Founding cohort — onboarding now

Someone is watching the alerts at 3am. It should not have to be you.

Ward Digital is managed detection and response for companies of 20–300 staff with no security team. An agent on every endpoint, a monitored pipeline behind it, and a human analyst who confirms what matters and contains it before your phone rings.

  • $14 per endpoint / month, 20 minimum
  • 24 / 7 monitored, human-confirmed
  • $0 extra when we respond
ward · watch · northgate-logistics Live
  • Credential-dumping behaviour on FIN-LT-014 matched. Signal raised to analyst queue. Detection pipeline

  • Confirmed true positive. Parent process traced to a macro in an emailed invoice. Analyst on shift

  • Host isolated from the network, process tree killed, session tokens revoked. Containment

  • Owner called. One laptop offline until morning; nothing encrypted, nothing exfiltrated. Analyst on shift

Illustrative console. Sample data — Ward is pre-launch.
The gap

Real detection is sold to companies that already have a security team.

Attackers stopped sorting targets by headcount years ago. A 60-person logistics firm has the same ransomware payoff as a 6,000-person one, with none of the defence. But monitored detection and response is packaged, priced and staffed for organisations that already have a SOC, a budget line and a CISO. Everything below that line buys antivirus, assumes it is enough, and finds out on a Sunday morning that it was not.

Where monitored detection is actually available, by company size A headcount scale from 1 to 5,000-plus staff. Unmonitored antivirus and EDR-lite tooling is sold across the small end of the scale. Enterprise managed detection with an in-house or contracted SOC begins at roughly 500 staff. Companies between 20 and 300 staff sit in the gap between the two, which is the band Ward Digital is built for. 20 – 300 STAFF Antivirus and EDR-lite — installed, unmonitored NO ONE READS THE ALERT Enterprise MDR with a SOC PRICED FOR A SOC BUDGET Ward Digital MONITORED · RESPONSE INCLUDED 1 20 300 5,000+ STAFF HEADCOUNT →
The market has a hole in the middle. Below roughly 300 staff you can buy software, and you can buy an emergency responder after the fact — but almost nobody will simply watch the thing for you at a price you can sign off.

Software is not a shift

An EDR licence puts a console in your admin panel. It does not put a person in front of it at 03:00 on a Sunday. Detection without a rota is a log file you read after the fact.

Your IT provider is not on watch

Most managed IT contracts cover uptime, patching and helpdesk. That is a different job with a different rota, and it usually stops at 6pm — which is when the interesting traffic starts.

The bill arrives at the worst moment

Detect-only contracts are cheap monthly and expensive on the night. Emergency incident response is billed at crisis rates, precisely when a 60-person company has the least room to negotiate.

How it works

An agent on every endpoint. A human on every decision.

Ward installs a lightweight agent on Windows, macOS and Linux machines and streams behavioural signal into a monitored pipeline. Rules and models raise candidates; an analyst on shift decides. When something is real, we contain it and then we call you. When nothing is real — which is most weeks — you hear nothing at all.

The Ward signal path, from endpoint agent to outcome Agents on Windows, macOS and Linux endpoints feed a signal pipeline covering endpoint behaviour, identity events and email compromise. The pipeline raises candidates to a human analyst on shift, who either contains the incident by isolating the host, killing the process and revoking sessions, or closes it silently with the reasoning logged. 01 · AGENT 02 · PIPELINE 03 · HUMAN 04 · OUTCOME Windows macOS Linux Signal pipeline process & behaviour identity & session email compromise Analyst on shift Confirms or dismisses. Nothing auto-escalates to you. Contain isolate · kill · revoke Close quietly logged · no phone call EVERY CONFIRMED SIGNAL IS ACTED ON BEFORE IT IS REPORTED — NOT AFTER
Signal path. The agent is the sensor; the pipeline narrows; the analyst decides. Containment happens on our authority under a scope you agree during onboarding, so nobody waits for a customer to wake up and approve an isolation.

Detection to containment, minute by minute

This is the sequence we run and the elapsed times we hold ourselves to. Ward is pre-launch, so treat it as the service design — not as a measured median. Once we have a full quarter of real incidents, the real numbers go on this page and replace it.

