Someone is watching the alerts at 3am. It should not have to be you.
Ward Digital is managed detection and response for companies of 20–300 staff with no security team. An agent on every endpoint, a monitored pipeline behind it, and a human analyst who confirms what matters and contains it before your phone rings.
Credential-dumping behaviour on FIN-LT-014 matched. Signal raised to analyst queue.
Detection pipeline
Confirmed true positive. Parent process traced to a macro in an emailed invoice.
Analyst on shift
Host isolated from the network, process tree killed, session tokens revoked.
Containment
Owner called. One laptop offline until morning; nothing encrypted, nothing exfiltrated.
Analyst on shift
Illustrative console. Sample data — Ward is pre-launch.
The gap
Real detection is sold to companies that already have a security team.
Attackers stopped sorting targets by headcount years ago. A 60-person logistics firm has the same ransomware payoff as a 6,000-person one, with none of the defence. But monitored detection and response is packaged, priced and staffed for organisations that already have a SOC, a budget line and a CISO. Everything below that line buys antivirus, assumes it is enough, and finds out on a Sunday morning that it was not.
The market has a hole in the middle. Below roughly 300 staff you can buy software, and you can buy an emergency responder after the fact — but almost nobody will simply watch the thing for you at a price you can sign off.
Software is not a shift
An EDR licence puts a console in your admin panel. It does not put a person in front of it at 03:00 on a Sunday. Detection without a rota is a log file you read after the fact.
Your IT provider is not on watch
Most managed IT contracts cover uptime, patching and helpdesk. That is a different job with a different rota, and it usually stops at 6pm — which is when the interesting traffic starts.
The bill arrives at the worst moment
Detect-only contracts are cheap monthly and expensive on the night. Emergency incident response is billed at crisis rates, precisely when a 60-person company has the least room to negotiate.
How it works
An agent on every endpoint. A human on every decision.
Ward installs a lightweight agent on Windows, macOS and Linux machines and streams behavioural signal into a monitored pipeline. Rules and models raise candidates; an analyst on shift decides. When something is real, we contain it and then we call you. When nothing is real — which is most weeks — you hear nothing at all.
Signal path. The agent is the sensor; the pipeline narrows; the analyst decides. Containment happens on our authority under a scope you agree during onboarding, so nobody waits for a customer to wake up and approve an isolation.
Detection to containment, minute by minute
This is the sequence we run and the elapsed times we hold ourselves to. Ward is pre-launch, so treat it as the service design — not as a measured median. Once we have a full quarter of real incidents, the real numbers go on this page and replace it.
The order matters more than the numbers. Most vendors notify first and act once you answer; Ward acts first and notifies second, because at 03:00 the only person available to make the decision is the one already on shift.
T+0 MIN
Signal fires
The endpoint agent flags behaviour, not just a file hash — credential access, unusual parent processes, mass file rename, a login from a place your staff are not.
T+3 MIN
Analyst confirms
A human on shift looks at the full process tree and the identity context and decides. Roughly nineteen in twenty candidates die here, quietly, without reaching you.
T+6 MIN
Host contained
Isolate the machine, kill the process tree, revoke the sessions. Pre-agreed during onboarding so nothing waits on an approval email at 3am.
T+11 MIN
You are told
A phone call to your named contact, then a written summary a non-technical owner can read and forward to an insurer or a board.
What we watch
Most weeks, this screen is boring. That is the product.
Your estate as we see it: every agent, its last check-in, and what state it is in. You get read access to the same view we work from — but you are never expected to sit in front of it. The console below is a mockup with sample data; it shows the shape of the information, not a real customer.
estate · 62 agents · last sync 00:00:04 Watching
Endpoint status — illustrative sample
Host
Platform
Agent
Last signal
State
OPS-WS-004
Windows 11
2.4.1
00:00:03
Clear
FIN-LT-014
Windows 11
2.4.1
00:00:01
Isolated
DEV-MBP-27
macOS 15.2
2.4.1
00:00:06
Under review
WH-TERM-31
Windows 10
2.3.9
00:00:11
Clear
SRV-FILE-01
Ubuntu 24.04
2.4.1
00:00:02
Clear
HR-LT-009
macOS 14.7
2.4.1
00:04:38
Offline
62 agents enrolled1 isolated1 under analyst review0 actions needed from you
What actually gets watched
Process behaviour and lineage on every enrolled endpoint
Identity events — impossible travel, MFA fatigue, new inbox rules
Mass file rename and shadow-copy deletion patterns
Remote-access tooling appearing where it has never been
Agent health itself — a silent sensor is treated as a signal
What you are never asked to do
Triage a queue. Interpret a severity score. Approve an isolation at 3am. Buy a separate response retainer once the incident has already started. If you find yourself doing any of these, we have sold you the wrong thing.
