Managed Security Services · Fortify
The managed security provider that is run by incident responders.
Fortify is IronSights' managed security services plan (MSSP) for Australian SMEs. It is designed by the team that handles ransomware and business email compromise incidents, to close the gaps we find on every one of them: remote access without MFA, unmonitored endpoints, mailboxes nobody watches, and backups the attacker can reach.
We are paid the way you would want us to be. If a Fortify client is breached, our responders handle it as part of the plan, with no hourly cap. The cheapest incident for us is the one that never happens, and we prove the work to your board, your insurer, and your clients every month.
Our approach
Fortify protects your environment.
We monitor your systems, respond to threats, and improve your security every month.
Security is not set once. It improves over time.
Monitor
Continuous detection across identities, endpoints, email, and cloud. Threats surface early, not after impact.
Respond
The same Australian responders who work and email compromise cases contain compromised accounts and devices, then explain what happened in plain language.
Educate
Targeted simulations and short-form training that lifts the human layer alongside the technical.
Improve
maturity moves forward every month: measured, reported, and benchmarked against your sector.
A year on Fortify
What the first twelve months usually look like.
Controls climb the Essential Eight one at a time while the phishing click rate falls with each simulation. Whatever still gets through is handled by the responders who built the plan. The figures are illustrative, shaped on a typical first year for an Australian SME.
Over twelve months the business moves from no Essential Eight controls at Maturity Level 2 to all eight. Microsoft Secure Score rises from 34 to 78 percent and the phishing simulation click rate falls from 21 to 3 percent. Along the way the Fortify team handles fifteen events, from a risky overseas sign-in and a malicious attachment to a password spray refused without the security key, and delivers a board report every month. All figures are illustrative.
Scope
What's included
in every Fortify engagement.
Nine capabilities included as standard. No per-item upsell, no surprise scope. Every Fortify client gets the full programme.
24/7 monitoring
Australian-staffed SOC watching your environment continuously.
Endpoint detection
EDR deployed across all managed devices with behavioural detection.
Identity protection
Real-time alerts on compromised credentials and risky sign-ins.
DNS filtering
Malicious and domains blocked before reaching your users.
Phishing simulations
Regular campaigns with targeted retraining for staff who click.
Awareness training
Short modules covering the threats actively targeting your sector.
M365 security uplift
, Defender, and configured to ASD standards.
Backup testing
Backups managed, restore-tested, and kept where an attacker inside the network cannot reach them.
Monthly reporting
Plain-English posture report for the board, technical detail for IT.
Built for Microsoft environments
Fortify is engineered around Microsoft 365, the platform most Australian SMEs already run.
We don't layer third-party agents on top of Microsoft's stack. Instead, we configure Entra ID, Defender, Intune, and Purview to ASD standards, which lifts your Microsoft Secure Score every month.
- Identity protection via Entra ID
- Conditional Access for every sign-in
- Endpoint security through Defender
- Secure Score lifted month on month
The gaps we see on incidents
What our responders find most often on Australian incidents, and what Fortify does about each one. Public cases from our breach tracker, no client named.
- Remote access with a password and no MFAMFA enforced on every external path, legacy sign-in blocked.
- A provider's remote-management tool as the way inProvider access reviewed, time-boxed, and alerted on.
- A mailbox nobody is watchingSign-in and inbox-rule monitoring across Microsoft 365.
- An endpoint where the attacker sat for daysDetection on every managed device, watched 24/7.
- Backups the attacker could reachBackups isolated and restore-tested, not assumed.
- Logs that rolled over before anyone lookedRetention long enough that the trail exists when needed.
What good looks like
Clear outcomes,
measurable every month.
Security is a posture, not a product.
Below are the four changes Fortify clients consistently see across their first six months: verified through monthly reporting, not promised at signing.
Fewer incidents
Most attacks never reach a user. Hardened identity, blocked domains, and applied controls remove the easy paths attackers rely on. The volume of incidents your team has to respond to drops sharply from month one.
Faster response
When something does get through, the responders are already your team. Containment happens in the first hour, not the next business day, and you get a plain-language account of what happened and what changes because of it.
Stronger controls
Identity, endpoints, and email configured to ASD standards and re-tested every month as the threat landscape moves. , Defender, and hardened deliberately, not left at the convenient defaults Microsoft ships with.
Improved posture
Your maturity tracked, reported, and benchmarked against your sector, so you can show the board where you sit, satisfy a application, or respond to a procurement questionnaire without scrambling.
Partnership
Already have an
IT provider?
Most of our clients do. Fortify is built to work alongside the team you already have, not replace them. Several of the incidents we work came in through a provider's tooling, so part of Fortify is making sure yours cannot be the way in.
General IT and dedicated cyber security are different disciplines. We close the security gap without overlapping with the team already keeping your environment running.
