Questions worth asking
a security partner
Straight answers to what buyers actually ask us — about how we operate, what we claim, and how we handle your data. If yours isn't here, just ask.
What exactly is an MSSP and a SOC?
A Managed Security Service Provider (MSSP) runs security for you as an outside team. The heart of it is a Security Operations Center (SOC): the people and tooling that watch your environment continuously, decide what's a real threat, and act on it. Cyber Pattern is an MSSP whose SOC runs 24/7, human-led, on a Wazuh-powered platform.
How fast do you respond when something happens?
When an alert fires, our median time to acknowledge and begin triage is under 15 minutes — and for confirmed incidents, containment moves in minutes, not days. We share that as an honest capability figure from how we operate, not a one-size contractual SLA; the specific commitments are agreed per engagement.
Do you work with teams our size?
Almost certainly. We exist precisely for growing organisations that have real security stakes but can't justify their own 24/7 team. We scope coverage to your size and risk rather than pushing an enterprise package you don't need.
What tools and platforms do you run on?
Our SOC is built on a Wazuh-powered SIEM — open and tuned per client — and our managed edge is built on Cloudflare (WAF, DDoS mitigation, TLS). Detections are mapped to MITRE ATT&CK. See Trust & Security for detail.
Are you SOC 2 or ISO 27001 certified?
We align our practices to SOC 2 and ISO/IEC 27001, and our Audit & Compliance service helps clients get and stay audit-ready against them. Where a specific certification or attestation matters for your procurement, ask us and we'll tell you exactly where we stand — we don't claim badges we haven't earned.
Where is our data handled, and is it confidential?
Confidentiality is the core of the job. We work on least-privilege access, collect only the telemetry needed to defend you, and never trade on or disclose what we learn about your environment. We won't even name you as a client without your explicit agreement.
How does the free assessment work?
It's a no-obligation 30-minute conversation and review of your exposure. We'll tell you honestly where a pattern is already forming and what we'd prioritise. No hard sell, and you keep the takeaways whether or not you work with us.
Can you work alongside our existing IT or security team?
Yes — that's the normal case. We augment and coordinate with your people rather than replacing them, handling the 24/7 watch and the specialist work while your team stays in control of the environment.
How is pricing structured?
Engagements are scoped to what you actually need — the services in play, the size of your environment, and the level of coverage. We'd rather quote something honest than list a headline price that hides the real cost. Tell us your situation and we'll be straight with you.
See your risk clearly.
Book a free 30-minute assessment. We'll review your exposure and show you where a pattern is already forming. No obligation.