How it works
From a conversation to a monthly letter.
MetisShield is the company the firm hires. We deploy the agents, hold the relationship, and do the human review. The detection software is open source, running on systems we administer. There is no partner SOC behind the logo.
The sequence
1. Assessment
A working session on what the firm already has: mail platform, MFA, endpoints, backups, and who the IT person is. We may look at settings with an admin on the call. We do not exploit anything, and we do not call it a penetration test. You receive a short written note.
2. Order
The order names the bundle, the approximate seat count, the log sources, the hours, and the price. Hours on this website are the default we will offer. They can be narrowed. They cannot be advertised as 24/7 staffed coverage while the staffing section of the plan still says otherwise.
3. Onboarding
Agents, log shippers, access, and a rollback. The first client will take longer than the tenth. We would rather slip a start date than discover the agent on a partner’s laptop the night before a filing.
4. Steady state
Automation continues. A person reviews on the published window and answers critical on-call. Once a month you get a letter: what fired, what was noise, what we need. A quiet month says so.
Who does what
This is the responsibility matrix we expect to attach to an order. It is a draft for that contract, not the contract. “The firm’s IT provider” is blank if you do not have one.
| Action | MetisShield | The firm | The firm’s IT provider |
|---|---|---|---|
| Watch alerts | Yes, on the published hours, with automation continuous. | You do not have to sit in a portal. | Copied only if you ask. |
| Call about a critical alert | We call the named contact. | Someone has to answer. | Copied when you want them on the bridge. |
| Isolate a computer | Only if the order authorizes it. | You can refuse that authority. | Often the person who is physically there. |
| Revoke a Microsoft 365 session and remove a malicious inbox rule | Automatic when ITDR is in the order and the audit log shows an account takeover. The log can lag 60–90 minutes. Not instant. The firm can narrow or decline this. | You own the tenant. | Do not race the same session without agreeing who acts. |
| Disable a cloud account, beyond that | Only with scoped access and written authority. | You own the tenant. | May already hold global admin. We should not both improvise. |
| Restore a backup | Not unless a separate scope says so. | You decide whether yesterday’s backup is the one to trust. | Often the operator of the backup product. |
| Tell clients, patients, or other parties | We do not. | You do, with your counsel. | Not their role unless you delegate it in writing. |
| Call the cyber insurer | We assemble the facts we have. | The named insured makes the call. | They can join. They are not the insured. |
| Repair a line-of-business application | We advise from the logs and the endpoint. | You decide when the practice can tolerate the fix. | Often the IT provider who already runs that application. |
Technology
The stack has its own page.
Named software, on machines we administer, including Microsoft Defender on Windows. Defender is not open source. Nothing in that list is installed for a client yet, and none of those projects have endorsed us.
Tell us how the firm is set up.
An assessment is a conversation and a short written note. It is not a penetration test, and it is not a contract. Nothing on this site takes payment.