Managed security services
Apollo 24x7 SOC
Continuous, intelligence-driven protection across identity, email, endpoints, cloud, and network, delivered by a security operations center built for regulated financial firms.
- 24/7 MDR
- SIEM + NIDS
- MITRE ATT&CK
- Zero Trust
- SEC · FINRA · SOC 2 Ready
24/7/365
Analyst-led managed detection and response on the Advanced and Comprehensive tiers
5 layers
Identity, email, endpoint, cloud, and network telemetry correlated in one SIEM
30 days
Incident response playbook finalized and attached to your agreement after signing
2% to 4%
Service credits per missed P1 SLA, up to a monthly cap, written into every Apollo agreement
A security operations center that sees everything and answers to your regulator
Apollo unifies 24/7 monitoring, next-generation EDR, identity protection, cloud security, and deep network inspection. AI-driven analytics, behavioral detection, and human-led investigation identify threats early and contain them before they become incidents.

Identity
Duo MFA, conditional access, ITDR, privilege monitoring
AI-driven phishing defense, sandboxing, URL protection
Endpoint
SentinelOne Complete EDR, encryption, vulnerability scanning
Cloud
M365, Google Workspace and SaaS posture, shadow IT
Network
Perimeter logs, Suricata DPI, exfiltration detection
Apollo platform
Correlate.
Detect.
Respond.
Centralized SIEM
Log ingestion and correlation across every layer
24/7 MDR
AI plus human analysts triaging in real time
Suricata NIDS
Deep packet inspection for lateral movement
Automation
Severity scoring, ticketing, containment playbooks
Containment
Isolation, credential resets, mail recall, blocking, guided by your playbook
Posture
Real-time risk dashboard, vulnerability remediation, hardening
Governance
Policies, risk assessments, vendor reviews, tabletop exercises
Evidence
Auditor-friendly reports for SEC, FINRA, SOC 2 and cyber insurers
Frameworks we build on
From identity and access control to endpoint telemetry, cloud posture, network inspection, threat hunting, and incident response, every layer is aligned with recognized standards.
Beyond detection
Apollo strengthens your posture with vulnerability management, cyber-risk scoring, zero-trust access enforcement, and continuous alignment with SEC, FINRA, and cyber-insurance expectations. Whether you are establishing foundational protections or need enterprise-grade resilience, the program safeguards your entire digital footprint, continuously and at scale.
Three tiers, one platform, no gaps between them
Start with foundational protection and compliance coverage, add 24/7 analyst-led response and governance, or step up to human-led threat hunting, zero-trust access, and cyber-insurance readiness.
Core Security
Foundational protection
- SentinelOne Complete EDR, two licenses per user
- Duo multi-factor authentication
- Full disk encryption strategy and rollout
- AI-driven email security with phishing reporting and banners
- Awareness training and quarterly phishing simulations
- Managed vulnerability scanning and remediation
- Cloud and SaaS data protection, ITDR
- Real-time risk dashboard and compliance reporting
Advanced Security
Proactive defense & response
Everything in Core, plus- 24/7 MDR with AI and human analysts
- Full environment oversight: endpoints, cloud, network, perimeter
- Duo Access: device posture and conditional access
- Centralized SIEM with MITRE ATT&CK-mapped detection
- Security policy program with annual reviews
- External attack surface and dark web monitoring
- Automated detection playbooks and containment
Comprehensive
Threat intel & strategic resilience
Everything in Advanced, plus- Control mapping to NIST CSF, ISO 27001, SEC cyber rules
- Duo Beyond zero-trust, certificate-based access
- Human-led custom threat hunting across SIEM, EDR, identity, network
- Premium threat intelligence and predictive indicators
- Fully orchestrated IR playbooks with dynamic isolation
- Suricata DPI exfiltration and insider threat detection
- Cyber-insurance readiness and audit evidence exports
Priced per user, per non-user endpoint and per cloud tenant, plus a platform fee that scales with tier. Contact us for a tailored proposal.
What each Apollo tier includes
Every capability, tier by tier. Where a tier upgrades a capability rather than simply including it, the note tells you how.
| Capability | Core | Advanced | Comprehensive |
|---|---|---|---|
| Endpoint, identity & access | |||
| SentinelOne Complete EDR (2 licenses per user) | |||
| Duo multi-factor authentication | Duo MFA | Duo Access | Duo Beyond (zero trust) |
| Full disk encryption strategy and implementation | |||
| Identity threat detection and response (ITDR) | |||
| Device posture checks and conditional access | |||
| Email & user protection | |||
| AI-driven email security, sandboxing, URL defense | |||
| Phishing reporting button and caution banners | |||
| Awareness training, quarterly simulations, annual webinar | |||
| Detection & response | |||
| Managed vulnerability scanning and remediation tracking | |||
| Cloud application and data protection (M365, Google, SaaS) | |||
| 24/7 managed detection and response (MDR) | |||
| Centralized SIEM with MITRE ATT&CK-mapped detection | |||
| External attack surface and dark web monitoring | |||
| Automated detection playbooks and containment | Fully orchestrated | ||
| Human-led custom threat hunting and premium intelligence feeds | |||
| Advanced behavioral analytics and forensic post-mortems | |||
| Network data exfiltration and insider threat detection (Suricata DPI) | Add-on | ||
| Governance, risk & compliance | |||
| Configurable compliance and activity reporting | Strategic reporting | Audit evidence exports | |
| Core security policies with annual review (IR, ISP, AUP, access control) | |||
| Vendor security reviews and periodic risk assessments | Due-diligence assessments | ||
| Regulatory control mapping (NIST CSF, ISO 27001, SEC rules) | |||
| Annual incident response and business continuity tabletops | Add-on | Add-on | |
| Cyber-insurance readiness and underwriter-aligned risk scoring | |||
| Service commitments | |||
| Incident response playbook finalized within 30 days | |||
| P1 SLA service credits and Data Processing Addendum | |||
| Named account manager, SOC manager, and escalation contact | |||
| Out-of-scope threat hunting and forensics | Hourly | Hourly | Discounted hourly |
Security that stands up to examiners, investors, and insurers
Detection is only half of a security program. Apollo pairs the technical stack with the policies, evidence, and contractual commitments that regulated firms are asked to produce, so a due-diligence questionnaire or an SEC examination becomes a document request rather than a fire drill.
