Managed security services

Apollo 24x7 SOC

Continuous, intelligence-driven protection across identity, email, endpoints, cloud, and network, delivered by a security operations center built for regulated financial firms.

  • 24/7 MDR
  • SIEM + NIDS
  • MITRE ATT&CK
  • Zero Trust
  • SEC · FINRA · SOC 2 Ready

24/7/365

Analyst-led managed detection and response on the Advanced and Comprehensive tiers

5 layers

Identity, email, endpoint, cloud, and network telemetry correlated in one SIEM

30 days

Incident response playbook finalized and attached to your agreement after signing

2% to 4%

Service credits per missed P1 SLA, up to a monthly cap, written into every Apollo agreement

Apollo 24x7 SOC

A security operations center that sees everything and answers to your regulator

Apollo unifies 24/7 monitoring, next-generation EDR, identity protection, cloud security, and deep network inspection. AI-driven analytics, behavioral detection, and human-led investigation identify threats early and contain them before they become incidents.

Glass shield protecting a glowing blue-violet core
Hover to scan

Identity

Duo MFA, conditional access, ITDR, privilege monitoring

Email

AI-driven phishing defense, sandboxing, URL protection

Endpoint

SentinelOne Complete EDR, encryption, vulnerability scanning

Cloud

M365, Google Workspace and SaaS posture, shadow IT

Network

Perimeter logs, Suricata DPI, exfiltration detection

Apollo platform

Correlate.
Detect.
Respond.

Centralized SIEM

Log ingestion and correlation across every layer

24/7 MDR

AI plus human analysts triaging in real time

Suricata NIDS

Deep packet inspection for lateral movement

Automation

Severity scoring, ticketing, containment playbooks

Containment

Isolation, credential resets, mail recall, blocking, guided by your playbook

Posture

Real-time risk dashboard, vulnerability remediation, hardening

Governance

Policies, risk assessments, vendor reviews, tabletop exercises

Evidence

Auditor-friendly reports for SEC, FINRA, SOC 2 and cyber insurers

Frameworks we build on

From identity and access control to endpoint telemetry, cloud posture, network inspection, threat hunting, and incident response, every layer is aligned with recognized standards.

Zero Trust NIST CSF ISO 27001 MITRE ATT&CK SEC Cyber Rules FINRA SOC 2

Beyond detection

Apollo strengthens your posture with vulnerability management, cyber-risk scoring, zero-trust access enforcement, and continuous alignment with SEC, FINRA, and cyber-insurance expectations. Whether you are establishing foundational protections or need enterprise-grade resilience, the program safeguards your entire digital footprint, continuously and at scale.

Managed SOC tiers

Three tiers, one platform, no gaps between them

Start with foundational protection and compliance coverage, add 24/7 analyst-led response and governance, or step up to human-led threat hunting, zero-trust access, and cyber-insurance readiness.

Tier 01

Core Security

Foundational protection

  • SentinelOne Complete EDR, two licenses per user
  • Duo multi-factor authentication
  • Full disk encryption strategy and rollout
  • AI-driven email security with phishing reporting and banners
  • Awareness training and quarterly phishing simulations
  • Managed vulnerability scanning and remediation
  • Cloud and SaaS data protection, ITDR
  • Real-time risk dashboard and compliance reporting
For: SMBs and smaller financial groups needing regulator-aligned foundations.
Tier 02Most selected

Advanced Security

Proactive defense & response

Everything in Core, plus
  • 24/7 MDR with AI and human analysts
  • Full environment oversight: endpoints, cloud, network, perimeter
  • Duo Access: device posture and conditional access
  • Centralized SIEM with MITRE ATT&CK-mapped detection
  • Security policy program with annual reviews
  • External attack surface and dark web monitoring
  • Automated detection playbooks and containment
For: Firms with SEC, FINRA or SOC 2 obligations.
Tier 03

Comprehensive

Threat intel & strategic resilience

Everything in Advanced, plus
  • Control mapping to NIST CSF, ISO 27001, SEC cyber rules
  • Duo Beyond zero-trust, certificate-based access
  • Human-led custom threat hunting across SIEM, EDR, identity, network
  • Premium threat intelligence and predictive indicators
  • Fully orchestrated IR playbooks with dynamic isolation
  • Suricata DPI exfiltration and insider threat detection
  • Cyber-insurance readiness and audit evidence exports
For: Hedge funds, large financial firms and enterprises needing the highest assurance.

