Containment at machine speed, inside boundaries you set
Everything in AI-MDR Essentials, plus autonomous response: within defined boundaries, containment executes in-environment rather than waiting for a human in the loop. The minutes between detection and containment are where most damage happens.
Autonomous response is only safe when the boundaries are explicit, so designing them is the core deliverable of onboarding — not an afterthought buried in a contract.
What you get
- Everything in Essentials — baseline, anomaly detection, 24/7 analyst oversight, weekly reporting, monthly model review.
- Autonomous response — containment executes at machine speed within your agreed scope.
- Response boundary design — a written definition of what may execute autonomously, what needs an analyst, and what needs you.
- Monthly threat briefing — a live 45-minute session for your leadership team.
- Incident timeline and after-action — written timeline, root cause where determinable, remediation plan with owners.
- Quarterly boundary review — autonomous scope re-examined against what actually fired.
Default response boundaries
- Autonomous from go-live — isolate a workstation, revoke user sessions, disable a standard user account, block indicators.
- Analyst-approved — isolate a server; disable privileged or service accounts (you are called).
- Your explicit approval — anything affecting production availability. No standing authority, ever.
The starting position is deliberately narrow and widens only as confidence is earned. Every autonomous action is logged with its triggering evidence and reviewed in the monthly briefing. If an action was wrong, you hear it from us first.
What is not included
- Any guarantee of prevention, or a financial warranty against breach outcomes.
- Remediation labour, rebuilds and restores.
- Forensics intended for litigation or insurance claims.
Billed monthly. No minimum term. Cancel any time before your next renewal date.