Managed Security Program

Keep the security program moving.

Praeven gives small and midsize businesses a practical security owner: recurring priorities, reviewed external exposure, business-platform review, and coordination with the people who run your technology.

Scope that matches how small businesses operate

Three ways to see the program.

External exposure, business platforms, and workforce devices each need a different kind of review. We agree on the relevant scope before work begins.

Internet-facing assets

Public IP addresses, hostnames, VPN gateways, web applications, email services, and cloud systems that your organization owns or is authorized to test.

Monthly external validation focuses on this approved list. It does not treat employee laptops as public scan targets.

Microsoft 365 and business platforms

Identity, multifactor authentication, privileged access, sharing, email protection, and other relevant tenant settings.

One Microsoft 365 tenant or comparable business platform can be included when its administrator or service provider supplies the agreed reports and evidence.

Endpoint security

Internal endpoint assessment, agent deployment, and ongoing device management require their own authorization, tooling, and delivery plan.

They are not included in the managed program. When a client already has endpoint tooling, its operator can provide agreed high-level evidence for discussion.

Built to work with your provider

Security leadership without replacing IT.

Praeven complements an internal IT team or managed service provider. We do not take over their help desk, infrastructure administration, log management, or remediation work.

Your provider continues to operate the environment. Praeven maintains priorities, translates findings into practical decisions, coordinates security work, and helps leadership see what needs attention next.

AI-assisted workflows organize recurring evidence and prepare reporting. Every client-facing recommendation is reviewed by Praeven operators and engineers.

What the monthly cadence produces

  • An agreed inventory of internet-facing assets and business platforms
  • A living risk register with accountable owners and practical next actions
  • Reviewed external vulnerability findings for approved public assets
  • Relevant Microsoft 365 or comparable business-platform observations when those services are in scope
  • A concise report and working session focused on progress, decisions, and blockers

For managed service providers

Add security leadership without giving up the customer relationship.

Praeven works alongside MSPs and internal IT teams that want a clearer security-program layer for their clients.

The provider retains technology operations, help desk, licensing, and implementation work. Praeven supplies recurring security priorities, reviewed external findings, leadership reporting, and a practical way to explain security progress to the client.

A clear division of work

  • Agree on client contacts, ownership, escalation paths, and evidence sources before work starts
  • Use a shared remediation plan so the provider can implement approved changes
  • Give leadership a concise, security-focused view of progress and decisions
  • Keep scope, technology access, and client communications visible to the right people

A three-month start

Establish the cadence before judging the result.

Managed programs begin with a three-month initial term so the right people, evidence, priorities, and remediation rhythm are in place.

Days 1–30

Set the scope

Confirm business contacts, approved internet-facing assets, service-provider roles, scan windows, available platform evidence, and the first priority list.

Days 31–60

Turn findings into work

Review the first validation and posture evidence, maintain the risk register, and help the organization or its provider sequence agreed fixes.

Days 61–90

Make it repeatable

Confirm ownership, report progress to leadership, establish the recurring review rhythm, and agree on the next quarter’s security priorities.

Choose the operating depth

Start with the work you need now.

Prices are monthly. Internet-facing assets, business platforms, response expectations, and any work outside the listed scope are confirmed before the engagement starts.

Managed Security Program comparison
ProgramExternal validationBusiness-platform reviewProgram leadershipPrice
External Exposure ReviewFor organizations that want a reviewed public-exposure view.Up to 5 approved internet-facing assets; monthly external vulnerability review—Concise findings report and monthly results call$895per month
Managed Security ProgramFor a small organization with IT support but no dedicated security owner.Up to 5 approved internet-facing assets; monthly reviewed validationOne business tenant and agreed identity, access, and configuration evidenceRisk register, monthly review, and up to 2 business-hours advisory hours$1,895per month
Managed Security Program — StandardFor a growing organization that needs regular coordination.Up to 25 approved internet-facing assets; monthly reviewed validationOne business tenant and expanded agreed evidence reviewRisk register, remediation coordination, regular working sessions, and up to 6 business-hours advisory hours$3,000per month
Managed Security Program — ExpandedFor an organization with deeper governance and reporting needs.Up to 25 approved internet-facing assets; expanded review and executive reportingOne business tenant and expanded agreed evidence reviewBiweekly working cadence, policy and vendor work, leadership reporting, and up to 12 business-hours advisory hours$5,000per month
Embedded Security LeadershipFor organizations that need substantial security-program ownership.Custom approved scopeCustom approved scopeWeekly operating cadence, executive leadership support, and substantial program ownershipCustom scopeleadership engagement

An internet-facing asset is a public IP address, fully qualified domain name, gateway, application, or cloud system specifically listed in the approved scope. Endpoint assessment, internal scanning, agent deployment, or endpoint management are separately scoped. Programs do not include 24/7 monitoring, active containment, malware removal, forensics, legal advice, breach notification, penetration testing, or testing of third-party systems without their written authorization.

Program additions

Add capacity where the program needs it.

These recurring additions are available with an active Managed Security Program. They extend an agreed scope; they are not standalone assessments, and they do not replace a higher tier when the operating cadence needs to grow.

Managed Security Program additions
AdditionScopePrice
Additional Internet-Facing Asset BlockManaged Security ProgramAdds up to five approved public IPs, hostnames, gateways, applications, email services, or cloud systems to the monthly external-validation list. Available up to 25 total approved internet-facing assets; broader scope moves to Standard or a custom engagement.$250per month · up to 5 additional assets
Additional Business Tenant ReviewManaged Security Program and aboveAdds a Microsoft 365, Google Workspace, or comparable business tenant to the agreed identity, access, sharing, and protection evidence review. Requires an agreed evidence source and an authorized tenant administrator or provider contact.$400per month · each additional tenant
Additional Advisory CapacityManaged Security Program and StandardAdds scheduled time for security planning, remediation coordination, policy decisions, vendor questions, or leadership preparation. Hours are used during the month and do not roll over; work outside the agreed scope is approved before it begins.$450per month · 2 business-hours
Quarterly Leadership ReadoutManaged Security Program and StandardAdds preparation, a leadership-facing review of progress and decisions, and a written next-quarter priority summary. Expanded and Embedded programs include leadership reporting as part of their operating cadence.$750per quarterly session

Industry fit

Start with the work your business depends on.

Managed Security Program is designed for organizations that have IT support but need a security owner who understands their daily operating decisions.

Contractors & field services

Protect estimates, invoices, mobile work, vendor trust, Microsoft 365, and the systems that keep jobs moving.

Explore field-service security

Hospitality & restaurant groups

Coordinate security around locations, suppliers, staff access, public brands, and customer-facing operations.

Explore hospitality security

See all industry starting points.

When a fixed project comes first

Build the foundation when the program has no starting point.

Some organizations need policies, ownership, and a prioritized roadmap before a monthly cadence will be useful.

Security Baseline and Security Foundations projects establish that foundation. Praeven can recommend a project before a managed program when current documentation, roles, or controls need attention first.

Before we begin

  • One legal entity and named business contacts
  • Written authorization for every internet-facing asset reviewed
  • A designated IT contact or service provider
  • An agreed evidence source for any business-platform review
  • Clear escalation and stop contacts

Prepare. Anticipate. Protect.