Security someone actually runs.
Most security programs fail in the gap between buying a tool and operating it. SubRosa runs the ongoing work: monitoring, training, email defence, and the telemetry underneath it. The controls you have bought become the controls that are actually working.
Managed SOC · Awareness training · Email security · Log ingestion
What is a managed security service provider?
A managed security service provider, or MSSP, operates parts of your security programme for you rather than selling you software to operate yourself. That usually covers continuous monitoring and response, security awareness training, email and endpoint defence, and the log collection that makes detection possible. The reason organizations use one is rarely the technology. Running security properly needs people on it at 3am, and most teams cannot staff that alone.
Four services, one team.
Each runs as an ongoing service with SubRosa engineers behind it, not a licence and a login.
Managed SOC
24/7 monitoring, detection, and response, triaged by SubRosa analysts before anything reaches your team.
Security awareness training
Phishing simulation and training that reduces the click rate, with the reporting your auditors ask for.
Managed email security
Managed defence against phishing, malware, and business email compromise on the channel attackers use most.
Third-party log ingestion
Bring telemetry from tools you already own into one place, so detection covers your whole estate rather than part of it.
From first call to running service.
Managed services go wrong at handover more often than in operation. This is how the transition is structured.
- 01
Scoping what you need run
Not every organisation needs every service. We establish what you genuinely need operated for you versus what your team is better placed to keep, because paying for managed coverage of something you already do well is waste.
- 02
Environment review
Before anything is deployed we look at what you have: existing tooling, log sources, coverage gaps and what can be reused. Replacing a working control to fit a service package is rarely in your interest.
- 03
Deployment and tuning
Agents, log sources and integrations are deployed and then tuned to your environment. Untuned detection produces alert volume nobody can sustain, and the tuning period is what determines whether the service is useful or ignored.
- 04
Baseline period
An initial period establishes what normal looks like for you. Alerting thresholds set before that baseline exists generate noise, and noise is how real alerts get missed.
- 05
Steady-state operation
The service runs with agreed response times and defined escalation. You know who to call, what happens automatically, and what needs your decision.
- 06
Regular review
Regular review of what fired, what was missed, and what changed in your environment. A managed service configured once and never revisited degrades quietly as the estate moves around it.
An operator, not a reseller.
Run by practitioners
Former incident responders and counterintelligence practitioners do the work, so escalations are judged by people who have handled the real thing.
One workspace
The SOC, your vulnerability findings and your control evidence share one workspace in Sable, instead of separate consoles that never reconcile.
Priced to be kept
Enterprise-grade operations without the cost of building the team in-house, which is what makes a security programme survive its second year.
Everything reports to one place.
Detection and response run inside Sable, in the same workspace as your policies, risk register, vulnerability findings and control evidence, so the question “are we covered?” has an answer instead of four exports. Awareness training is delivered directly rather than through the platform.
- 24/7Managed SOC3 alerts triaged, 0 escalated
- LiveVulnerability findings9 open, ranked by risk
- CurrentControls & evidenceSOC 2 controls mapped
- This quarterPolicies94% acknowledged
Common questions
- What is a managed security service provider (MSSP)?
- A managed security service provider operates parts of your security programme for you rather than selling you software to run yourself. That typically covers continuous monitoring and response, security awareness training, email and endpoint defence, and the log collection that makes detection possible. Organizations use an MSSP because running security properly requires people on it around the clock, which most internal teams cannot staff alone.
- What managed security services does SubRosa offer?
- Four: a 24/7 managed SOC with detection and response triaged by SubRosa analysts; security awareness training with continuous phishing simulation; managed email security against phishing, malware, and business email compromise; and third-party log ingestion to bring telemetry from tools you already own into one place.
- How are managed security services different from buying security tools?
- A tool gives you a console and an alert queue that someone has to watch, tune, and act on. A managed service includes the people doing that work. Most security programmes fail in the gap between purchase and operation, where controls are bought and configured but nobody owns them day to day.
- Do the services have to be bought together?
- No. Each runs independently and organizations commonly start with one, most often the managed SOC or awareness training. They do compound: log ingestion improves what the SOC can detect, and awareness training reduces the volume of email incidents the SOC has to handle.
- What is the difference between an MSP and an MSSP?
- An MSP manages IT — devices, infrastructure, helpdesk — with security as one part. An MSSP focuses on security operations: monitoring, detection, response. Many organisations have an MSP and assume security is covered because it appears on the invoice. It is worth checking what is actually being monitored and who responds when something fires at 2am.
- Can you work alongside our existing IT provider?
- Yes, and that is the common arrangement. We handle security operations while your MSP continues managing IT, with clear boundaries about who does what during an incident agreed up front rather than negotiated mid-incident.
- Do we have to replace our existing security tools?
- No. We review what you have first and reuse what works — including third-party log ingestion, so existing tooling can feed the service. Replacing a control that works to fit a package is rarely in your interest, and we would rather say that than sell a migration.
- How quickly does the service become useful?
- Deployment is fast; genuine usefulness follows the tuning and baseline period, typically a few weeks. Alerting configured before we know what normal looks like in your environment produces noise, and noise is how real alerts get missed.
Ready to hand the running of it over?
Tell us what you are trying to cover and we will tell you honestly which of these you need, and which you do not.