Network traffic
Monitored for connections to known-bad destinations, unexpected data volumes leaving the network, and lateral movement between systems that have no business talking to each other.
Pillar 03 ยท Monitor
Cyber security monitoring answers the question a cyber security audit cannot: what about next month?
An audit tells you where you stood the week it was done. That is valuable, but it has a shelf life.
Between one audit and the next, your business changes. New employees, new software, new suppliers, a laptop that stops getting patched, and a firewall rule someone added for a good reason in March and never removed can all have an impact. Meanwhile the threats themselves move independently of anything you do.
Monitoring is the answer to this drift. It is the always-on complement to the point-in-time assessment, and for most businesses, it turns "we had an audit" into "we manage our security".
Continuous monitoring means someone is watching your environment for evidence of an attack while your business gets on with its day, including the hours when nobody is in the office, which is exactly when serious attacks tend to be staged.
Monitored for connections to known-bad destinations, unexpected data volumes leaving the network, and lateral movement between systems that have no business talking to each other.
Watched for malware, unusual process behaviour, disabled security tooling and devices falling behind on patching.
Still the front door for most attacks. We track volume, sender anomalies, and the patterns that precede business email compromise.
Tracked for bursts of failed logins, sign-ins from improbable locations, repeated multi-factor prompts a user did not trigger, and new administrator accounts appearing.
An issue because most environments degrade slowly rather than failing all at once.
Triggers an alert if your domains and credentials appear in breach dumps or criminal marketplaces.
Generating alerts is easy. The value lies in telling the difference between noise and something that matters, and getting a human decision in front of you quickly when it does.
Detection time is the reason this is worth paying for. Serious intrusions are rarely a single dramatic event. Someone gets a foothold, looks around, works out where the valuable systems and the backups are, escalates their access, and only then does the visible damage. This reconnaissance phase is where an attack is cheapest to stop, and it is almost entirely invisible to a business that is not watching. By the time the obvious symptoms appear, with files encrypted and systems unavailable, the decisions that determine how bad it gets have already been made for you.
Alerts are assessed and the great majority are resolved without troubling you. A single failed login is not an incident.
Where something needs your attention but is not urgent, such as a device drifting out of patch compliance or a user account behaving oddly, notification is provided as part of the regular reporting with a recommended action.
Where there are signs of an active compromise, we contact your named contacts directly by phone, according to established escalation criteria. You are notified of what we have seen, what we think it is, what we recommend, and what we need from you.
Depending on the level of access you have granted us, we can act to contain the event by isolating a device or disabling an account, or we can walk your IT team through doing it. This is agreed upon up front and in writing, because 2am is not the time to be negotiating authority.
A written account of what happened and what we would change to stop it from happening again is provided. If it is a reportable incident, we support you with the evidence your insurer and the ICO will want.
Only 25% of UK businesses have a formal incident response plan, falling to 21% of micro businesses and rising to 57% of medium-sized ones. Establishing the escalation path in advance is a large part of the value here, which is quite separate from the monitoring itself.
Phishing simulation operates across monitoring and training, and we run it as part of both.
As a monitoring activity it is a recurring measurement. Controlled, realistic emails are sent on a schedule, with click, credential-entry and reporting rates tracked over time. It tells you whether your human layer is getting stronger or slowly decaying, which is not something any technical control will report on.
Results are always aggregated for management. We do not hand over lists of names for disciplinary purposes. A simulation programme that people experience as a trap will destroy the reporting culture it is meant to build. See cyber security training.
Between full penetration tests, regular vulnerability scanning keeps you honest about the basics.
Scanning is automated, so it is cheap enough to run frequently, and it catches the things that are responsible for most real-world compromises: missing patches on internet-facing systems, unsupported software, exposed services, weak configurations, and expired certificates.
While less thorough than a pen test, a scanner finds known issues, whereas a person will chain three minor weaknesses into a serious one. Run scanning continuously and testing periodically, and between them you will cover both the routine and the unusual.
This matters more since the April 2026 Cyber Essentials update, which made failure to install high-risk and critical updates within 14 days an automatic fail. If you are certified, you need to know about missing patches within days, not at your next annual review.
You get a monthly report with the things a manager needs: what we saw, what we did, what changed, what is outstanding and what we recommend next. This report is written in plain English, with the technical details attached.
Reports are built to be usable in three situations beyond your own management meeting: insurance renewals, client security questionnaires and certification evidence. Being able to produce 12 months of monitoring reports and simulation results answers a lot of questions that would otherwise be awkward.
Where remediation is needed, we will either do it if it is within the agreed scope, or hand your IT provider something specific enough to act on without a translation layer.
Monitoring produces the proof as a by-product.
This is why we bother. Fourarmed grew out of an insurance broker, and one thing that becomes obvious from the claims side is how often a business had the right controls but simply could not prove it when it mattered. See what cyber insurers require.
If you have had an audit and want to keep the picture current, or you have never had eyes on your network out of hours, start with a conversation about what is worth watching in your environment.