Managed Security Services (MSSP)

Our SOC. In Canada. Awake.

An MSSP, managed security services provider, runs your security monitoring and response for you. happier IT does this from its own security operations centre in Canada, staffed by our own employees rather than a subcontracted platform. That single fact is the main thing that separates this service from most of the market.

Who it's for

This is for organizations that have the tools and still are not covered.

Buying security software is the easy half. The half that protects you is someone competent looking at what it says, at an inconvenient hour.

You already own the licences. Endpoint protection, Microsoft 365 security features, a firewall with logging. Nobody reads the output. This is extremely common and almost never anybody's fault, it takes a rota, not a person.

You have one IT person, or a small team. They cannot be on call permanently, and asking them to be is how you lose them.

A client or an insurer wants continuous monitoring. Increasingly a written requirement rather than a nice-to-have, and "we have antivirus" no longer answers it.

You want to know where your data is. Some organizations, public sector, healthcare, legal, anyone with a Canadian residency requirement, need to be able to say where the monitoring happens and who sees it.

The question to ask every MSSP

"Who is actually watching, are they your employees, and where do they sit?"

A large part of this market resells a monitoring platform and outsources the watching. That is not disgraceful, but it changes what you are buying, and it is rarely volunteered.

What's included

What the SOC does.

A security operations centre is a rota, a severity scale, a defined action for each kind of alert, and a way to reach you at 3am. Here is ours.

  • Continuous monitoring

    Endpoints, servers, identity and cloud sign-in activity, network and firewall logs, and Microsoft 365 audit data, collected centrally and correlated rather than watched in six separate consoles.

  • Human triage

    Analysts decide which alerts matter. The overwhelming majority of security alerts are noise; the value of a SOC is a person separating the two so your team never sees the noise.

  • Containment, not just notification

    Isolating a compromised device, disabling an account, blocking a sender. We agree in advance what we are authorised to do without waking you, and what always needs a call.

  • Incident response, run to a written process

    Identify, contain, remove, restore, report. You see that process before you need it, not during.

  • Threat intelligence applied to you

    What is actually being used against Canadian organizations of your size and sector, turned into detection rules, rather than a monthly newsletter.

  • Reporting you can hand to a board or an insurer

    What was seen, what was acted on, what changed, and what we recommend next. Written to be read by a non-technical reader.

  • A named escalation path

    Real names, in order, with the hours each is reachable. Both directions, ours to you, and yours to us.

  • Quarterly review of what is being watched

    Coverage drifts as you add systems. Once a quarter we check that what we monitor still matches what you run.

How it works

Onboarding takes about three weeks.

Most of it is connecting data sources and tuning out noise. Rushing that step is how you end up ignoring your own alerts.

  1. Week 1, connect and baseline

    We connect the log sources: identity, endpoints, email, cloud, network. Then we watch quietly to learn what normal looks like in your environment, because an alert only means something relative to normal.

  2. Week 2–3, tune and agree the rules

    We cut the false positives, set the severity scale, and agree in writing what we may act on unilaterally and what always warrants a phone call. You approve that document.

  3. Ongoing: watch, act, report

    Continuous monitoring with human triage, containment inside the agreed authority, and a report you can actually read. Reviewed with you every quarter.

What it costs

Priced per user and per monitored system.

Security monitoring priced per alert or per gigabyte creates a bad incentive: it punishes you for having visibility. We do not price it that way.

happier IT's managed security is priced on the number of people and the number of monitored systems, as a fixed monthly fee.

What moves it:

  • How many log sources. Identity and endpoints are the baseline. Firewalls, servers and line-of-business systems add coverage and cost.
  • Your response authority. Letting us contain automatically is cheaper and faster than routing everything through an approval.
  • Reporting and evidence obligations. Regulated sectors need more of both.

It is materially cheaper bundled with managed IT, because the same team already knows your environment.

What "24/7" should mean

Ask any provider, including us, to state staffed hours rather than monitoring hours. Software runs continuously almost everywhere. People do not.

happier IT's staffed hours: 24/7, with the Surrey office on Monday to Friday, 8:00 am to 5:00 pm Pacific.

