Guardian

    Everything your business needs. Flat rate. No surprises.

    One plan that covers managed IT, cybersecurity, backup, and strategic guidance. Built so our incentives match yours — we make money keeping your systems running, not fixing what broke.

    PhantomTS advisor walking a leadership team through Guardian tier comparisons in a boardroom

    What's inside

    Guardian is organized around three jobs: protect your business, keep it running, and help it move forward.

    Protect

    • AI-powered EDR on every endpoint
    • 24/7 monitoring + Managed Detection & Response
    • Email security, anti-phishing & archiving
    • Automated daily cloud backup
    • Zero-trust access controls
    • Security awareness training

    Run

    • Unlimited remote help desk support
    • Under-1-hour response on critical issues
    • Automated patching for OS and key apps
    • Microsoft 365 administration
    • Asset & license tracking
    • Always-current IT documentation

    Advance

    • Annual technology business review
    • Multi-year technology roadmap
    • Cyber insurance readiness review
    • Budget planning & forecasting
    • Vendor management
    • AI & automation guidance

    Pick your tier

    One framework. Three ways to deploy it.

    Guardian scales with your business. Start where you are today — move up when your risk profile, regulatory environment, or internal team changes.

    For businesses without internal IT

    Guardian Fundamentals

    "Your IT department — fully managed, fully accountable."

    Best for: Small and midsize businesses (roughly 1–50 users) with no internal IT staff who want one partner to run the whole stack.


    What you get

    • Managed endpoints, users, devices, and Microsoft 365
    • Patch and update management across OS and approved apps
    • Managed EDR, backup, and recovery on endpoints and M365 data
    • Network monitoring and business-hours support
    • User onboarding and offboarding handled end-to-end
    • Annual technology business review

    Typical client

    A 25-person professional services or light-manufacturing business whose "IT guy" is the office manager. They want patching, backup, security, and a help desk — without hiring anyone.

    Request Assessment

    Custom-scoped — pricing per Statement of Work.

    Most Popular

    M365 E5 · SIEM · Air-gapped backup

    Guardian Compliance

    "Microsoft 365 E5, SIEM-monitored logging, air-gapped backups, and quarterly executive security reviews."

    Microsoft 365 E524/7 SIEM MonitoringAir-Gapped BackupsQuarterly Executive Reviews

    Best for: Regulated and insured organizations that need documented governance, monitored compliance logging, and tested backups — not just good IT.


    What you get

    • Everything in Fundamentals, plus:
    • Microsoft 365 E5 — full enterprise security and compliance suite
    • Continuous compliance logging with SIEM monitoring
    • Monthly air-gapped server backups, tested and verified
    • Quarterly vCIO executive security reviews
    • CIS IG3 mapped to HIPAA, PCI-DSS, SOX, CMMC, NIST
    • Annual written and exercised incident response plan

    Typical client

    A 40-person legal practice, medical-adjacent firm, or financial services group facing HIPAA, GLBA, FTC Safeguards, CMMC, or a cyber insurance renewal with real security questions on the application.

    Request Assessment

    Custom-scoped — pricing per Statement of Work.

    For businesses with internal IT

    Guardian Co-Managed

    "Enterprise-grade security for teams that already have IT."

    Best for: Organizations with qualified internal IT staff (IT Director or equivalent) who want PTS-grade security tooling, governance, and tier 2/3 escalation support alongside their own team.


    What you get

    • Security monitoring and alerting (SIEM-lite or full SIEM)
    • Managed EDR across all endpoints
    • Tier 2/3 engineering escalation
    • Firewall management and patch coordination with internal IT
    • Monthly security posture reviews with your IT lead
    • Quarterly strategic planning and governance review
    • Optional vCISO services per SOW

    Typical client

    A 120-person manufacturer or distributor with one internal IT director and a helpdesk tech. They handle day-to-day — we own the security stack, the SOC relationship, and the quarterly governance.

    Request Assessment

    Custom-scoped — pricing per Statement of Work.

    Not sure where you fit?

    We'll scope it with you in a free 30-minute assessment — no pressure, no quote pushed before we understand your environment.

    Book a 30-minute assessment

    Guardian grows with you

    Fundamentals

    (outsourced IT)

    Compliance

    (E5 + SIEM + governance)

    Co-Managed

    (internal IT + us)

    Start where you are. We'll tell you when it's time to move up.

    Guardian Fundamentals — proof of work

    What you receive each year

    Fundamentals runs on an annual vCIO cadence. Once a year, your leadership team gets a clear, written record of where your IT stands and what's coming next.

    Annual Technology Business Review

    A written annual review of your environment, roadmap, and budget — covering what changed in the last 12 months and what's planned for the next 12.

    Cyber insurance posture summary

    A written summary of how your environment maps to your cyber insurance policy's control requirements — so renewal questionnaires answer themselves.

    Multi-year technology roadmap

    A documented roadmap covering planned upgrades, license renewals, hardware refreshes, and security improvements over the next 24–36 months.

    Always-current IT documentation

    A continuously maintained record of your environment — assets, licenses, network diagrams, accounts, and vendor contacts. Fully owned by you.

    Need a faster strategic cadence and audit-ready quarterly deliverables? That's what Guardian Compliance is built for — see below.

    Guardian Compliance — proof of work

    What you receive every quarter

    Compliance isn't a feeling — it's a paper trail. Every 90 days, your leadership team gets the documents auditors, regulators, and cyber insurers actually ask for.