MSP partner program→Your IT team
Internal or external
IronSights Fortify
Security operations
Hardware, devices, and procurement
Continuous threat monitoring across endpoints, identities, and email
Patching and software updates
Incident containment within the first hour
Helpdesk, onboarding, and user support
Essential Eight maturity uplift and reporting
Network and infrastructure
Phishing simulations and staff awareness training
Email and collaboration setup
Board, insurer, and procurement-ready briefings
Client voice
We weren’t looking for fear or complexity, we just wanted a clear picture of where we stood and what to focus on. IronSights delivered that. The advice was direct, practical, and aligned to how we work. It’s helped us move forward with confidence.
Akram
Managing Director · Student Immigration Agency
Common questions
Asked by buyers like you.
Not in this list? Book a 30-minute consultation. No obligation.
What is a managed security service provider (MSSP)?
An MSSP is a specialist firm that runs your security operations for you: monitoring your systems around the clock, detecting and containing threats, and reporting on your posture. It is the security equivalent of what a managed service provider (MSP) does for general IT. Fortify is IronSights' managed security service: a 24/7 Australian-staffed SOC, incident response, and Essential Eight uplift on a fixed monthly fee.
What is the difference between an MSP and an MSSP?
An MSP keeps your technology running: helpdesk, devices, servers, email. An MSSP keeps it secure: threat monitoring, detection and response, hardening, and compliance reporting. They are different disciplines with different tooling and staffing, which is why most of our clients keep their existing MSP and add Fortify alongside it rather than replacing anyone.
Who is Fortify built for?
Australian small and mid-sized businesses (typically 20 to 500 staff) running Microsoft 365 as their primary technology environment. We are particularly well-suited to professional services, financial services, healthcare, and any organisation with client data sensitive enough that a breach would damage the business commercially.
Do we need to replace our IT provider?
No. Fortify works alongside your existing internal IT team or managed service provider. We close the security gap that general IT support is not staffed to cover: continuous monitoring, threat hunting, incident response, and Essential Eight uplift. We do not duplicate what your IT team already does well. If you want to understand exactly where that boundary sits, read our guide on IT support vs a dedicated cyber security provider. For organisations weighing managed security against building an in-house function, our overview of cyber security roles and salaries in Australia gives useful context.
How quickly can you onboard us?
Onboarding typically takes two to four weeks depending on the size and complexity of your environment. The first week is assessment, the second is deploying monitoring and hardening high-risk gaps, and ongoing weeks layer in the full Essential Eight programme.
What if we get hit by an incident?
Our responders handle it as part of the plan, with no hourly cap. They contain the affected systems, investigate what was accessed, and walk you through any notification obligations under the Notifiable Data Breaches scheme. The exclusions are the ones you would expect: attacks by nation-state actors, a compromise that was already in place before you joined Fortify, and systems outside the managed scope. Everything else on a Fortify environment is ours to resolve at no additional charge.
Why would an incident response firm sell prevention?
Because the response work shows us exactly how Australian businesses get breached, and most of it is preventable. Fortify is the plan we would want every business we have responded to to have had in place. It also lines our interests up with yours. Since we carry the response for our own clients, the cheapest incident for us is the one that never happens.
Is Fortify an incident response retainer?
It includes one. Fortify clients get our responders as part of the plan, not a separate engagement at emergency rates. Most of the value, though, is in the months where nothing happens, because the gaps that cause incidents have been closed.
How is Fortify priced?
Fortify is a monthly retainer scoped to the size of your environment: number of users, devices, and the complexity of your existing Microsoft 365 tenancy. We provide a fixed monthly fee following the initial assessment so you can budget with certainty.
Solutions we deploy
What Fortify puts in place.
Microsoft 365 Security
Harden identities, email, and data across the M365 tenant you already run.
Explore solution→Microsoft Defender
Endpoint, identity, email, and cloud app threat detection across Defender.
Explore solution→Conditional Access
Zero Trust access policies and device compliance in Microsoft Entra.
Explore solution→Microsoft Purview
Sensitivity labels, data loss prevention, and information governance.
Explore solution→Copilot Security Readiness
Permissions and oversharing cleanup before a Microsoft Copilot rollout.
Explore solution→DNS Filtering
Network-layer blocking of malicious and phishing domains.
Explore solution→Awareness Training
Phishing simulations and behavioural training that change habits.
Explore solution→Related services
Other IronSights capabilities.
Audit & Assurance
Start with an independent baseline assessment against Essential Eight, ISO 27001, NIST CSF, or SMB1001 before or alongside managed security.
Learn more→Virtual CISO (vCISO)
The strategy layer above managed security. A vCISO owns the roadmap, governance, and board reporting that Fortify's operations deliver against.
Learn more→Penetration Testing
Validate that Fortify's hardened controls hold up against a real attacker. Manual pen testing to stress-test what we've built.
Learn more→Incident Response
The emergency line. If you are mid-incident now, start there, not here. Fortify clients already have these responders on their plan.
Learn more→First step
Start with a review.
Tell us about your environment. We'll assess where your risks sit and put a scoped Fortify proposal in front of you within a week. No obligation.