Go deeper

Specialisms under this service

Each of these is a distinct piece of work with its own page. Most clients need some of them, not all of them.

SOC as a Service

Our people. Our building.

A security operations centre in Canada, staffed by happier IT employees rather than resold. Monitoring, triage and containment for teams of 15 to 200.

Managed EDR

The detection, plus the person.

Endpoint detection and response, watched and acted on by happier IT’s own Canadian security team. For organizations of 15 to 200 people in Alberta, BC and Ontario.

XDR as a Service

Six consoles, one story.

Extended detection and response: endpoint, identity, email, cloud and network signals joined into one timeline, watched by our Canadian security team.

SASE

Security that travels.

Secure access service edge: filtering, access control and zero trust delivered from the cloud, so remote staff get the same protection as head office does.

Email Security

A quieter, safer inbox.

Filtering configured properly, SPF, DKIM and DMARC published, and a Canadian security team who can pull a bad message out of every mailbox it reached after delivery.

Firewall Management

Rules someone still understands.

happier IT owns the configuration, firmware, rules and logs on your firewalls, including removing the rule added for a project that finished four years ago.

Patch Management

Boring, on a schedule.

Operating systems, applications, servers and firmware updated on a tested schedule, with failures chased and a compliance number you can show an insurer.

Password Management

Stop reusing the good one.

A private vault for every person, proper shared vaults for teams, and the rollout work that gets people using them, plus monitoring for leaked credentials.

Security Staff Augmentation

A named person, not a queue.

A named happier IT security specialist working inside your team for an agreed period, your tickets, your tools, your priorities, with our team behind them.

Incident Response & Digital Forensics

A number to call, and a plan.

The plan agreed in daylight, the number to call, and the forensic work that establishes what actually happened. Retainers and engagements for AB, BC and Ontario.

Why us for this

Ours is in Canada, and the analysts are our employees.

This is the part of happier IT that is genuinely hard for a competitor of our size to copy, and on the old website it was buried on one page. It belongs at the front.

Running your own security operations centre is expensive. It means employing enough analysts to cover a rota without burning them out, and keeping them current. The reason to do it rather than resell somebody else's is that the person who looks at your alert at 3am already knows your environment, can see your ticket history, and can phone you, instead of raising a case with a provider who raises a case with you.

Data stays in Canada. The security team holds Certified Ethical Hacker credentials, alongside our Microsoft, Cisco, VMware, CompTIA and Red Hat certifications. The full list is on our awards and certifications page.

Go deeper

Questions

What people ask before they sign anything.

What is the difference between an MSP and an MSSP?

An MSP, managed service provider, runs your IT: helpdesk, servers, networks, devices. An MSSP runs your security monitoring and response. Many providers do both, which is usually simpler, because the team answering your helpdesk already knows your environment. happier IT does both.

Do we need this if we already have endpoint protection?

Endpoint protection generates alerts. An MSSP is the part that reads them. If somebody in your organization genuinely reviews that console daily and knows what to do with what they find, you may not need us. In most organizations under 200 people, nobody does, and that is not a criticism, it is a staffing reality.

Can you work alongside our existing IT provider?

Yes. It is a common arrangement and it works as long as the boundaries are written down: who monitors, who fixes, who owns the machine during an incident. We will insist on agreeing that in advance, because it is the thing that goes wrong at the worst moment.

What happens during an actual incident?

We follow a defined sequence: identify what happened and how far it reached, contain it, remove it, restore what was affected, and report properly: to you, and where required to a regulator, insurer or client. You will have read that process before it is needed, and you will have a named person to call.

Will you wake me up?

Only for the severities where you told us to. That is agreed in writing during onboarding and reviewed quarterly. Waking a client for something we were authorised to handle ourselves is a failure of the design, not diligence.

Is my data stored in Canada?

Yes, for the monitoring we run. Where a third-party product in your environment stores data elsewhere, we will name it rather than implying we control it.

How long is the commitment?

Long enough to be worth doing, tuning takes a few weeks and the value compounds after that, but we are not going to state a term here that we have not confirmed. Our standard agreement runs twelve months and then continues month to month, with sixty days’ notice either way.

Related

Want to know what this would look like for you?

A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.