Priced per user, per non-user endpoint and per cloud tenant, plus a platform fee that scales with tier. Contact us for a tailored proposal.

Capability comparison

What each Apollo tier includes

Every capability, tier by tier. Where a tier upgrades a capability rather than simply including it, the note tells you how.

CapabilityCoreAdvancedComprehensive
Endpoint, identity & access
SentinelOne Complete EDR (2 licenses per user)
Duo multi-factor authenticationDuo MFADuo AccessDuo Beyond (zero trust)
Full disk encryption strategy and implementation
Identity threat detection and response (ITDR)
Device posture checks and conditional access
Email & user protection
AI-driven email security, sandboxing, URL defense
Phishing reporting button and caution banners
Awareness training, quarterly simulations, annual webinar
Detection & response
Managed vulnerability scanning and remediation tracking
Cloud application and data protection (M365, Google, SaaS)
24/7 managed detection and response (MDR)
Centralized SIEM with MITRE ATT&CK-mapped detection
External attack surface and dark web monitoring
Automated detection playbooks and containmentFully orchestrated
Human-led custom threat hunting and premium intelligence feeds
Advanced behavioral analytics and forensic post-mortems
Network data exfiltration and insider threat detection (Suricata DPI)Add-on
Governance, risk & compliance
Configurable compliance and activity reportingStrategic reportingAudit evidence exports
Core security policies with annual review (IR, ISP, AUP, access control)
Vendor security reviews and periodic risk assessmentsDue-diligence assessments
Regulatory control mapping (NIST CSF, ISO 27001, SEC rules)
Annual incident response and business continuity tabletopsAdd-onAdd-on
Cyber-insurance readiness and underwriter-aligned risk scoring
Service commitments
Incident response playbook finalized within 30 days
P1 SLA service credits and Data Processing Addendum
Named account manager, SOC manager, and escalation contact
Out-of-scope threat hunting and forensicsHourlyHourlyDiscounted hourly
Governance, risk & service commitments

Security that stands up to examiners, investors, and insurers

Detection is only half of a security program. Apollo pairs the technical stack with the policies, evidence, and contractual commitments that regulated firms are asked to produce, so a due-diligence questionnaire or an SEC examination becomes a document request rather than a fire drill.

Policy program

Incident Response Plan, Information Security Policy, Acceptable Use Policy, access control standards, business continuity and DR plans, vendor risk management, and Acceptable AI Use Policy, in regulated and non-regulated variants, reviewed annually.

Records & retention

Retention architecture that separates vendor-side retention from firm-side capture obligations, with templates covering FINRA 4511, SEA 17a-4, and Advisers Act 204-2 retention periods.

Third-party & AI risk

Vendor due-diligence assessments and formal vendor risk documentation, including reviews of AI platforms before they touch client data.

Contractual commitments in every Apollo agreement

CommitmentDetail
Incident response playbookFinalized and attached as a schedule within 30 days of the effective date; reviewed annually or after any material incident
Service credits2% credit per missed P1 SLA, capped at 4% of the monthly fee, with a 15-day request window
Data Processing AddendumApplies to all personal data processed in the delivery of security services, and takes precedence over the MSA
Incident notificationPrimary and secondary client contacts with an agreed notification method (phone, email, or both)
Named teamAccount manager, security lead / SOC manager, and executive escalation contact with direct lines
TermsOne-year initial term, annual renewal, 30-day termination after the initial term, written change orders for scope changes

Evidence we produce for you

  • Penetration test attestation letters issued after testing and full remediation of findings, ready for investors and counterparties
  • Auditor-friendly posture summaries and event correlation for SEC and FINRA inquiries
  • Cyber-insurance qualification assistance with underwriter-aligned posture scoring
  • DDQ and ODD responses for investor operational due diligence
  • Tabletop exercise reports with executive summaries and recommendations
  • Quarterly site-level threat reports and regulatory-aligned network posture summaries with network IDS

In-house offensive testing. External and internal penetration tests are run by Option One Technologies using an automated network penetration testing platform, mapped to OWASP and MITRE ATT&CK, with remediation tracked to closure.

