§ 01Services

The people who build the platform are the people who defend it

Eigenvector IT designs and runs the platforms that carry regulated workloads, then defends them once they are live. Eight service lines across two practices, delivered by our own employees under one master services agreement.

Arrange a scoping conversation

§ 02The two practices

What each practice is accountable for

A detection raised by the analysts becomes engineering work the same week, under one accountable lead and one service manager.

Technology Services

Four service lines

Trading platforms, claims systems, clinical records, plant networks and payroll. We design them, migrate them, and staff the desk that keeps them running. Led by Henrik Lindqvist. Bought as a fixed-price project or a monthly managed service.

Cyber Defence

Four service lines

We monitor the estate, test it against real attack paths, respond when something happens, and prepare the evidence an auditor asks for. Led by Priyanka Raghunathan. Bought as a monthly managed service, an incident response retainer or a defined test.

§ 03Technology services

Platforms, identity, operations and recovery

Four service lines: the platforms themselves, the identities that control access to them, the desk that keeps them running, and the recovery plan behind them. Each is sold on its own or inside a monthly managed service.

  1. 01

    Cloud and Infrastructure Engineering

    We design, migrate and run the platforms that carry regulated workloads. The migration date, the rollback point and the run book are fixed in the scope before work starts. If rollback has not been tested, the cutover does not proceed.

    • Landing zone design for AWS, Azure and GCP
    • Datacentre exit and workload migration
    • Kubernetes platform build and operation
    • Infrastructure as code and change automation
    • Hybrid network and private connectivity design
  2. 02

    Managed IT Operations

    Service desk, endpoint management and platform operations, with a named service manager who signs the report. Response times, coverage hours and the escalation path are set in the service level schedule, and the monthly report shows performance against every one of them, including the months we miss.

    • Service desk inside contracted coverage hours, with the escalation path named
    • Endpoint build, patching and configuration baselines
    • Monitoring, alerting and capacity management
    • Vendor and third-party escalation management
    • Quarterly service reviews against agreed metrics
  3. 03

    Identity and Access Management

    Identity is the control plane. We build it, tighten it, and prove who holds access. Standing privileged access is replaced by time-bound elevation, access reviews are evidenced quarterly, and every entitlement traces to an approver and a date.

    • Single sign-on and conditional access rollout
    • Privileged access management and credential vaulting
    • Joiner, mover and leaver automation
    • Entitlement review and access recertification
    • Directory consolidation after merger or divestment
  4. 04

    Continuity and Disaster Recovery

    Recovery plans that have been run, timed and signed off, not filed. Recovery targets are proved by a timed failover you attend, and the recorded time, not an estimate, is what goes in the report.

    • Business impact analysis and recovery objectives
    • Backup architecture with immutable copies
    • Failover testing against live recovery targets
    • Crisis playbooks for board and operations
    • Third-party and supply chain dependency mapping

§ 04Cyber defence

Detection, response, testing and compliance

One practice lead is accountable for all four service lines. The analyst who watches your estate works for the firm that built it, under the same agreement and the same service level schedule.

  1. 01

    Managed Detection and Response

    We monitor your estate across endpoint, cloud and network, and tune the detections to it rather than to a vendor default. Priority one detections are acknowledged and triaged within 15 minutes inside contracted coverage hours, containment authority is agreed in advance, and every case is reported monthly against that threshold.

    • Monitoring across endpoint, cloud and network
    • Threat hunting on a fortnightly cycle
    • Detection engineering tuned to your estate
    • Containment actions taken under agreed authority
    • Monthly reporting on dwell time and coverage
  2. 02

    Incident Response and Digital Forensics

    We contain the incident and produce evidence that survives legal and regulatory review. Clients without a retainer start at enquiries@eigenvector.group, with the word Incident first in the message. Retained clients hold an escalation channel and a mobilisation time agreed in the retainer. One written report follows, in a form the regulator, the insurer and the board can each use.