Policy program
Incident Response Plan, Information Security Policy, Acceptable Use Policy, access control standards, business continuity and DR plans, vendor risk management, and Acceptable AI Use Policy, in regulated and non-regulated variants, reviewed annually.
Records & retention
Retention architecture that separates vendor-side retention from firm-side capture obligations, with templates covering FINRA 4511, SEA 17a-4, and Advisers Act 204-2 retention periods.
Third-party & AI risk
Vendor due-diligence assessments and formal vendor risk documentation, including reviews of AI platforms before they touch client data.
Contractual commitments in every Apollo agreement
| Commitment | Detail |
|---|---|
| Incident response playbook | Finalized and attached as a schedule within 30 days of the effective date; reviewed annually or after any material incident |
| Service credits | 2% credit per missed P1 SLA, capped at 4% of the monthly fee, with a 15-day request window |
| Data Processing Addendum | Applies to all personal data processed in the delivery of security services, and takes precedence over the MSA |
| Incident notification | Primary and secondary client contacts with an agreed notification method (phone, email, or both) |
| Named team | Account manager, security lead / SOC manager, and executive escalation contact with direct lines |
| Terms | One-year initial term, annual renewal, 30-day termination after the initial term, written change orders for scope changes |
Evidence we produce for you
- Penetration test attestation letters issued after testing and full remediation of findings, ready for investors and counterparties
- Auditor-friendly posture summaries and event correlation for SEC and FINRA inquiries
- Cyber-insurance qualification assistance with underwriter-aligned posture scoring
- DDQ and ODD responses for investor operational due diligence
- Tabletop exercise reports with executive summaries and recommendations
- Quarterly site-level threat reports and regulatory-aligned network posture summaries with network IDS
In-house offensive testing. External and internal penetration tests are run by Option One Technologies using an automated network penetration testing platform, mapped to OWASP and MITRE ATT&CK, with remediation tracked to closure.
Extend Apollo where your risk profile demands it
Security add-ons
Cisco Umbrella
All tiersCloud-delivered DNS and web security blocking malicious domains, phishing sites, and command-and-control callbacks. Packages from DNS Security Essentials through SIG Advantage with firewall, CASB, DLP, and sandboxing.
Proofpoint email security
All tiersAdvanced email threat protection with anti-phishing, impersonation detection, sandboxing, link isolation, and outbound DLP. Essentials Business, Essentials Advanced, and Enterprise packages, plus security awareness training.
Mimecast email security & continuity
All tiersEmail filtering, attachment sandboxing, and URL protection paired with cloud archiving (99-year retention), continuity, and DMARC brand protection.
Data loss prevention
All tiersDLP policies across endpoints, cloud storage, and email to safeguard sensitive data, with device media and USB locking.
Advanced IDS/NIDS with insider & exfiltration detection
Tier 2 & 3Full Suricata deployment per site with expanded VLAN coverage and high-throughput tuning, plus quarterly site-level threat reports.
Dedicated forensic & threat hunting retainer
Tier 2 & 3Reserved hours for deep investigations and tailored hunt missions.
Incident response retainer
All tiersPre-purchased block of hours for emergency forensic investigation and incident response outside standard SOC coverage.
Professional services
Cybersecurity risk assessment
A comprehensive evaluation aligned to NIST CSF, ISO 27001, and SEC and FINRA requirements: policy review, configuration analysis, identity and access risk, endpoint and cloud posture, vendor risk, business impact and likelihood scoring, a prioritized 30/60/90-day remediation roadmap, executive and technical reports, and a cyber-insurance control readiness evaluation. Priced by organization size.
Internal & external penetration testing
External: simulated real-world attacks against internet-facing infrastructure, firewalls, VPNs, mail gateways, web apps, and DNS. Internal: simulated insider or local-network attacker attempting lateral movement, privilege escalation, and data access. Mapped to OWASP and MITRE ATT&CK, priced by perimeter size or endpoint count, with an attestation letter on full remediation.
Tabletop exercises
Facilitated incident response or business continuity simulations with executive summary and recommendations. Included annually on the Comprehensive tier.
Custom policy development
Additional or specialized security policies beyond the standard set, such as Acceptable AI Use, records retention, or client-specific control frameworks.
SOC onboarding & deployment
Initial deployment, agent installation, SIEM configuration, playbook setup, and environment baseline. Frequently waived on annual agreements.
From first call to fully managed in weeks, not quarters
Every engagement starts with a short discovery of your users, sites, platforms and regulatory obligations. From there we recommend a tier, scope any onboarding projects, and present a single ordering document with transparent monthly pricing.
Discovery
A 45-minute working session to map users, endpoints, sites, cloud tenants, applications and compliance frameworks.
Proposal
Recommended tiers, add-ons and onboarding scope in one ordering document under our Master Services Agreement.
Onboarding
Structured rollout with a named engineer team, documentation package and an executive checkpoint at go-live.
Next step
Know your exposure before someone else does.
Start with a 45-minute discovery. We respond within one business day with a slot and a preliminary tier recommendation.