Add-ons & professional services

Extend Apollo where your risk profile demands it

Security add-ons

Cisco Umbrella

All tiers

Cloud-delivered DNS and web security blocking malicious domains, phishing sites, and command-and-control callbacks. Packages from DNS Security Essentials through SIG Advantage with firewall, CASB, DLP, and sandboxing.

Proofpoint email security

All tiers

Advanced email threat protection with anti-phishing, impersonation detection, sandboxing, link isolation, and outbound DLP. Essentials Business, Essentials Advanced, and Enterprise packages, plus security awareness training.

Mimecast email security & continuity

All tiers

Email filtering, attachment sandboxing, and URL protection paired with cloud archiving (99-year retention), continuity, and DMARC brand protection.

Data loss prevention

All tiers

DLP policies across endpoints, cloud storage, and email to safeguard sensitive data, with device media and USB locking.

Advanced IDS/NIDS with insider & exfiltration detection

Tier 2 & 3

Full Suricata deployment per site with expanded VLAN coverage and high-throughput tuning, plus quarterly site-level threat reports.

Dedicated forensic & threat hunting retainer

Tier 2 & 3

Reserved hours for deep investigations and tailored hunt missions.

Incident response retainer

All tiers

Pre-purchased block of hours for emergency forensic investigation and incident response outside standard SOC coverage.

Professional services

Cybersecurity risk assessment

A comprehensive evaluation aligned to NIST CSF, ISO 27001, and SEC and FINRA requirements: policy review, configuration analysis, identity and access risk, endpoint and cloud posture, vendor risk, business impact and likelihood scoring, a prioritized 30/60/90-day remediation roadmap, executive and technical reports, and a cyber-insurance control readiness evaluation. Priced by organization size.

Internal & external penetration testing

External: simulated real-world attacks against internet-facing infrastructure, firewalls, VPNs, mail gateways, web apps, and DNS. Internal: simulated insider or local-network attacker attempting lateral movement, privilege escalation, and data access. Mapped to OWASP and MITRE ATT&CK, priced by perimeter size or endpoint count, with an attestation letter on full remediation.

Tabletop exercises

Facilitated incident response or business continuity simulations with executive summary and recommendations. Included annually on the Comprehensive tier.

Custom policy development

Additional or specialized security policies beyond the standard set, such as Acceptable AI Use, records retention, or client-specific control frameworks.

SOC onboarding & deployment

Initial deployment, agent installation, SIEM configuration, playbook setup, and environment baseline. Frequently waived on annual agreements.

Next steps

From first call to fully managed in weeks, not quarters

Every engagement starts with a short discovery of your users, sites, platforms and regulatory obligations. From there we recommend a tier, scope any onboarding projects, and present a single ordering document with transparent monthly pricing.

01

Discovery

A 45-minute working session to map users, endpoints, sites, cloud tenants, applications and compliance frameworks.

02

Proposal

Recommended tiers, add-ons and onboarding scope in one ordering document under our Master Services Agreement.

03

Onboarding

Structured rollout with a named engineer team, documentation package and an executive checkpoint at go-live.

Next step

Know your exposure before someone else does.

Start with a 45-minute discovery. We respond within one business day with a slot and a preliminary tier recommendation.

Continuous monitoring

24 / 7 / 365.
The page ends. The watch doesn't.

  • Helpdesk24x7x365ONLINE
  • Network operationsAll sitesMONITORING
  • Apollo SOC5 layers → SIEMACTIVE
  • Private cloudEast ↔ West99.99%
Telemetry ingest · live
Option One Technologies

Managed IT, 24x7 network operations, private cloud, and the Apollo security operations center for SEC and FINRA-regulated financial firms and growth companies.

© 2026 Option One Technologies LLC. Service descriptions are summaries; the governing scope, service levels and commercial terms are set out in the Master Services Agreement and applicable Ordering Document. Microsoft, Lenovo, Cisco, Meraki, Fortinet, Palo Alto Networks, SentinelOne, Duo, Suricata, Intune, Jamf, Kandji, Bloomberg and Amazon Bedrock are trademarks of their respective owners.