    • Incident response retainer with a mobilisation time agreed in the retainer
    • Containment and eradication alongside your teams
    • Forensic imaging and malware analysis
    • Regulatory notification support under GDPR and DORA
    • Post-incident report with a remediation sequence
  3. 03

    Offensive Security

    Penetration testing, red teaming and adversary simulation, delivered by testers who hold the OSCP in their own names. Findings are ranked by exploitability rather than scanner severity, the report is delivered 10 working days after fieldwork ends, and a retest within 90 days closes it at no additional charge.

    • Infrastructure, application and cloud penetration testing
    • Red team and purple team exercises
    • Support to your threat-led testing programme, alongside the accredited tester
    • Build review, code review and configuration audit
    • Retest included within 90 days
  4. 04

    Governance, Risk and Compliance

    Regulatory readiness and audit evidence, prepared before the assessor arrives rather than in the week they do. Evidence is collected once and mapped across regimes. We prepare and evidence the controls; the certificate or opinion is issued by the assessor you engage, never by us.

    • Readiness for ISO/IEC 27001:2022 and SOC 2, run by consultants who have sat on the audit side
    • PCI DSS readiness, scope reduction and gap assessment
    • DORA, NIS2 and operational resilience mapping
    • Third-party and supplier assurance programmes
    • Board reporting and risk register design

§ 05Service levels

The commitments written into the service level schedule

These are contract terms, not measurements. Each one is the level a client can hold the firm to in every month, including the worst one, and each is reported monthly with the underlying data behind it. They tighten by negotiation where an estate requires it.

Table 01 — commitments written into the master services agreement
CommitmentTargetDetail
Priority one alert acknowledged 15 minutes An analyst acknowledges and begins triage on any priority one detection within 15 minutes of the alert, inside contracted coverage hours. Coverage hours are set in the service level schedule. Outside them, an on-call responder acknowledges within 60 minutes.
Containment action taken 30 minutes Actions listed in the authority matrix agreed at onboarding — host isolation, account disable, rule block — are taken under standing authority and reported to your duty contact within 30 minutes.
Incident response mobilised Agreed in the retainer Retained clients escalate through the channel agreed in their retainer. Everyone else starts at enquiries@eigenvector.group. Mobilisation time for retained clients is agreed in the retainer and written into the schedule. It is not a published figure.
Service desk first response 30 minutes The service desk gives a first response to a priority two ticket within 30 minutes, measured monthly with the underlying data behind it.
Service report issued Fifth working day A service report covering every agreed service level for the previous month is issued on the fifth working day and signed by the service manager named in your contract. Missed targets are reported with the cause and the corrective action beside them.
Reply to every enquiry One working day Every enquiry to enquiries@eigenvector.group is answered by a named person within one working day, whether it arrives from a client, a supplier or a candidate.

How the firm works

If a finding cannot be reproduced in front of the client, it does not go in the report

Priyanka Raghunathan

Practice Lead, Cyber Defence

§ 07Delivery method

Five stages, from written scope to quarterly review

These stages describe a managed or platform engagement, and the week numbers are typical for a mid-sized programme. Testing work compresses the second, third and fourth stages into a single fieldwork window and closes at retest rather than on a quarterly cycle.

01Before signature

Written scope and named team

We agree the boundary, the assumptions and the exclusions in writing before anything is signed. Everyone who will do the work is named in the proposal, alongside the lead accountable for it and the date each deliverable lands. There is no sales team. The lead who scopes the work is the one who delivers it and signs the report.

02Weeks 1–4

Baseline against evidence

We measure the estate as it is: configuration, identity, recovery times, detection coverage. Findings are ranked by impact and remediation effort, and each one carries the evidence behind it. We do not present an estimate as a measurement.

03Weeks 5–18

Build to a dated plan

Work runs against a plan with dates, owners and a tested rollback for every change. Your engineers attend our stand-ups. Nothing goes live without a run book, and every handover is a platform we would run ourselves.

04Weeks 19–20

Transition into service

Service levels, escalation paths and containment authority are agreed before the first alert. Run books, detection rules and infrastructure code sit in your repositories. A named service manager takes the account from the delivery lead.