Mockup with sample hostnames — Ward is pre-launch and has no customer data to show.
Included
Nine things, one line item.
Ward is deliberately a single subscription rather than a menu. Splitting detection, response, training and reporting into separate SKUs is how a small company ends up with three of the four and a gap where the fourth should be.
Endpoint agent, three platforms
One agent for Windows, macOS and Linux. Installs with your existing MDM or a script, sits at around one percent CPU, and self-reports when it stops reporting.
WINDOWS 10/11 · SERVER 2016+
MACOS 13+ · INTEL & APPLE SILICON
UBUNTU · DEBIAN · RHEL
24/7 monitored detection
A staffed rota, not an inbox that gets read on Monday. Every candidate signal is seen by a person before it is either acted on or closed.
HUMAN CONFIRMATION ON EVERY ACTION
NO SEVERITY SCORE HANDED TO YOU
WEEKENDS AND HOLIDAYS INCLUDED
Automatic host isolation
A confirmed compromise is cut off from the network in seconds, with our management channel kept open so recovery does not need a site visit.
NETWORK ISOLATION · PROCESS KILL
SESSION AND TOKEN REVOCATION
SCOPE AGREED BEFORE, NOT DURING
Identity & email compromise
Most small-company incidents start in a mailbox, not on a laptop. Ward watches Microsoft 365 and Google Workspace sign-ins, forwarding rules and OAuth grants alongside the endpoints.
IMPOSSIBLE TRAVEL · MFA FATIGUE
NEW FORWARDING & INBOX RULES
SUSPICIOUS OAUTH CONSENT
Phishing simulation & training
Quarterly simulated campaigns and five-minute follow-ups for the people who click. Measured as a trend, never used to name and shame an individual.
QUARTERLY CAMPAIGNS
ROLE-AWARE SCENARIOS
TREND REPORTING, NOT LEAGUE TABLES
Quarterly posture report
Written for an owner or a board, not for an engineer. What we saw, what we stopped, what is still weak, and the three things worth fixing next quarter — in order.
PLAIN LANGUAGE, NO CVE DUMPS
SHAREABLE WITH INSURERS & CLIENTS
PRIORITISED, NOT EXHAUSTIVE
Incident retainer, named responder
A specific person who knows your estate, agreed contacts, and a documented escalation path — in the subscription, not on a separate invoice raised on the night.
NAMED RESPONDER PER ACCOUNT
NO HOURLY CRISIS BILLING
ANNUAL TABLETOP EXERCISE
MSP mode
If you resell security to your own client base, Ward runs multi-tenant: per-client isolation of data, a partner console, and white-labelled quarterly reports.
MULTI-TENANT SEPARATION
PARTNER MARGIN, NOT A REFERRAL FEE
WHITE-LABEL REPORTING
Onboarding in a week
Scoping call, agent rollout with your IT provider, containment authority agreed in writing, then a baseline period before we start acting. No six-month deployment project.
DAY 1 — SCOPE & AUTHORITY
DAY 2–4 — AGENT ROLLOUT
DAY 5–14 — BASELINE, THEN LIVE
The difference
Response is in the subscription. That changes whose side we are on.
A detect-only vendor makes money twice: a low monthly fee, then emergency response billed at crisis rates on the worst night of your year. It is a defensible business model and a bad alignment. Ward includes response, so an incident that goes long costs us, not you. Our incentive is to stop the thing early.
Comparison of a typical detect-only security contract with the Ward Digital subscription
Typical detect-only contract
Ward Digital
Who reads the alert
Your admin, when they next open the console
An analyst on shift, within minutes, around the clock
Who contains the host
You do, once you have understood the alert
We do, under authority agreed before anything happens
Cost of an incident
Emergency response billed hourly at crisis rates
Included — no invoice is raised on the night
What arrives at 3am
An email, a push notification, or nothing at all
A phone call, after the machine is already isolated
Reporting
A dashboard you have to interpret yourself
A quarterly report written for a non-technical owner
Minimum viable customer
An organisation with a security team to run it
20 endpoints and no security staff at all
Characterisation of the common detect-only model, not a claim about any specific named vendor.
Pricing
One number, per endpoint, per month.
No detection tier, no response tier, no per-incident charge. If you can count your laptops you can price Ward, and the number does not change on the night something happens.
Ward Managed Detection & Response
$14per endpoint / month · 20-endpoint minimum
Billed monthly or annually. Servers count as endpoints. Identity and mailbox monitoring for your staff is included at no extra per-seat cost.
