§ 01Services
The people who build the platform are the people who defend it
Eigenvector IT designs and runs the platforms that carry regulated workloads, then defends them once they are live. Eight service lines across two practices, delivered by our own employees under one master services agreement.
§ 02The two practices
What each practice is accountable for
A detection raised by the analysts becomes engineering work the same week, under one accountable lead and one service manager.
Four service lines
Trading platforms, claims systems, clinical records, plant networks and payroll. We design them, migrate them, and staff the desk that keeps them running. Led by Henrik Lindqvist. Bought as a fixed-price project or a monthly managed service.
Four service lines
We monitor the estate, test it against real attack paths, respond when something happens, and prepare the evidence an auditor asks for. Led by Priyanka Raghunathan. Bought as a monthly managed service, an incident response retainer or a defined test.
§ 03Technology services
Platforms, identity, operations and recovery
Four service lines: the platforms themselves, the identities that control access to them, the desk that keeps them running, and the recovery plan behind them. Each is sold on its own or inside a monthly managed service.
-
01
Cloud and Infrastructure Engineering
We design, migrate and run the platforms that carry regulated workloads. The migration date, the rollback point and the run book are fixed in the scope before work starts. If rollback has not been tested, the cutover does not proceed.
-
02
Managed IT Operations
Service desk, endpoint management and platform operations, with a named service manager who signs the report. Response times, coverage hours and the escalation path are set in the service level schedule, and the monthly report shows performance against every one of them, including the months we miss.
-
03
Identity and Access Management
Identity is the control plane. We build it, tighten it, and prove who holds access. Standing privileged access is replaced by time-bound elevation, access reviews are evidenced quarterly, and every entitlement traces to an approver and a date.
-
04
Continuity and Disaster Recovery
Recovery plans that have been run, timed and signed off, not filed. Recovery targets are proved by a timed failover you attend, and the recorded time, not an estimate, is what goes in the report.
§ 04Cyber defence
Detection, response, testing and compliance
One practice lead is accountable for all four service lines. The analyst who watches your estate works for the firm that built it, under the same agreement and the same service level schedule.
-
01
Managed Detection and Response
We monitor your estate across endpoint, cloud and network, and tune the detections to it rather than to a vendor default. Priority one detections are acknowledged and triaged within 15 minutes inside contracted coverage hours, containment authority is agreed in advance, and every case is reported monthly against that threshold.
-
02
Incident Response and Digital Forensics
We contain the incident and produce evidence that survives legal and regulatory review. Clients without a retainer start at enquiries@eigenvector.group, with the word Incident first in the message. Retained clients hold an escalation channel and a mobilisation time agreed in the retainer. One written report follows, in a form the regulator, the insurer and the board can each use.
-
03
Offensive Security
Penetration testing, red teaming and adversary simulation, delivered by testers who hold the OSCP in their own names. Findings are ranked by exploitability rather than scanner severity, the report is delivered 10 working days after fieldwork ends, and a retest within 90 days closes it at no additional charge.
-
04
Governance, Risk and Compliance
Regulatory readiness and audit evidence, prepared before the assessor arrives rather than in the week they do. Evidence is collected once and mapped across regimes. We prepare and evidence the controls; the certificate or opinion is issued by the assessor you engage, never by us.
§ 05Service levels
The commitments written into the service level schedule
These are contract terms, not measurements. Each one is the level a client can hold the firm to in every month, including the worst one, and each is reported monthly with the underlying data behind it. They tighten by negotiation where an estate requires it.
| Commitment | Target | Detail |
|---|---|---|
| Priority one alert acknowledged | 15 minutes | An analyst acknowledges and begins triage on any priority one detection within 15 minutes of the alert, inside contracted coverage hours. Coverage hours are set in the service level schedule. Outside them, an on-call responder acknowledges within 60 minutes. |
| Containment action taken | 30 minutes | Actions listed in the authority matrix agreed at onboarding — host isolation, account disable, rule block — are taken under standing authority and reported to your duty contact within 30 minutes. |
| Incident response mobilised | Agreed in the retainer | Retained clients escalate through the channel agreed in their retainer. Everyone else starts at enquiries@eigenvector.group. Mobilisation time for retained clients is agreed in the retainer and written into the schedule. It is not a published figure. |
| Service desk first response | 30 minutes | The service desk gives a first response to a priority two ticket within 30 minutes, measured monthly with the underlying data behind it. |
| Service report issued | Fifth working day | A service report covering every agreed service level for the previous month is issued on the fifth working day and signed by the service manager named in your contract. Missed targets are reported with the cause and the corrective action beside them. |
| Reply to every enquiry | One working day | Every enquiry to enquiries@eigenvector.group is answered by a named person within one working day, whether it arrives from a client, a supplier or a candidate. |
If a finding cannot be reproduced in front of the client, it does not go in the report
Priyanka Raghunathan
Practice Lead, Cyber Defence
§ 07Delivery method
Five stages, from written scope to quarterly review
These stages describe a managed or platform engagement, and the week numbers are typical for a mid-sized programme. Testing work compresses the second, third and fourth stages into a single fieldwork window and closes at retest rather than on a quarterly cycle.