05Every quarter

Quarterly review

Each quarter we report performance against every agreed metric, the incidents raised, the changes made and the risks still open. The service manager named in your contract signs the report, and the next quarter's work is agreed in the same meeting.

§ 08Credentials

Credentials held by people, not by the firm

Eigenvector IT holds no corporate certification. SOC 2 Type I is in preparation and the examination date is set. Everything below it is a personal credential, held by the named practitioner and verifiable with the body that issued it.

  • SOC 2 Type IIn preparation. Not held.Readiness work with an independent CPA firm is underway. The Type I examination is scheduled for 1 December 2026 and the report is expected by 31 January 2027. The Type II observation window opens 1 January 2027 and closes 30 June 2027.
  • CISSPNadia Ben Salah, Priyanka RaghunathanPersonal certification, ISC2
  • OSCPPriyanka Raghunathan, Rania HaddadPersonal certification, OffSec
  • GCFAIfeoma Adeyemi, Aleksandra NowakPersonal certification, GIAC
  • CISASofia Marchetti, Katharina VogtPersonal certification, ISACA
  • CCSPDiego SotomayorPersonal certification, ISC2
  • AWS and AzureHenrik Lindqvist, Tobias Reinhardt, Diego SotomayorAzure Solutions Architect Expert and AWS Solutions Architect – Professional, held individually

§ 09Procurement routes

How the work is bought, and how people are screened

Work is bought in one of four ways: a fixed-price project, a monthly managed service, an incident response retainer or a defined test. The contract is the master services agreement, its levels sit in the service level schedule and its data terms in the data processing agreement. The firm holds no facility clearance. Personnel screening is run to the standard your contract specifies, and the screening completed for each named person is stated in the proposal.

§ 10Procurement and security review

What procurement and security teams ask before signature

The contractual position sits in the master services agreement and its data processing agreement, available under mutual non-disclosure.

How is the work priced?

Three models, and the proposal states which applies. A fixed-price project is priced against a written scope, with change control for anything outside it. Advisory, testing and forensics are priced per day against a published rate card. A monthly managed service is priced in bands, by user, device or monitored data volume. Day rates and band prices are fixed for the contract term; the monthly charge moves only when a band boundary is crossed. Renewal uplift is capped at US CPI-U as published by the Bureau of Labor Statistics.

What are the contract terms and notice periods?

A master services agreement runs for 12, 24 or 36 months. After the initial term, either party may terminate on 90 days' written notice. An incident response retainer runs for 12 months with 60 days' notice, and unused retainer days convert to advisory or testing work rather than lapsing. Projects end on delivery and acceptance, not on a rolling term.

Where is client data held, and who can reach it?

Client data is stored and processed in the region you select: northern Virginia for the United States, Frankfurt for the European Union, and Toronto for Canada on request. Telemetry is segregated per client. Access from outside the region takes place from managed devices under privileged access controls, and every transfer is requested in writing and recorded. The subprocessor list is contractual, and any change requires 30 days' notice.

Do you subcontract delivery?

Delivery is by our own employees. Nothing is subcontracted except hardware forensics beyond our laboratory and external legal counsel during a regulated incident, both named in the proposal and both under our contract. Both also require your written approval. Named personnel are not substituted without notice and the replacement's résumé.

What happens at exit, and what do we get back?

The exit plan is written during onboarding. Run books, detection rules, infrastructure code and configuration baselines sit in your repositories throughout the contract, so nothing is extracted under pressure. Assisted transition runs inside the 90-day notice period at no additional charge, with up to 90 further days at day rates. Data returns in open formats within 30 days, followed by a certificate of deletion.

§ 11Next step

A practice lead replies within one working day

Send an outline of the estate, the regulatory deadline you are working to, and the date you need cover in place. The first scoping call carries no fee; a baseline assessment, if one follows, is fixed-fee against a written scope. If an incident is in progress, retained clients escalate through the channel agreed in their retainer, and everyone else writes to enquiries@eigenvector.group with the word Incident first in the message.