MetisShield
MenuClose

Questions

Asked before anyone books.

These are the limits we would rather say on the first call than discover in a contract draft. Nothing here is a service level.

Is someone watching at three in the morning?

Not as a staffed shift. Collection and detection run continuously. A person reviews alerts on business days, 8:00–18:00 in the client’s time zone. Critical alerts outside that window go to whoever is on call, best effort, not a night desk. A staffed 24/7 SOC is not offered. That sentence changes only when a rota actually covers every hour.

What antivirus runs on Windows?

Microsoft Defender, which we manage, on the firm’s own Microsoft license. Defender is not open source. We will not put an open-source antivirus in its place and describe it as the same control.

How quickly can you see a Microsoft 365 account takeover?

Often not in the moment. Microsoft audit logs can lag 60 to 90 minutes, and we do not call that instant. When Managed ITDR is in the order and the log shows a takeover, the automatic actions are to revoke the session and remove a malicious inbox rule. Disabling the account outright still needs written authority. Google Workspace does not get that automatic pair until we have built and tested it.

Are the prices on this site a quote?

Proposed — pending validation of hosting and staffing cost. They are anchored on a public list price recorded 6 October 2026 so a firm can compare shape, not so we can borrow a brand. There is no checkout and no card form. The price that matters is a written proposal after an assessment.

Can you show customers, certifications, or a score?

No. There are no customers to cite, no testimonials, no awards, and no certifications. We will not invent a number or a logo wall. CISO Assistant reports, when we write them, are not attestations.

Will you take a dental or healthcare client?

Not until a business associate agreement exists. It does not. We will not accept patient logs, images, or a clinic tenant without one. The dental page describes the work we would do later. It is not an offer to start now.

Is the assessment a penetration test or a product demo?

Neither. It is a conversation about mail, endpoints, backups, and who already does IT, plus a short written note. We do not run exploits. Vulnerability scanners are not part of that conversation. They run only inside a written scope after an order. The form does not open a live console.

What happens after the form is sent?

A person is supposed to read it and reply within two business days once delivery exists. That aim is not a service level. The site does not send email. A developer machine saves the request to a local file. The production server stores or forwards it only when ASSESSMENT_DESTINATION is set in that server’s environment, to a file or to an HTTPS endpoint MetisShield operates. If that variable is empty, nothing is stored. The form never takes payment.

Tell us how the firm is set up.

An assessment is a conversation and a short written note. It is not a penetration test, and it is not a contract. Nothing on this site takes payment.

Book an assessment