Damocles managed-defence service

Put analysts, investigation and accountable response behind the security technology.

Aegis combines compatible monitoring and protection sources with Damocles source-health review, alert triage, investigation, escalation, action tracking and service reporting.

Australian data residency

Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.

Source-health monitoringAlert triage and investigationCustomer escalationGuardian actions and reporting
Buyer decision summary

Know what Aegis Managed Defence does, what the customer sees and what Damocles is responsible for before activation.

Guardian retains supported source state, alert and investigation lifecycle, timestamps, disposition, linked assets or users, evidence references, escalation, customer action and review history.

The proposal identifies covered endpoints, users, sources, collectors, ingestion, retention, coverage hours, triage, investigation, escalation, reporting, incident-response boundary and the selected compatible platforms.

Aegis does not guarantee detection or prevention of every malicious event and does not imply unlimited sources, ingestion, retention, investigation, incident response or remediation.

01

What the product does

The selected service tier defines coverage hours, included sources, investigation depth, escalation and reporting.

02

What the customer sees

The analyst console can vary; the Guardian customer experience remains stable.

03

What Damocles manages

Business-hours, extended-hours and 24×7 options remain distinct where supported and contracted.

The operational problem

Security technology produces signals. Customers buy managed defence because someone still has to decide what matters and drive the response.

A security platform can collect events and raise alerts, but a useful service must also know whether the expected sources are reporting, whether the alert belongs to the customer, what evidence supports the conclusion, who must respond and whether the required action was completed.

Aegis is the Damocles operating service. It can work with supported customer, provider or Damocles-selected technologies while Guardian keeps the customer view, investigation, escalation, risk, actions and reporting consistent.

01

Know the service is functioning

Monitor expected agents, collectors, integrations and log sources so silence is not mistaken for security.

02

Separate noise from material activity

Use approved rules, asset, identity, vulnerability and customer context to prioritise alerts.

03

Escalate a clear required response

Tell the customer or provider what happened, what evidence supports it and what must happen next.

Product capability

The managed operational work delivered by Aegis.

The selected service tier defines coverage hours, included sources, investigation depth, escalation and reporting.

SH

Source-health monitoring

Track expected agents, collectors, APIs and log sources and identify stale, zero-data, degraded and unavailable states.

AT

Alert triage

Review, prioritise, enrich and suppress avoidable noise using approved logic and customer context.

IV

Investigation

Assess material activity, collect authorised evidence and record customer-scoped conclusions and disposition.

ES

Escalation

Use agreed severity, contacts, channels and response paths when customer, MSP or Damocles action is required.

AC

Action tracking

Link required containment, remediation, policy or customer work to Guardian risks and All Actions.

RP

Service reporting

Report monitored scope, source health, alerts, investigations, escalations, actions and unresolved gaps.

What the customer sees

Customers see what was monitored, investigated and left open.

The analyst console can vary; the Guardian customer experience remains stable.

OV

Operations overview

Current source health, alerts, investigations, vulnerability context, escalations and open actions.

ID

Investigation detail

Customer-readable summary, timeline, evidence, disposition, affected scope and required response.

LH

Log-source health

Expected sources, last-seen state, zero-data and unavailable conditions with ownership and follow-up.

AL

Alert history

Normalised severity, source, status, priority, linked investigation and customer action.

SR

Service review

Coverage, tuning, source gaps, investigations, response quality and unresolved customer decisions.

PV

Provider view

Authorised customer operations, escalation and reporting for MSPs with clearly defined first-line responsibilities.

What Damocles manages

Damocles operates the service according to the contracted coverage and response model.

Business-hours, extended-hours and 24×7 options remain distinct where supported and contracted.

ON

Service onboarding

Confirm source inventory, customer mappings, contacts, priorities, response authority and expected evidence.

BL

Baseline and tuning

Establish expected source health, common activity, asset context and approved detection or suppression logic.

MO

Managed monitoring

Review source state and incoming security activity during the contracted coverage window.

IN

Managed investigation

Gather authorised context, determine likely significance and document the customer-facing conclusion.

ER

Escalation and response coordination

Invoke the agreed customer, MSP, incident or emergency pathway when action is required.

SI

Service improvement

Review quality, false positives, source gaps, customer delays and approved tuning opportunities.

Operating lifecycle

From connected source to triaged alert, investigation, escalation and reviewed outcome.

Aegis can operate compatible security technologies while preserving one Guardian operating model.

01

Onboard

Confirm products, sources, customer scope, contacts, severity model, escalation and response authority.

02

Baseline

Establish expected source state, common activity, assets, identities and service context.

03

Monitor and triage

Review source health and prioritise security signals during the coverage window.

04

Investigate

Gather authorised evidence, correlate context and record disposition and confidence.

05

Escalate and act

Contact the agreed party and create the required action, risk or incident pathway.

06

Review and improve

Track closure, customer response, tuning, source health and service reporting.

Common use cases

Common Aegis managed-defence models.

