Pillar 03 ยท Monitor

24/7 Cyber Security Monitoring

Cyber security monitoring answers the question a cyber security audit cannot: what about next month?

An audit tells you where you stood the week it was done. That is valuable, but it has a shelf life.

Between one audit and the next, your business changes. New employees, new software, new suppliers, a laptop that stops getting patched, and a firewall rule someone added for a good reason in March and never removed can all have an impact. Meanwhile the threats themselves move independently of anything you do.

Monitoring is the answer to this drift. It is the always-on complement to the point-in-time assessment, and for most businesses, it turns "we had an audit" into "we manage our security".

Surfaces
Network, endpoints, email, authentication, config drift, dark web
Escalation
By phone, to named contacts, against agreed criteria
Containment
Only where you have granted access, agreed in writing
Reporting
Monthly, in plain English with technical detail attached
Also includes
Vulnerability scanning and phishing simulation
Usable for
Insurance renewal, client questionnaires, certification evidence

What We Monitor

Six surfaces, continuously

Continuous monitoring means someone is watching your environment for evidence of an attack while your business gets on with its day, including the hours when nobody is in the office, which is exactly when serious attacks tend to be staged.

Network traffic

Monitored for connections to known-bad destinations, unexpected data volumes leaving the network, and lateral movement between systems that have no business talking to each other.

Endpoints

Watched for malware, unusual process behaviour, disabled security tooling and devices falling behind on patching.

Email

Still the front door for most attacks. We track volume, sender anomalies, and the patterns that precede business email compromise.

Authentication

Tracked for bursts of failed logins, sign-ins from improbable locations, repeated multi-factor prompts a user did not trigger, and new administrator accounts appearing.

Configuration drift

An issue because most environments degrade slowly rather than failing all at once.

Dark web exposure

Triggers an alert if your domains and credentials appear in breach dumps or criminal marketplaces.

Generating alerts is easy. The value lies in telling the difference between noise and something that matters, and getting a human decision in front of you quickly when it does.

Detection time is the reason this is worth paying for. Serious intrusions are rarely a single dramatic event. Someone gets a foothold, looks around, works out where the valuable systems and the backups are, escalates their access, and only then does the visible damage. This reconnaissance phase is where an attack is cheapest to stop, and it is almost entirely invisible to a business that is not watching. By the time the obvious symptoms appear, with files encrypted and systems unavailable, the decisions that determine how bad it gets have already been made for you.

How Threats Get Escalated

You need to know what happens at 2am
  1. Triage

    Alerts are assessed and the great majority are resolved without troubling you. A single failed login is not an incident.

  2. Notification

    Where something needs your attention but is not urgent, such as a device drifting out of patch compliance or a user account behaving oddly, notification is provided as part of the regular reporting with a recommended action.

  3. Escalation

    Where there are signs of an active compromise, we contact your named contacts directly by phone, according to established escalation criteria. You are notified of what we have seen, what we think it is, what we recommend, and what we need from you.

  4. Containment

    Depending on the level of access you have granted us, we can act to contain the event by isolating a device or disabling an account, or we can walk your IT team through doing it. This is agreed upon up front and in writing, because 2am is not the time to be negotiating authority.

  5. Afterwards

    A written account of what happened and what we would change to stop it from happening again is provided. If it is a reportable incident, we support you with the evidence your insurer and the ICO will want.

Only 25% of UK businesses have a formal incident response plan, falling to 21% of micro businesses and rising to 57% of medium-sized ones. Establishing the escalation path in advance is a large part of the value here, which is quite separate from the monitoring itself.

Phishing Tests and Vulnerability Scanning

Two recurring measurements

Phishing tests and simulations

Phishing simulation operates across monitoring and training, and we run it as part of both.

As a monitoring activity it is a recurring measurement. Controlled, realistic emails are sent on a schedule, with click, credential-entry and reporting rates tracked over time. It tells you whether your human layer is getting stronger or slowly decaying, which is not something any technical control will report on.

Results are always aggregated for management. We do not hand over lists of names for disciplinary purposes. A simulation programme that people experience as a trap will destroy the reporting culture it is meant to build. See cyber security training.

Vulnerability scanning

Between full penetration tests, regular vulnerability scanning keeps you honest about the basics.

Scanning is automated, so it is cheap enough to run frequently, and it catches the things that are responsible for most real-world compromises: missing patches on internet-facing systems, unsupported software, exposed services, weak configurations, and expired certificates.

While less thorough than a pen test, a scanner finds known issues, whereas a person will chain three minor weaknesses into a serious one. Run scanning continuously and testing periodically, and between them you will cover both the routine and the unusual.

This matters more since the April 2026 Cyber Essentials update, which made failure to install high-risk and critical updates within 14 days an automatic fail. If you are certified, you need to know about missing patches within days, not at your next annual review.

Reporting and Remediation

Monthly, and usable elsewhere

You get a monthly report with the things a manager needs: what we saw, what we did, what changed, what is outstanding and what we recommend next. This report is written in plain English, with the technical details attached.

Reports are built to be usable in three situations beyond your own management meeting: insurance renewals, client security questionnaires and certification evidence. Being able to produce 12 months of monitoring reports and simulation results answers a lot of questions that would otherwise be awkward.

Where remediation is needed, we will either do it if it is within the agreed scope, or hand your IT provider something specific enough to act on without a translation layer.

Monitoring produces the proof as a by-product.

This is why we bother. Fourarmed grew out of an insurance broker, and one thing that becomes obvious from the claims side is how often a business had the right controls but simply could not prove it when it mattered. See what cyber insurers require.

Common questions

Five questions
What exactly do you monitor?
Network traffic, endpoints, email, authentication, configuration drift and dark web exposure. Between them these cover how attacks arrive, how they move, and how they show up before the damage is visible.
What happens if you find something at 2am?
Where there are signs of an active compromise, we contact your named contacts directly by phone, according to escalation criteria established in advance. You are told what we have seen, what we think it is, what we recommend, and what we need from you.
Do you need access to our systems?
Yes, and the level of access is agreed up front and in writing. Depending on what you have granted us, we can act to contain an event by isolating a device or disabling an account, or we can walk your IT team through doing it. Two in the morning is not the time to be negotiating authority.
What is the difference between monitoring and a penetration test?
Monitoring is continuous and tells you when something is happening. A penetration test is a point-in-time exercise that tells you whether someone trying to break in would succeed. Run scanning continuously and testing periodically, and between them you cover both the routine and the unusual.
Can we use your reports for our insurance renewal?
Yes. Reports are built to be usable at insurance renewals, in client security questionnaires and as certification evidence, as well as in your own management meetings.
Talk to us

Never had eyes on your network out of hours?

If you have had an audit and want to keep the picture current, or you have never had eyes on your network out of hours, start with a conversation about what is worth watching in your environment.