---
title: "Attack monitoring and response"
description: "Every alert is handled by an on-duty engineer, not a shared inbox. $26 per seat a month: $18 the device and $8 the account. Round the clock."
locale: en
canonical: https://finleadgen.com/en/services/managed-detection
source: https://finleadgen.com/en/services/managed-detection.md
price_reviewed: 2026-08-06
---

# Attack monitoring and response

An engineer on duty works the alert, not an inbox.

**$26 per seat per month: $18 the device and $8 the account.**

## Who handles your antivirus alert at three in the morning?

Nobody. The email lands in a shared inbox and is opened in the morning. By then it is over — or it is not, and you find out from an invoice, from a partner's email or from work that has stopped. Antivirus can spot it. It cannot respond.

## An alert is closed by a person, not a rule

The answer reaches you sorted out, not forwarded. An on-duty engineer takes every alert to the end: looks at what happened, cuts the machine off the network, removes the malware and writes down what was done.

We watch email and cloud too: someone else signing into a mailbox, a quiet forward of your mail to an outsider, swapped bank details in a message. Usually this is noticed once the money has gone the wrong way. These signs are seen by whoever watches them all the time.

Once a month a report arrives: what fired, what turned out to be real and what was done about it. Your insurer and your client accept it.

## What monitoring covers

| What | State | Price |
| --- | --- | --- |
| Every alert handled by a person, not by an email to a shared address | included |  |
| Cutting the machine off the network and removing the malware | included |  |
| Accounts: outside sign-ins and mail forwarded to an outsider | included |  |
| Logs collected and kept in the form an auditor asks for | included |  |
| A monthly report your insurer accepts | included |  |
| Set-up, tuning and daily care of the protection | included |  |
| False alarms sorted out and exclusions tuned | included |  |
| Endpoint protection licences at the vendor's invoice, markup $0.00 | paid to the vendor |  |

## Your price

| Plan | Price | Note |
| --- | --- | --- |
| Computers | $18 per endpoint a month | Computers: the alert handled and the machine cut off the network. |
| Accounts | $8 per account a month | Email and cloud: outside sign-ins and quiet mail forwarding. |
| The whole seat | $26 per seat a month | One person's machine and account. |
**Computers**
- Round the clock: we handle the alert and cut the machine off
**Accounts**
- We watch sign-ins, mail forwarding and open sessions
**The whole seat**
- Round the clock: we handle the alert and cut the machine off
- We watch sign-ins, mail forwarding and open sessions
- A report every month, for the insurer and the auditor

## Extras

| What | State | Price |
| --- | --- | --- |
| If you are breached, we investigate — monthly | not included | $670 a month |
| External penetration test of network and applications | not included | from $4,480 |
| Preparing for a cyber policy renewal | not included | $2,250 one-off |
| Backups and a check that they actually restore | not included | $1,340 per site per year |
| Patient records kept protected | not included | +$40 per seat a month |
| Employee computers looked after | not included | from $102 per seat |
| Fractional chief information security officer | not included | from $2,500 a month |
| Questionnaires your client has sent | not included | $1,350 per questionnaire |

### There are four of us. Isn't round-the-clock monitoring too much?

No. You pay per computer and per account, so a bill for four is ten times smaller than a bill for forty. There is no minimum: we take on as many machines as you have today and as many mailboxes as exist.

### We already have antivirus. Why this on top?

Because antivirus only flags. A person closes the case: looks at what was flagged, separates the false from the real, cuts the machine off the network and writes a report. Your own antivirus usually stays where it is.

### Is handling an alert included in the price or charged separately?

Included. Handling alerts is exactly what you pay for each month. The machine leaves the network within the first minutes, the malware is removed, the accounts used on it are closed and opened again. You get an email: what was done and whether anyone has to be notified.

### Is the report good enough for an insurer and a client?

Yes, that is what it is made for: what fired, how often, how it ended and how fast. The same pack goes into a client questionnaire and into a policy renewal application — you will not have to order the work twice.

## Where to send the quote

Tell us how many machines and mailboxes you have — we will send the quote by email.
