A Fortify 24x7 brand. Security operated for the plant, the depot, and the offices behind both.Sign inRaise a job
Industry LockNetworks
Bay 01 / Detection and response

Something watches, and a shift answers.

A detection product is three things bolted together: software on the machine that can tell an ordinary backup job apart from an encryption run, a layer that reads it against everything else moving through the estate, and a rota of people deciding what happens next. All three ride on each of the six lines below.

SentinelOneFluencyDesk manned every shift
Every tag in this bay carries its own counting unit
Tags in this bay6
Plant on the lineSentinelOne + Fluency
One unit equalsEndpoint, or Kubernetes node
CoverManned every shift

What the agent is genuinely looking at

Matching a list of known bad files stopped being sufficient some years ago, and everybody in this trade knows it. The SentinelOne agent models what is going on inside the machine: the processes started, the files opened, the places reached, and whether the shape of it resembles collection, encryption, or somebody quietly working sideways through a network.

It keeps judging with nothing connected at all, which counts for more in an industrial business than most vendors will admit. The laptop in a van between depots and the workstation on a mezzanine that only sees the network on alternate Thursdays are both still being judged.

Picking a level of response

The detection line does triage and gives advice. The extended line broadens what is read side by side, so a peculiar sign-in at one site and an odd process at another stop being unrelated curiosities filed by different people. The response level adds containment and reversal with nobody asking for it, which is exactly the behavior you want on a Sunday night.

Kubernetes nodes carry lines of their own. Nodes get their own lines. The agent behaves unlike its endpoint sibling, and merging the two counts would leave an invoice that quietly misstates things. Count nodes, not pods.

An alert that arrives without its context is a job for you. An alert that arrives with it is a job for us.
Tags in this bay

Specifications and rates

Every rate on this page comes live off the billing service. Anything locked on stays on the worklist while you read on.

Hasp open, tags below
Fortify-MDRDanger tag

Managed Detection and Response

Plant · SentinelOne on the box, Fluency holding the record, analysts on shift

A behavioral agent watches what each process is actually doing, and a desk with people on it decides what happens next. What reaches you is a finding with a recommended action attached, not a chart to interpret in the small hours.

  • The agent covers Windows, Mac, and Linux, and it keeps judging even with the machine off the network.
  • Fortify 24x7 engineers on shift do the triage, the investigation, and the escalation.
  • Every finding, and the reasoning underneath it, stays legible in your portal.
Mounted onSentinelOne, on a Windows, Mac, or Linux endpoint
IsolatesA process that has started encrypting, collecting, or spreading
Retained forCase notes, retained the whole time a line is running
Released byYour own team, working to the written instruction the analyst leaves
Signed off byThe Fortify 24x7 engineer who closed the case, in the case record
Readingper protected endpoint
settled one month ahead
QTY
Fortify-XDRDanger tag

Extended Detection Across Layers

Plant · SentinelOne, with Fluency reading the other sources beside it

Everything the detection line does, but widened, so a peculiar sign-in logged at one site and an odd process running at another stop being unrelated curiosities filed by different people.

  • Endpoint activity gets read beside identity, beside mail, and beside network records.
  • Findings that no agent working alone could arrive at from its own record.
  • Longer retention, because some sequences only make sense looking backwards.
Mounted onSentinelOne agent, with Fluency taking feeds from your other sources
IsolatesA pattern that only shows up once two systems are read together
Retained forJoined-source retention, extended, agreed at scoping
Released byYour own team, working to the written instruction the analyst leaves
Signed off byThe Fortify 24x7 engineer who closed the case, in the case record
Readingper protected endpoint
settled one month ahead
QTY
Fortify-XDR+Danger tag

Extended Detection with Response

Plant · SentinelOne, with containment and rollback left armed

The joined-up tier with hands on it. Cross the response threshold and the machine leaves its network and is reverted before anyone at our desk has finished reading the case. That is the gap between a bad hour and a bad quarter.

