Guardian
Everything your business needs. Flat rate. No surprises.
One plan that covers managed IT, cybersecurity, backup, and strategic guidance. Built so our incentives match yours — we make money keeping your systems running, not fixing what broke.

What's inside
Guardian is organized around three jobs: protect your business, keep it running, and help it move forward.
Protect
- AI-powered EDR on every endpoint
- 24/7 monitoring + Managed Detection & Response
- Email security, anti-phishing & archiving
- Automated daily cloud backup
- Zero-trust access controls
- Security awareness training
Run
- Unlimited remote help desk support
- Under-1-hour response on critical issues
- Automated patching for OS and key apps
- Microsoft 365 administration
- Asset & license tracking
- Always-current IT documentation
Advance
- Annual technology business review
- Multi-year technology roadmap
- Cyber insurance readiness review
- Budget planning & forecasting
- Vendor management
- AI & automation guidance
Pick your tier
One framework. Three ways to deploy it.
Guardian scales with your business. Start where you are today — move up when your risk profile, regulatory environment, or internal team changes.
For businesses without internal IT
Guardian Fundamentals
"Your IT department — fully managed, fully accountable."
Best for: Small and midsize businesses (roughly 1–50 users) with no internal IT staff who want one partner to run the whole stack.
What you get
- Managed endpoints, users, devices, and Microsoft 365
- Patch and update management across OS and approved apps
- Managed EDR, backup, and recovery on endpoints and M365 data
- Network monitoring and business-hours support
- User onboarding and offboarding handled end-to-end
- Annual technology business review
Typical client
A 25-person professional services or light-manufacturing business whose "IT guy" is the office manager. They want patching, backup, security, and a help desk — without hiring anyone.
Custom-scoped — pricing per Statement of Work.
M365 E5 · SIEM · Air-gapped backup
Guardian Compliance
"Microsoft 365 E5, SIEM-monitored logging, air-gapped backups, and quarterly executive security reviews."
Best for: Regulated and insured organizations that need documented governance, monitored compliance logging, and tested backups — not just good IT.
What you get
- Everything in Fundamentals, plus:
- Microsoft 365 E5 — full enterprise security and compliance suite
- Continuous compliance logging with SIEM monitoring
- Monthly air-gapped server backups, tested and verified
- Quarterly vCIO executive security reviews
- CIS IG3 mapped to HIPAA, PCI-DSS, SOX, CMMC, NIST
- Annual written and exercised incident response plan
Typical client
A 40-person legal practice, medical-adjacent firm, or financial services group facing HIPAA, GLBA, FTC Safeguards, CMMC, or a cyber insurance renewal with real security questions on the application.
Custom-scoped — pricing per Statement of Work.
For businesses with internal IT
Guardian Co-Managed
"Enterprise-grade security for teams that already have IT."
Best for: Organizations with qualified internal IT staff (IT Director or equivalent) who want PTS-grade security tooling, governance, and tier 2/3 escalation support alongside their own team.
What you get
- Security monitoring and alerting (SIEM-lite or full SIEM)
- Managed EDR across all endpoints
- Tier 2/3 engineering escalation
- Firewall management and patch coordination with internal IT
- Monthly security posture reviews with your IT lead
- Quarterly strategic planning and governance review
- Optional vCISO services per SOW
Typical client
A 120-person manufacturer or distributor with one internal IT director and a helpdesk tech. They handle day-to-day — we own the security stack, the SOC relationship, and the quarterly governance.
Custom-scoped — pricing per Statement of Work.
Not sure where you fit?
We'll scope it with you in a free 30-minute assessment — no pressure, no quote pushed before we understand your environment.
Book a 30-minute assessmentGuardian grows with you
Fundamentals
(outsourced IT)
Compliance
(E5 + SIEM + governance)
Co-Managed
(internal IT + us)
Start where you are. We'll tell you when it's time to move up.
Guardian Fundamentals — proof of work
What you receive each year
Fundamentals runs on an annual vCIO cadence. Once a year, your leadership team gets a clear, written record of where your IT stands and what's coming next.
Annual Technology Business Review
A written annual review of your environment, roadmap, and budget — covering what changed in the last 12 months and what's planned for the next 12.
Cyber insurance posture summary
A written summary of how your environment maps to your cyber insurance policy's control requirements — so renewal questionnaires answer themselves.
Multi-year technology roadmap
A documented roadmap covering planned upgrades, license renewals, hardware refreshes, and security improvements over the next 24–36 months.
Always-current IT documentation
A continuously maintained record of your environment — assets, licenses, network diagrams, accounts, and vendor contacts. Fully owned by you.
Need a faster strategic cadence and audit-ready quarterly deliverables? That's what Guardian Compliance is built for — see below.
Guardian Compliance — proof of work
What you receive every quarter
Compliance isn't a feeling — it's a paper trail. Every 90 days, your leadership team gets the documents auditors, regulators, and cyber insurers actually ask for.