Detection-to-containment sequence with elapsed minutes Four stages plotted against a twelve-minute elapsed ruler. At zero minutes the agent raises a signal. At about three minutes an analyst confirms it is a true positive. At about six minutes the host is isolated, the process killed and sessions revoked. At about eleven minutes the owner is called with a plain-language summary. Containment completes before the customer is contacted. ILLUSTRATIVE SEQUENCE TARGET SERVICE DESIGN · NOT A MEASURED RESULT T+0 MIN Signal fires Agent flags credential-dumping behaviour on one laptop and raises it to the analyst queue. T+3 MIN Analyst confirms A person on shift reads the process tree and calls it a true positive. No auto-escalation. T+6 MIN Host contained Machine isolated from the network, process tree killed, session tokens revoked. T+11 MIN You are told A call, then a written summary in plain language: what we saw, what we did, what you do next. 0 3 6 9 12 min CONTAINED BEFORE YOU ARE CALLED CALL + WRITTEN SUMMARY
The order matters more than the numbers. Most vendors notify first and act once you answer; Ward acts first and notifies second, because at 03:00 the only person available to make the decision is the one already on shift.
  1. T+0 MIN

    Signal fires

    The endpoint agent flags behaviour, not just a file hash — credential access, unusual parent processes, mass file rename, a login from a place your staff are not.

  2. T+3 MIN

    Analyst confirms

    A human on shift looks at the full process tree and the identity context and decides. Roughly nineteen in twenty candidates die here, quietly, without reaching you.

  3. T+6 MIN

    Host contained

    Isolate the machine, kill the process tree, revoke the sessions. Pre-agreed during onboarding so nothing waits on an approval email at 3am.

  4. T+11 MIN

    You are told

    A phone call to your named contact, then a written summary a non-technical owner can read and forward to an insurer or a board.

What we watch

Most weeks, this screen is boring. That is the product.

Your estate as we see it: every agent, its last check-in, and what state it is in. You get read access to the same view we work from — but you are never expected to sit in front of it. The console below is a mockup with sample data; it shows the shape of the information, not a real customer.

estate · 62 agents · last sync 00:00:04 Watching
Endpoint status — illustrative sample
Host Platform Agent Last signal State
OPS-WS-004 Windows 11 2.4.1 00:00:03 Clear
FIN-LT-014 Windows 11 2.4.1 00:00:01 Isolated
DEV-MBP-27 macOS 15.2 2.4.1 00:00:06 Under review
WH-TERM-31 Windows 10 2.3.9 00:00:11 Clear
SRV-FILE-01 Ubuntu 24.04 2.4.1 00:00:02 Clear
HR-LT-009 macOS 14.7 2.4.1 00:04:38 Offline
62 agents enrolled 1 isolated 1 under analyst review 0 actions needed from you

What actually gets watched

  • Process behaviour and lineage on every enrolled endpoint
  • Identity events — impossible travel, MFA fatigue, new inbox rules
  • Mass file rename and shadow-copy deletion patterns
  • Remote-access tooling appearing where it has never been
  • Agent health itself — a silent sensor is treated as a signal

What you are never asked to do

Triage a queue. Interpret a severity score. Approve an isolation at 3am. Buy a separate response retainer once the incident has already started. If you find yourself doing any of these, we have sold you the wrong thing.

Mockup with sample hostnames — Ward is pre-launch and has no customer data to show.

Included

Nine things, one line item.

Ward is deliberately a single subscription rather than a menu. Splitting detection, response, training and reporting into separate SKUs is how a small company ends up with three of the four and a gap where the fourth should be.

Endpoint agent, three platforms

One agent for Windows, macOS and Linux. Installs with your existing MDM or a script, sits at around one percent CPU, and self-reports when it stops reporting.

  • WINDOWS 10/11 · SERVER 2016+
  • MACOS 13+ · INTEL & APPLE SILICON
  • UBUNTU · DEBIAN · RHEL

24/7 monitored detection

A staffed rota, not an inbox that gets read on Monday. Every candidate signal is seen by a person before it is either acted on or closed.

  • HUMAN CONFIRMATION ON EVERY ACTION
  • NO SEVERITY SCORE HANDED TO YOU
  • WEEKENDS AND HOLIDAYS INCLUDED

Automatic host isolation

A confirmed compromise is cut off from the network in seconds, with our management channel kept open so recovery does not need a site visit.

