Pulse · Managed Detection & Response

Your tools provide the signal.
Our analysts do the rest.

Pulse is 24/7 security operations that fit the way you work. We connect to the stack you already own, watch everything it produces, and handle detection through containment for you.

Book a demo View packages
Touchpoint Security · Pulse · INC-0054
Touchpoint Pulse
Incidents Trace Signal Attest
Charlotte · Meridian Group
INC-0054 MISCONFIGURATION · OPEN_PORT HIGH
FTP exposed to the internet
Analyst: James Carter · Touchpoint SLA: 1h 42m to respond · first response in 6 min
TRACE DETECTION · 14:22 UTC
Port 21 / FTP open on web-prod-01 — port open to 185.220.101.47
JC
James CarterTOUCHPOINT14:28 UTC
Trace flagged FTP port 21 open on web-prod-01. Can you confirm if this is intentional? FTP sends credentials in plaintext — credential-intercept risk even with a password.
CH
CharlotteMERIDIAN GROUP14:47 UTC
Yes — FTP is our hosting platform, for deployment uploads only. Only our deployment team has credentials. Is the open port itself the problem?
JC
James CarterTOUCHPOINT15:02 UTC
Yes — credentials don't protect against plaintext sniffing. Two options:
① Migrate to SFTP — encrypted, same workflow
② IP allowlist port 21 — restrict while you plan migration
What you actually get

Security outcomes without the overhaul

Works with what you have We connect to your existing stack in days, then correlate threats across endpoint, identity, cloud, network and SaaS.
No black boxes, ever You work in the same console as our analysts. Every investigation, every response, in real time, with our reasoning attached.
SLAs we put in writing 15-minute acknowledge and 60-minute containment for critical incidents, backed by named analysts who know your environment.
How we do it

Five steps, on repeat, around the clock

STEP 1 · CONNECT
Up and running with your own tech No agents to rip out, nothing to replace. Pulse plugs into your existing security stack and starts pulling telemetry the same week.
STEP 2 · DETECT
One incident, not fifty alerts Detections correlate across your whole estate, so related signals collapse into a single incident with the full story attached.
STEP 3 · INVESTIGATE
Automation gathers, analysts decide Our platform assembles evidence and context in seconds. A named analyst makes the judgment call, and you can read their working.
STEP 4 · RESPOND
Contained, not just flagged We isolate hosts, disable accounts and block indicators on your behalf, within the actions you pre-approve, with a full audit trail.
STEP 5 · IMPROVE
Security that gets stronger every month Every incident sharpens detections. Trace tracks every exposure we find until it’s closed, by your team or our engineers, and Attest turns the evidence into audit-ready proof.
Pulse in detail

Everything included in the service

01 · 24/7 SOC monitoring

Analysts watching every hour of every day

A staffed security operations centre monitors telemetry from your endpoints, identities, cloud, email and network. Every alert is triaged by a person, not just a rule.

  • ✓Coverage across EDR, identity, cloud, email and SaaS
  • ✓Detections mapped to MITRE ATT&CK and tuned to your environment
  • ✓Related alerts correlated into a single incident
  • ✓Proactive threat hunts after major new campaigns
02 · Investigation & containment

Contained, not just flagged

When an alert is real, our analysts investigate it end to end and take action in your environment within the permissions you agree at onboarding.

See what we do without calling you →
  • ✓Host isolation, session revocation and account lockout
  • ✓Malicious hashes, domains and IPs blocked
  • ✓Root cause and scope confirmed before we close
  • ✓Full audit trail of every action taken
03 · Signal threat intel

Intelligence matched to what you actually run

Signal filters vulnerability disclosures and threat campaigns to the operating systems, hardware, software and packages in your estate, so you only hear about what affects you.

See recent advisories →
  • ✓Stack-matched advisories, not generic feeds
  • ✓Clear actions and patch versions with every advisory
  • ✓Emerging threats trigger targeted hunts in Pulse
  • ✓Weekly digest plus urgent alerts for critical issues
04 · Shared incident workspace

One place for you and our analysts

Every incident lives in a workspace you share with the analyst handling it: timeline, evidence, actions and conversation, visible in real time.

  • ✓Same console and evidence our analysts use
  • ✓Message the analyst on your incident directly
  • ✓Approve or decline response actions in one click
  • ✓Exportable incident reports for insurers and auditors
Response authority

What we do without calling you, and what we don't

You agree these actions at onboarding and they go into your contract, not a sales deck. Change them any time in the console.

We act immediately Then tell you what we did and why
  • Isolate a compromised endpoint
  • Revoke active sessions and tokens
  • Force a password reset
  • Block a malicious hash, domain or IP
  • Quarantine a phishing email tenant-wide
We act, unless you object within 15 minutes For accounts and systems you mark as sensitive
  • Disable a privileged or executive account
  • Isolate a server
  • Disable a mailbox rule or OAuth app
  • Block a sign-in location
Only with your approval We recommend, you decide
  • Take a production system offline
  • Change firewall or network rules
  • Contact law enforcement, insurers or regulators
A worked example

02:07, Saturday. A stolen password. Contained by 02:41.

An illustrative account-takeover incident, showing what happens and when you hear about it.

  1. 02:07Detect. Entra ID flags a sign-in for the finance director from a new country, followed by a new mailbox forwarding rule.
  2. 02:11Acknowledge. The analyst on shift picks it up. Pulse has already correlated both signals into one incident.
  3. 02:19Contain. Sessions revoked and the forwarding rule removed without asking you (pre-approved). The account is marked sensitive, so we give you 15 minutes to object before disabling it.
  4. 02:22Call. Your on-call contact gets a phone call, not an email: what happened, what we've done, and the one thing we need from you.
  5. 02:41Scope. Mailbox audit confirms no data left the tenant. The account is disabled and a reset is issued.
  6. Mon 09:00Improve. A written summary lands in your workspace, with the root cause (no phishing-resistant MFA) raised as a Trace finding.
Onboarding

Watching in a week, tuned in a month

Day 1Kick-offAgree scope, contacts, escalation paths and response authority.From you: 1 hour, an admin contact
Days 2–7ConnectAPI connections to your EDR, identity, cloud and email. 24/7 monitoring starts the moment data flows.From you: read-only and response API access
Days 8–30TuneWe learn what normal looks like, cut the noise, and run your first Trace Exposure scan and Attest baseline.From you: a weekly 30-min check-in
Day 30First reportYour first monthly report and a review of what we found, what we contained and what's next.See a sample report →
Included with Pulse

Real security operations, not alert forwarding

24/7 SOC monitoring Real-time triage and investigation around the clock, every day of the year.
Executed response Containment actions carried out for you, not a ticket telling you to do it yourself.
Exposure management Trace maps your attack surface and tracks every vulnerability to remediation.
Threat intelligence Signal filters advisories to the OSes, hardware, software and packages you actually run.
Compliance evidence Attest runs framework assessments on live platform data, exportable for audit.
Metrics and reporting Monthly reports your board can read, with the numbers behind every claim.
Threat hunting Hypothesis-led hunts across your telemetry to find what automation missed.
Strategic guidance Quarterly reviews, resilience recommendations and honest advice on reducing risk.
Related reading
MDR vs MSSP vs SOC-as-a-service How much does MDR cost?

See Pulse before you buy it

Watch how we find and contain a threat, in the actual console. No sales pitch, just the real thing.

Book a demo