The operating responsibility can be adapted for direct customers and external MSP relationships.

BH

Business-hours managed defence

Provide managed source health, triage, investigation and escalation during an agreed business-hours window.

24

24×7 managed defence

Provide continuous contracted monitoring and escalation where the source, staffing and response model support it.

MS

MSP escalation service

Allow the MSP to retain first-line customer communication while Damocles provides agreed security-operation escalation.

HY

Hybrid technology estate

Operate supported sources from different compatible platforms while keeping the customer workflow consistent.

VR

Vulnerability-informed triage

Use supported asset and vulnerability context to improve investigation priority and remediation.

IR

Incident-readiness integration

Use the agreed incident contacts, playbooks and response authority when an investigation crosses the escalation threshold.

Operating model

How Aegis Managed Defence is onboarded, integrated, evidenced and scoped commercially.

These details remain explicit before activation, but are grouped into one operating view so buyers can review the responsibilities without working through four separate page sections.

ON

Onboarding and implementation

Aegis onboarding defines the sources, coverage, people and response authority before monitoring begins. Damocles confirms customer and provider relationships, expected agents and sources, selected compatible platform, asset and identity context, coverage hours, contacts, severity model, investigation depth, escalation channels, response authority and reporting. The onboarding period validates source ownership, source health, sample alerts, field quality, customer-safe evidence, disposition, action linkage and handoff between the customer, MSP and Damocles. Go-live requires a documented runbook, source register, escalation matrix, service schedule, reporting cadence, customer responsibilities and a process for source failure, major change and incident-response activation.

IN

Connector and integration model

Aegis is independent of one vendor platform and can operate supported compatible connectors. The selected security technology remains responsible for collection, platform processing and source-specific functionality. Guardian connectors provide explicit customer mapping, source health, supported alert or investigation data and safe failure state. The public product is Aegis Managed Defence. The proposal identifies the selected platform or connectors, licensing, ingestion, retention, source types and support. This allows a customer to retain suitable existing technology or migrate later without changing the managed-service concept. New connector requests are assessed for API maturity, customer isolation, event and investigation quality, source health, evidence, volume, retention, supportability and engineering effort before being added to a service schedule.

EV

Data, evidence and reporting

Aegis retains a customer-readable operational record while protecting analyst and platform-sensitive information. Guardian retains supported source state, alert and investigation lifecycle, timestamps, disposition, linked assets or users, evidence references, escalation, customer action and review history. Credentials, raw upstream payloads, unrelated customer records, sensitive detection logic and analyst-only notes remain restricted. Customer reports include enough evidence and context to explain the result without exposing unsafe detail. A failed connector or stale source remains visible in source-health reporting. The absence of alerts is not represented as evidence of a healthy monitoring service when expected data is missing.

CM

Commercial unit and responsibilities

Commercial scope separates the technology, connector, capacity and managed analyst service. The proposal identifies covered endpoints, users, sources, collectors, ingestion, retention, coverage hours, triage, investigation, escalation, reporting, incident-response boundary and the selected compatible platforms. Aegis does not automatically include unlimited source onboarding, rule engineering, 24×7 response, forensics, containment, recovery or remediation engineering. Those responsibilities must be expressly listed. The customer or MSP owns timely access, source deployment, response authority and remediation assigned to them. Damocles owns the Aegis activities stated in the service schedule.

Frequently asked questions

Questions buyers ask about Aegis Managed Defence.

The exact answer is confirmed in the proposal and package schedule, but these points should be understood before activation.

Q1

Can Aegis work with our existing tools?

Yes where supported connectors exist and the technology provides the source health, alerts and investigation context required.

Q2

Is 24×7 included?

Only in a contracted 24×7 service tier with the required source, staffing, escalation and response model.

Q3

Can our MSP stay first-line?

Yes. The MSP and Damocles responsibilities, customer communication and escalation are defined before onboarding.

Q4

Does Aegis include incident response?

Monitoring and escalation do not automatically include unlimited containment, forensics or recovery. Incident services are separately defined.

Q5

How are false positives handled?

Analysts record disposition and approved tuning opportunities. Material detection or suppression changes follow the agreed change process.

Q6

What if a source fails?

Guardian shows the source-health gap and Damocles follows the contracted operational process rather than treating the service as healthy.

Scope and boundaries

Aegis coverage follows the contracted sources, hours, investigation and response responsibilities.

Aegis does not guarantee detection or prevention of every malicious event and does not imply unlimited sources, ingestion, retention, investigation, incident response or remediation.

Unsupported sources, incomplete customer authority, unavailable evidence and unlicensed technology features remain explicit limitations.

Customer, MSP and Damocles responsibilities are recorded before service activation and reviewed when the technology or operating model changes.

Take the next practical step

Review the security signals and response responsibilities your current team cannot reliably operate.

We will map the sources, compatible technology, coverage window, analyst duties, escalation, incident boundary and Guardian customer experience.