external penetration testing
- Findings come back as a prioritized remediation proposal, effort against impact, not a list
It Is Not If. It Is When.
Every environment McNallan has evaluated for a new client had gaps: most often security defaults that were never changed, former employees still active, or admin rights spread across accounts nobody remembered. A single stolen password is usually all it takes.
The organizations that come through an incident well are the ones that had the controls, the people, and the air-gapped backups in place before it started. That is what this program is.
Need CMMC Level 2? That Is Its Own Engagement.
Managed security puts many of the controls a defense contract requires in place: endpoint detection and response, a hardened Microsoft 365 tenant, protected backups, and trained users. It does not prove them.
If a prime contractor or customer has made CMMC Level 2 a condition, McNallan runs a separate CMMC Readiness Assessment: every requirement reviewed with the people who run your systems, the gaps documented, and McNallan available to answer questions during certification.
Questions Businesses Ask Before They Call
Do we have to switch IT providers?
No. Managed security is sold on its own and runs alongside your current IT provider. McNallan takes control of endpoint detection and response, the Microsoft 365 tenant, and the backups; your provider keeps doing everyday IT.
What does it cost?
Every environment is different. On a quick call, once McNallan knows your users, sites, and endpoints, you get a ballpark. Scope is confirmed before anything is deployed.
Who is actually watching?
A 24x7 staffed security operations center receives the signals from your endpoints and tenant, investigates them, and isolates devices at the kernel level during an active attack. McNallan’s own security staff manage the program, the tooling, and the response with you.
Will application whitelisting get in the way of work?
It is deployed in learning mode first, so the applications your team already uses are approved before enforcement starts. New software requests go through a quick vetting step. Expect some alerts in the first weeks; that is the system doing its job.
We already have antivirus. Isn’t that enough?
Antivirus stops what it recognizes. Endpoint detection and response backed by people finds what it does not, and takes action. In new environments the response tooling has found active issues on day one that the previous antivirus had missed for years.
What about our VPN?
Zero-trust network access is available as an add-on and replaces the traditional VPN. Logins are allowed only from verified users and devices, which closes the most common way in.
What about CMMC or another compliance requirement?
Compliance is a separate engagement. Managed security puts many of the required controls in place; a CMMC Readiness Assessment is how a defense manufacturer finds and documents every remaining gap before the assessor arrives. If a prime contractor or customer is asking, start there.
Does this help with cyber insurance?
The controls insurers ask about, endpoint detection and response, a hardened Microsoft 365 tenant, backups an attacker cannot reach, and security training, are the program. You answer the application with what is actually in place.
Ready to Close the Gaps Before Someone Finds Them?
This is right for you if:
- Your IT provider handles security as an afterthought, or not at all
- Your cyber insurance renewal or a customer questionnaire is asking questions you cannot answer
- You want people watching around the clock, not just software
- You want one partner responsible for endpoints, the Microsoft 365 tenant, and backups