  • NETWORK ISOLATION · PROCESS KILL
  • SESSION AND TOKEN REVOCATION
  • SCOPE AGREED BEFORE, NOT DURING

Identity & email compromise

Most small-company incidents start in a mailbox, not on a laptop. Ward watches Microsoft 365 and Google Workspace sign-ins, forwarding rules and OAuth grants alongside the endpoints.

  • IMPOSSIBLE TRAVEL · MFA FATIGUE
  • NEW FORWARDING & INBOX RULES
  • SUSPICIOUS OAUTH CONSENT

Phishing simulation & training

Quarterly simulated campaigns and five-minute follow-ups for the people who click. Measured as a trend, never used to name and shame an individual.

  • QUARTERLY CAMPAIGNS
  • ROLE-AWARE SCENARIOS
  • TREND REPORTING, NOT LEAGUE TABLES

Quarterly posture report

Written for an owner or a board, not for an engineer. What we saw, what we stopped, what is still weak, and the three things worth fixing next quarter — in order.

  • PLAIN LANGUAGE, NO CVE DUMPS
  • SHAREABLE WITH INSURERS & CLIENTS
  • PRIORITISED, NOT EXHAUSTIVE

Incident retainer, named responder

A specific person who knows your estate, agreed contacts, and a documented escalation path — in the subscription, not on a separate invoice raised on the night.

  • NAMED RESPONDER PER ACCOUNT
  • NO HOURLY CRISIS BILLING
  • ANNUAL TABLETOP EXERCISE

MSP mode

If you resell security to your own client base, Ward runs multi-tenant: per-client isolation of data, a partner console, and white-labelled quarterly reports.

  • MULTI-TENANT SEPARATION
  • PARTNER MARGIN, NOT A REFERRAL FEE
  • WHITE-LABEL REPORTING

Onboarding in a week

Scoping call, agent rollout with your IT provider, containment authority agreed in writing, then a baseline period before we start acting. No six-month deployment project.

  • DAY 1 — SCOPE & AUTHORITY
  • DAY 2–4 — AGENT ROLLOUT
  • DAY 5–14 — BASELINE, THEN LIVE
The difference

Response is in the subscription. That changes whose side we are on.

A detect-only vendor makes money twice: a low monthly fee, then emergency response billed at crisis rates on the worst night of your year. It is a defensible business model and a bad alignment. Ward includes response, so an incident that goes long costs us, not you. Our incentive is to stop the thing early.

Comparison of a typical detect-only security contract with the Ward Digital subscription
  Typical detect-only contract Ward Digital
Who reads the alert Your admin, when they next open the console An analyst on shift, within minutes, around the clock
Who contains the host You do, once you have understood the alert We do, under authority agreed before anything happens
Cost of an incident Emergency response billed hourly at crisis rates Included — no invoice is raised on the night
What arrives at 3am An email, a push notification, or nothing at all A phone call, after the machine is already isolated
Reporting A dashboard you have to interpret yourself A quarterly report written for a non-technical owner
Minimum viable customer An organisation with a security team to run it 20 endpoints and no security staff at all

Characterisation of the common detect-only model, not a claim about any specific named vendor.

Pricing

One number, per endpoint, per month.

No detection tier, no response tier, no per-incident charge. If you can count your laptops you can price Ward, and the number does not change on the night something happens.

Ward Managed Detection & Response

$14 per endpoint / month · 20-endpoint minimum

Billed monthly or annually. Servers count as endpoints. Identity and mailbox monitoring for your staff is included at no extra per-seat cost.

Get a posture assessment
  • Endpoint agent for Windows, macOS and Linux
  • 24/7 monitored detection with human confirmation
  • Containment and full incident response — included, never billed hourly
  • Identity and email compromise monitoring
  • Quarterly phishing simulation and staff training
  • Quarterly posture report and a named responder

What that comes to

Estate size Per month Per year
20 endpoints$280$3,360
60 endpoints$840$10,080
150 endpoints$2,100$25,200
300 endpoints$4,200$50,400
MSP & partner

Volume

Multi-tenant deployment for providers reselling security to their own client base. Partner margin on the per-endpoint rate, white-labelled reporting, and one escalation path for all of your clients.

Talk about partnering
Posture assessment

Free

Before anyone signs anything: a 45-minute call and a short written read on what you actually have, where the obvious gaps are, and whether Ward is the right answer. Sometimes it is not, and we will say so.