  • Once conviction is firm the endpoint takes itself off the network.
  • On systems that support it, whatever a convicted process altered gets put back.
  • A person reads each automated action back afterwards and writes it up.
Mounted onSentinelOne on the endpoint, response left armed
IsolatesThe endpoint itself, off its network the moment conviction lands
Retained forCase notes, retained the whole time a line is running
Released byA Fortify 24x7 analyst, after the review of the automated action
Signed off byThe Fortify 24x7 engineer who closed the case, in the case record
Readingper protected endpoint
settled one month ahead
QTY
Fortify-MDR-K8Danger tag

Managed Detection, Kubernetes Node

Plant · SentinelOne, watching container workloads at runtime

Detection for containerized workloads. Nodes are what get counted, so the invoice matches whatever figure your platform team is already tracking. Count nodes, not pods.

  • An agent sits on the node and covers whatever the scheduler puts there.
  • Runtime behavior rather than image scanning done once at build time.
  • Same desk, same triage, and a case that runs exactly as it would on an endpoint line.
Mounted onSentinelOne for Kubernetes, on each node you enroll
IsolatesA workload behaving unlike anything the cluster is supposed to run
Retained forCase notes, retained the whole time a line is running
Released byYour own platform team, working to the analyst instruction
Signed off byThe Fortify 24x7 engineer who closed the case, in the case record
Readingper Kubernetes node
settled one month ahead
QTY
Fortify-XDR-K8Danger tag

Extended Detection, Kubernetes Node

Plant · SentinelOne on the nodes, with Fluency reading them alongside everything else

Node detection with the joining layer live, which sets cluster activity next to identity records and endpoint records instead of walling it off in its own window.

  • Node records read inside Fluency beside whatever else is running.
  • Findings that join a workload to the account which reached into it.
  • Retention that stretches across cluster records and endpoint records at once.
Mounted onSentinelOne for Kubernetes, taking the cluster feed into Fluency
IsolatesA chain that runs from an account into a workload and back out
Retained forJoined-source retention, extended, agreed at scoping
Released byYour own platform team, working to the analyst instruction
Signed off byThe Fortify 24x7 engineer who closed the case, in the case record
Readingper Kubernetes node
settled one month ahead
QTY
Fortify-XDR+K8Danger tag

Response Tier, Kubernetes Node

Plant · SentinelOne, acting on a container without waiting to be asked

Node detection with response armed, for a cluster whose work cannot be left misbehaving until somebody opens a laptop on Monday.

  • Where a workload passes the response threshold, containment follows on its own.
  • A single case, built at once from cluster evidence, identity evidence, and endpoint evidence.
  • A person reads each automated action back afterwards, records it, and sends it through.
Mounted onSentinelOne for Kubernetes, response left armed
IsolatesThe offending workload, contained where it stands
Retained forCase notes, retained the whole time a line is running
Released byA Fortify 24x7 analyst, after the review of the automated action
Signed off byThe Fortify 24x7 engineer who closed the case, in the case record
Readingper Kubernetes node
settled one month ahead
QTY
Honest scope

Where this bay stops

As a control detection is decent. As a guarantee it is worthless. What follows is the ground these six lines cannot cover, written down so the gap is yours to fill knowingly.

  • Nothing here goes on the control network. These agents install on IT endpoints, servers, and Kubernetes nodes. They do not go on a PLC, an HMI, a historian, or a safety instrumented system, and we will not pretend the coverage extends onto the plant floor because the logo suggests it might.
  • Detection is not prevention. When an agent recognizes an intrusion, the intrusion has already started. What is being bought is the speed of what comes next. Nobody anywhere sells the promise that nothing ever begins.
  • Hardware with no agent produces nothing. Unenrolled hardware emits nothing at all. It cannot appear in an investigation, and no line in this bay reaches it.
  • Reversal is not a backup. On systems that support it, the response level restores what a convicted process changed. It will not resurrect a dead drive, nor last Tuesday's version of a drawing. That work belongs in the backup and continuity bay.
  • The node lines reach the nodes. Cluster architecture, the binding of roles, the handling of secrets, and whatever admission policy says all stay yours. Ask and you get an opinion. Owning them is not our job.
Money side

Heads up: card statements show FORTIFY 24X7 - Industry Lock Networks is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.