01Before signature
Written scope and named team
We agree the boundary, the assumptions and the exclusions in writing before anything is signed. Everyone who will do the work is named in the proposal, alongside the lead accountable for it and the date each deliverable lands. There is no sales team. The lead who scopes the work is the one who delivers it and signs the report.
02Weeks 1–4
Baseline against evidence
We measure the estate as it is: configuration, identity, recovery times, detection coverage. Findings are ranked by impact and remediation effort, and each one carries the evidence behind it. We do not present an estimate as a measurement.
03Weeks 5–18
Build to a dated plan
Work runs against a plan with dates, owners and a tested rollback for every change. Your engineers attend our stand-ups. Nothing goes live without a run book, and every handover is a platform we would run ourselves.
04Weeks 19–20
Transition into service
Service levels, escalation paths and containment authority are agreed before the first alert. Run books, detection rules and infrastructure code sit in your repositories. A named service manager takes the account from the delivery lead.
05Every quarter
Quarterly review
Each quarter we report performance against every agreed metric, the incidents raised, the changes made and the risks still open. The service manager named in your contract signs the report, and the next quarter's work is agreed in the same meeting.
§ 08Credentials
Credentials held by people, not by the firm
Eigenvector IT holds no corporate certification. SOC 2 Type I is in preparation and the examination date is set. Everything below it is a personal credential, held by the named practitioner and verifiable with the body that issued it.
- SOC 2 Type IIn preparation. Not held.Readiness work with an independent CPA firm is underway. The Type I examination is scheduled for 1 December 2026 and the report is expected by 31 January 2027. The Type II observation window opens 1 January 2027 and closes 30 June 2027.
- CISSPNadia Ben Salah, Priyanka RaghunathanPersonal certification, ISC2
- OSCPPriyanka Raghunathan, Rania HaddadPersonal certification, OffSec
- GCFAIfeoma Adeyemi, Aleksandra NowakPersonal certification, GIAC
- CISASofia Marchetti, Katharina VogtPersonal certification, ISACA
- CCSPDiego SotomayorPersonal certification, ISC2
- AWS and AzureHenrik Lindqvist, Tobias Reinhardt, Diego SotomayorAzure Solutions Architect Expert and AWS Solutions Architect – Professional, held individually
§ 09Procurement routes
How the work is bought, and how people are screened
Work is bought in one of four ways: a fixed-price project, a monthly managed service, an incident response retainer or a defined test. The contract is the master services agreement, its levels sit in the service level schedule and its data terms in the data processing agreement. The firm holds no facility clearance. Personnel screening is run to the standard your contract specifies, and the screening completed for each named person is stated in the proposal.
§ 10Procurement and security review
What procurement and security teams ask before signature
The contractual position sits in the master services agreement and its data processing agreement, available under mutual non-disclosure.
How is the work priced?
Three models, and the proposal states which applies. A fixed-price project is priced against a written scope, with change control for anything outside it. Advisory, testing and forensics are priced per day against a published rate card. A monthly managed service is priced in bands, by user, device or monitored data volume. Day rates and band prices are fixed for the contract term; the monthly charge moves only when a band boundary is crossed. Renewal uplift is capped at US CPI-U as published by the Bureau of Labor Statistics.
What are the contract terms and notice periods?
A master services agreement runs for 12, 24 or 36 months. After the initial term, either party may terminate on 90 days' written notice. An incident response retainer runs for 12 months with 60 days' notice, and unused retainer days convert to advisory or testing work rather than lapsing. Projects end on delivery and acceptance, not on a rolling term.
Where is client data held, and who can reach it?
Client data is stored and processed in the region you select: northern Virginia for the United States, Frankfurt for the European Union, and Toronto for Canada on request. Telemetry is segregated per client. Access from outside the region takes place from managed devices under privileged access controls, and every transfer is requested in writing and recorded. The subprocessor list is contractual, and any change requires 30 days' notice.
Do you subcontract delivery?
Delivery is by our own employees. Nothing is subcontracted except hardware forensics beyond our laboratory and external legal counsel during a regulated incident, both named in the proposal and both under our contract. Both also require your written approval. Named personnel are not substituted without notice and the replacement's résumé.
What happens at exit, and what do we get back?
The exit plan is written during onboarding. Run books, detection rules, infrastructure code and configuration baselines sit in your repositories throughout the contract, so nothing is extracted under pressure. Assisted transition runs inside the 90-day notice period at no additional charge, with up to 90 further days at day rates. Data returns in open formats within 30 days, followed by a certificate of deletion.
§ 11Next step
A practice lead replies within one working day
Send an outline of the estate, the regulatory deadline you are working to, and the date you need cover in place. The first scoping call carries no fee; a baseline assessment, if one follows, is fixed-fee against a written scope. If an incident is in progress, retained clients escalate through the channel agreed in their retainer, and everyone else writes to enquiries@eigenvector.group with the word Incident first in the message.