Book the call
Founding cohort

Ward is pre-launch. The first cohort of customers gets rate protection for 24 months and direct access to the people building the detection content — in exchange for tolerating a young service and telling us honestly when it is wrong.

What we will publish

We have not run a year yet. Here is what we will report when we have.

Ward is a new company and has not yet completed a quarter of live monitoring, so there are no customer logos on this page, no testimonials and no case studies — because there is nothing honest to put there yet. These are the three numbers we will publish every quarter from the first full quarter onwards, including the quarters that look bad.

Median detection → containment

Minutes from the agent raising a confirmed signal to the host being isolated. Measured on every true positive, median and 90th percentile, not a best case.

First published: quarter one after launch
Incidents stopped pre-encryption

Confirmed ransomware attempts contained before any customer file was encrypted, as a share of all confirmed attempts. Including the ones we do not catch in time.

First published: quarter one after launch
Endpoints under watch

Agents actively reporting across all customers, with agent-health coverage as a second figure — because an installed agent that has stopped sending is not coverage.

First published: quarter one after launch

Why we are telling you this

Security marketing has a credibility problem, and small companies are the ones who pay for it. Every vendor in this category will show you a dashboard with impressive numbers and no methodology. We would rather show you an empty table with the methodology attached and fill it in publicly.

So: no logos we have not earned, no compliance badges we do not hold, no statistics designed to frighten you into a call. If we tell you a number later, we will tell you how it was counted.

Ward Digital — founding team

Who Ward is built for

Company size
20–300 staff
Security staff
0–1
Sectors
Logistics · Professional · Health · Manufacturing
Estate
Windows / macOS / Linux
Also
MSPs reselling security

Where Ward is a bad fit

If you already run a SOC, if you need a specific certification signed off this quarter, or if your estate is mostly unmanaged personal devices, Ward is the wrong purchase and we will tell you on the assessment call rather than after the contract.

Questions

The things people ask on the first call.

Will you isolate a machine without asking me first?

Yes — inside a scope you define in writing during onboarding, and only after a human analyst has confirmed the signal. Most customers authorise full isolation on laptops and desktops immediately, and require a call before touching production servers. You can change the scope at any time, and every containment action is logged with the analyst's reasoning attached.

What happens if you are wrong and isolate a healthy machine?

We release it, we call you, and it goes in the quarterly report as a false positive with the detection that caused it. A machine offline for twenty minutes is a bad morning; a machine encrypting a file server is a bad quarter, so we will keep making that trade in the same direction. We publish our false-positive rate for the same reason we publish everything else.

Do we still need antivirus?

Keep whatever you have — Microsoft Defender is genuinely good and is free with the licences you already own. Ward is not a replacement for prevention; it is the monitoring and response layer that sits on top of it. If you are paying for a third-party antivirus product you do not need, the posture assessment will usually find you some of Ward's cost there.

How much work is this for our IT provider?

An afternoon to push the agent through your existing management tooling, a scoping call, and a standing invitation to the quarterly review. After that they should hear from us only when there is something real. We work alongside managed IT providers rather than replacing them, and we are happy to route incident calls to them first if that is how you prefer to run things.

What data leaves our machines?

Security telemetry: process metadata, command lines, network connection records, authentication events and file-operation patterns. Not document contents, not keystrokes, not screenshots, not browsing history for its own sake. The full field list is in the data schedule of the contract, and you can read it before you sign rather than after.

Are you certified?

Not yet, and we are not going to imply otherwise. Ward is a new company; formal audit programmes take a year of operating history before they mean anything. We can share our security architecture, our data-handling schedule, our subprocessor list and our access controls today, and we will publish audit status honestly as it changes. If a certificate is a hard requirement for your procurement this quarter, we are not yet the right supplier.

What if we are in the middle of something right now?

Do not fill in a web form. Go to the contact page and use the phone number at the bottom of it, and in the meantime disconnect affected machines from the network without powering them off — powering off destroys memory evidence.

Next step

Find out what is actually watching your estate tonight.

A 45-minute posture assessment: what you have, what it covers, what it does not, and whether you need us. Free, no obligation, and we will tell you if the honest answer is that your current setup is fine.

$14 / endpoint / month · 20-endpoint minimum · response included