    Risk register update

    A current view of every tracked risk in your environment — what changed, what closed, what's newly identified, and where you stand against your framework.

    Control gap analysis

    A written gap report against CIS IG3 mapped to your framework (HIPAA, PCI-DSS, SOX, CMMC, NIST), with prioritized remediation recommendations.

    Compliance calendar review

    Upcoming audits, policy reviews, training cycles, attestations, and renewal deadlines for the next two quarters — so nothing slips through the cracks.

    SIEM and incident summary

    A summary of compliance-relevant events captured by SOC monitoring, incidents investigated, and the supporting documentation auditors expect to see.

    Backup verification report

    Evidence that your monthly air-gapped server backups were performed, restored, and verified by PhantomTS staff — with dates, results, and tester sign-off.

    vCIO executive briefing

    A written executive briefing covering posture, prioritized recommendations, budget impacts, and decisions needed from leadership before the next review.

    Plus an annual written and exercised incident response plan, an annual cyber insurance policy review, and a 5-year IT budget and device lifecycle plan.

    See the full Guardian Compliance stack

    Guardian vs. a typical MSP

    The full comparison. No fine print, no asterisks.

    Response time SLA

    Guardian

    Under 1 hour

    Typical MSP

    Next business day

    24/7 monitoring + MDR

    Guardian

    Included

    Typical MSP

    Not included

    Endpoint security (EDR)

    Guardian

    AI-powered EDR + Zero-Trust

    Typical MSP

    Basic antivirus

    Patch management

    Guardian

    Automated, tested, scheduled

    Typical MSP

    Reactive

    Backup & recovery

    Guardian

    Automated daily cloud backup

    Typical MSP

    Optional or manual

    Email security & archiving

    Guardian

    Advanced filtering + archiving

    Typical MSP

    Provider defaults

    Cyber insurance readiness

    Guardian

    Fully audit-ready

    Typical MSP

    On your own

    Strategic vCIO / roadmap

    Guardian

    Annual technology business review

    Typical MSP

    None

    IT documentation

    Guardian

    Always current, fully owned by you

    Typical MSP

    None

    Pricing model

    Guardian

    Flat per-user / month

    Typical MSP

    Break-fix or hourly

    What you can count on

    <1 hour

    Response on critical issues

    24/7

    Monitoring & MDR

    Flat

    Per-user rate

    0

    Surprise bills

    Looking for home or family IT support?

    Guardian Residential brings the same proactive monitoring, security, and same-team support to your home network. Built for executives, remote workers, and families who want the security posture they have at work — at home too.

    Common questions

    How is this different from block-hour or hourly MSPs?

    Block-hour pricing rewards your provider when things break. Guardian is a flat monthly rate, so we make money by keeping your systems running — our incentives are aligned with yours.

    What size business is Guardian for?

    Guardian scales across the full SMB range. Guardian Fundamentals is built for 1–50 users. Guardian Compliance is built for 25–150 users in regulated industries. Guardian Co-Managed supports teams with an existing IT person or department, typically 50–250+ users. If you're a team of 1 or a team of 200, there's a tier built for you.

    Do you handle Microsoft 365 licensing?

    Yes. We can procure and administer your Microsoft 365 licenses, manage Entra (formerly Azure AD), and handle tenant security — all included in Guardian.

    What's included in the Microsoft 365 E5 license at the Compliance tier?

    Guardian Compliance upgrades your Microsoft 365 to E5 — the full enterprise security and compliance suite. That includes Defender for Endpoint, Defender for Office 365 Plan 2, Defender for Identity, and Defender for Cloud Apps for threat protection; Purview Information Protection, Data Loss Prevention, and Message Encryption for data governance; Insider Risk Management, Communication Compliance, and eDiscovery (Premium) for regulatory workflows; plus Entra ID P2 with risk-based conditional access. These are full licenses, not add-ons or trials.

    What does SIEM monitoring actually cover?

    At the Compliance tier, our SOC ingests logs from your endpoints, servers, Microsoft 365 tenant, identity provider, firewalls, and network gear into a SIEM platform monitored 24/7. Compliance-relevant events — failed logins at scale, privilege escalation, data exfiltration patterns, policy violations — are correlated, investigated, and documented. You get the audit trail regulators and cyber insurers expect, and we get to incidents before they become breaches.

    How often are the air-gapped backups tested?

    Every month. At the Compliance tier, your servers receive image-based cloud backup continuously, plus a monthly air-gapped backup that's physically disconnected from your network. PhantomTS staff perform a test restore from that air-gapped copy every month and document the result — date, files restored, integrity check, and tester sign-off. You also receive a physical local-backup kit with three rotating 2TB external drives. Untested backups are not backups.

    What do I actually get out of a quarterly executive security review?

    A written executive briefing every 90 days covering: a current risk register update, a control gap analysis against your framework, a compliance calendar for the next two quarters, a SIEM and incident summary, a backup verification report, and prioritized recommendations with budget impact. Your leadership team walks out with the documentation auditors ask for and a clear list of decisions to make before the next review — same cadence a Fortune 500 security team runs internally, scaled for a regulated SMB.

    What if we already have cyber insurance?

    Even better. We'll review your policy's control requirements and make sure your environment can answer 'yes' to every question on the renewal questionnaire.

    How fast can you onboard us?

    Most clients are fully onboarded within 2–4 weeks, depending on environment size. Critical security controls are deployed in the first week.

    Ready to see what it would cost?

    Free assessment. Plain-English recommendations. No pressure, no jargon.

    Schedule Free Assessment