Risk register update
A current view of every tracked risk in your environment — what changed, what closed, what's newly identified, and where you stand against your framework.
Control gap analysis
A written gap report against CIS IG3 mapped to your framework (HIPAA, PCI-DSS, SOX, CMMC, NIST), with prioritized remediation recommendations.
Compliance calendar review
Upcoming audits, policy reviews, training cycles, attestations, and renewal deadlines for the next two quarters — so nothing slips through the cracks.
SIEM and incident summary
A summary of compliance-relevant events captured by SOC monitoring, incidents investigated, and the supporting documentation auditors expect to see.
Backup verification report
Evidence that your monthly air-gapped server backups were performed, restored, and verified by PhantomTS staff — with dates, results, and tester sign-off.
vCIO executive briefing
A written executive briefing covering posture, prioritized recommendations, budget impacts, and decisions needed from leadership before the next review.
Plus an annual written and exercised incident response plan, an annual cyber insurance policy review, and a 5-year IT budget and device lifecycle plan.
See the full Guardian Compliance stackGuardian vs. a typical MSP
The full comparison. No fine print, no asterisks.
Response time SLA
Guardian
Typical MSP
24/7 monitoring + MDR
Guardian
Typical MSP
Endpoint security (EDR)
Guardian
Typical MSP
Patch management
Guardian
Typical MSP
Backup & recovery
Guardian
Typical MSP
Email security & archiving
Guardian
Typical MSP
Cyber insurance readiness
Guardian
Typical MSP
Strategic vCIO / roadmap
Guardian
Typical MSP
IT documentation
Guardian
Typical MSP
Pricing model
Guardian
Typical MSP
What you can count on
Response on critical issues
Monitoring & MDR
Per-user rate
Surprise bills
Looking for home or family IT support?
Guardian Residential brings the same proactive monitoring, security, and same-team support to your home network. Built for executives, remote workers, and families who want the security posture they have at work — at home too.
Common questions
How is this different from block-hour or hourly MSPs?
Block-hour pricing rewards your provider when things break. Guardian is a flat monthly rate, so we make money by keeping your systems running — our incentives are aligned with yours.
What size business is Guardian for?
Guardian scales across the full SMB range. Guardian Fundamentals is built for 1–50 users. Guardian Compliance is built for 25–150 users in regulated industries. Guardian Co-Managed supports teams with an existing IT person or department, typically 50–250+ users. If you're a team of 1 or a team of 200, there's a tier built for you.
Do you handle Microsoft 365 licensing?
Yes. We can procure and administer your Microsoft 365 licenses, manage Entra (formerly Azure AD), and handle tenant security — all included in Guardian.
What's included in the Microsoft 365 E5 license at the Compliance tier?
Guardian Compliance upgrades your Microsoft 365 to E5 — the full enterprise security and compliance suite. That includes Defender for Endpoint, Defender for Office 365 Plan 2, Defender for Identity, and Defender for Cloud Apps for threat protection; Purview Information Protection, Data Loss Prevention, and Message Encryption for data governance; Insider Risk Management, Communication Compliance, and eDiscovery (Premium) for regulatory workflows; plus Entra ID P2 with risk-based conditional access. These are full licenses, not add-ons or trials.
What does SIEM monitoring actually cover?
At the Compliance tier, our SOC ingests logs from your endpoints, servers, Microsoft 365 tenant, identity provider, firewalls, and network gear into a SIEM platform monitored 24/7. Compliance-relevant events — failed logins at scale, privilege escalation, data exfiltration patterns, policy violations — are correlated, investigated, and documented. You get the audit trail regulators and cyber insurers expect, and we get to incidents before they become breaches.
How often are the air-gapped backups tested?
Every month. At the Compliance tier, your servers receive image-based cloud backup continuously, plus a monthly air-gapped backup that's physically disconnected from your network. PhantomTS staff perform a test restore from that air-gapped copy every month and document the result — date, files restored, integrity check, and tester sign-off. You also receive a physical local-backup kit with three rotating 2TB external drives. Untested backups are not backups.
What do I actually get out of a quarterly executive security review?
A written executive briefing every 90 days covering: a current risk register update, a control gap analysis against your framework, a compliance calendar for the next two quarters, a SIEM and incident summary, a backup verification report, and prioritized recommendations with budget impact. Your leadership team walks out with the documentation auditors ask for and a clear list of decisions to make before the next review — same cadence a Fortune 500 security team runs internally, scaled for a regulated SMB.
What if we already have cyber insurance?
Even better. We'll review your policy's control requirements and make sure your environment can answer 'yes' to every question on the renewal questionnaire.
How fast can you onboard us?
Most clients are fully onboarded within 2–4 weeks, depending on environment size. Critical security controls are deployed in the first week.
Ready to see what it would cost?
Free assessment. Plain-English recommendations. No pressure, no jargon.
Schedule Free Assessment