Containment and full incident response — included, never billed hourly
Identity and email compromise monitoring
Quarterly phishing simulation and staff training
Quarterly posture report and a named responder
What that comes to
Estate size
Per month
Per year
20 endpoints
$280
$3,360
60 endpoints
$840
$10,080
150 endpoints
$2,100
$25,200
300 endpoints
$4,200
$50,400
MSP & partner
Volume
Multi-tenant deployment for providers reselling security to their own client base. Partner margin on the per-endpoint rate, white-labelled reporting, and one escalation path for all of your clients.
Before anyone signs anything: a 45-minute call and a short written read on what you actually have, where the obvious gaps are, and whether Ward is the right answer. Sometimes it is not, and we will say so.
Ward is pre-launch. The first cohort of customers gets rate protection for 24 months and direct access to the people building the detection content — in exchange for tolerating a young service and telling us honestly when it is wrong.
What we will publish
We have not run a year yet. Here is what we will report when we have.
Ward is a new company and has not yet completed a quarter of live monitoring, so there are no customer logos on this page, no testimonials and no case studies — because there is nothing honest to put there yet. These are the three numbers we will publish every quarter from the first full quarter onwards, including the quarters that look bad.
Median detection → containment— min
Minutes from the agent raising a confirmed signal to the host being isolated. Measured on every true positive, median and 90th percentile, not a best case.
First published: quarter one after launch
Incidents stopped pre-encryption— / —
Confirmed ransomware attempts contained before any customer file was encrypted, as a share of all confirmed attempts. Including the ones we do not catch in time.
First published: quarter one after launch
Endpoints under watch—
Agents actively reporting across all customers, with agent-health coverage as a second figure — because an installed agent that has stopped sending is not coverage.
First published: quarter one after launch
Why we are telling you this
Security marketing has a credibility problem, and small companies are the ones who pay for it. Every vendor in this category will show you a dashboard with impressive numbers and no methodology. We would rather show you an empty table with the methodology attached and fill it in publicly.
So: no logos we have not earned, no compliance badges we do not hold, no statistics designed to frighten you into a call. If we tell you a number later, we will tell you how it was counted.
Ward Digital — founding team
Who Ward is built for
Company size
20–300 staff
Security staff
0–1
Sectors
Logistics · Professional · Health · Manufacturing
Estate
Windows / macOS / Linux
Also
MSPs reselling security
Where Ward is a bad fit
If you already run a SOC, if you need a specific certification signed off this quarter, or if your estate is mostly unmanaged personal devices, Ward is the wrong purchase and we will tell you on the assessment call rather than after the contract.
Questions
The things people ask on the first call.
Will you isolate a machine without asking me first?
Yes — inside a scope you define in writing during onboarding, and only after a human analyst has confirmed the signal. Most customers authorise full isolation on laptops and desktops immediately, and require a call before touching production servers. You can change the scope at any time, and every containment action is logged with the analyst's reasoning attached.
What happens if you are wrong and isolate a healthy machine?
We release it, we call you, and it goes in the quarterly report as a false positive with the detection that caused it. A machine offline for twenty minutes is a bad morning; a machine encrypting a file server is a bad quarter, so we will keep making that trade in the same direction. We publish our false-positive rate for the same reason we publish everything else.
Do we still need antivirus?
Keep whatever you have — Microsoft Defender is genuinely good and is free with the licences you already own. Ward is not a replacement for prevention; it is the monitoring and response layer that sits on top of it. If you are paying for a third-party antivirus product you do not need, the posture assessment will usually find you some of Ward's cost there.
How much work is this for our IT provider?
An afternoon to push the agent through your existing management tooling, a scoping call, and a standing invitation to the quarterly review. After that they should hear from us only when there is something real. We work alongside managed IT providers rather than replacing them, and we are happy to route incident calls to them first if that is how you prefer to run things.
What data leaves our machines?
Security telemetry: process metadata, command lines, network connection records, authentication events and file-operation patterns. Not document contents, not keystrokes, not screenshots, not browsing history for its own sake. The full field list is in the data schedule of the contract, and you can read it before you sign rather than after.
Are you certified?
Not yet, and we are not going to imply otherwise. Ward is a new company; formal audit programmes take a year of operating history before they mean anything. We can share our security architecture, our data-handling schedule, our subprocessor list and our access controls today, and we will publish audit status honestly as it changes. If a certificate is a hard requirement for your procurement this quarter, we are not yet the right supplier.
What if we are in the middle of something right now?
Do not fill in a web form. Go to the contact page and use the phone number at the bottom of it, and in the meantime disconnect affected machines from the network without powering them off — powering off destroys memory evidence.
Next step
Find out what is actually watching your estate tonight.
A 45-minute posture assessment: what you have, what it covers, what it does not, and whether you need us. Free, no obligation, and we will tell you if the honest answer is that your current setup is fine.