Managed Security Services
For Proactive Cybersecurity
Proactive Blocking and Threat Hunting For Emerging Threats And Instant Active Remediation Response When A Threat Is Identified.

Our Managed Service Service Packages
Holistic IT Services to Design, Build and Manage to Achieve
Business Outcomes At A Predictable Per User Cost
Vigilance
Essential Security
Perfect for companies needing a fractional
security solution that partners with company internal IT staff, but without the expensive tooling and certified staffing requirements.
• 24/7/365 Security Operations Center (SOC) with active human monitoring
• Incident escalation upon detection to your
internal team for containment and mitigation
•Threat intelligence that exposes the
cyberattacker and their online infrastructure
Vigilance
Professional Security
Ideal for the larger enterprise customers and entities with regulatory and policy requirements.
• Vigilance Essential +
• Real Time Active Response and Incident
Management
• Threat hunting that seeks out threats before they land to prevent exploitation (and frustrate hackers).
• Weekly meeting availability
• Monthly SOC Reports
Vigilance
Ultimate Security
Our expanded service offering allows you to free up your team to focus on what they do best.
• Vigilance Professional +
• M365 Support and license management
• Vulnerability Management to monitor and
proactively fix known vulnerabilities found
within your network.
Managed Firewall
Our managed firewall service takes the
headache and worry from making sure your
ACL’s and policies match organizational
outcomes and goals.
This service includes firmware upgrades and vulnerability patching.
| 24/7/365 Active Monitoring | Incident Escalation | Threat Intelligence | Incident Containment | Active Response | Threat Hunting | M365 Support | Vulnerability Management | |
| Essential | √ | √ | √ | + | + | + | ||
| Professional | √ | √ | √ | √ | √ | |||
| Ultimate | √ | √ | √ | √ | √ | √ | √ | √ |
Security Incident Workflow
We utilize the NIST Cyber Security Framework to Integrate assets into a common logging and alerting platform and monitor, analyze and investigate IT threats.
Integration
Integration of cloud and on-premise SIEM tools with security endpoints.
Collection
Collection of cloud and on-premise user data, device, application and infrastructure log data.
Detection & Reporting
Detection and Reporting of prioritized threats with processes to root out false positives.
Investigation
Investigation of threats in real time to determine size and nature of the threat.
Containment & Eradication
Containment of the endpoint and/or identity to prevent further spread and eradication of all known vectors with strategic remediation to prevent follow up incidents.
Review
Review includes post-incident reports, lessons learned, root cause analysis and policy considerations.
Why TorchLight?
At TorchLight, our “why” is simple: we exist to serve our customers and protect them from the relentless threat of hackers. This mission drives everything we do, setting us apart in the Secured and Managed IT landscape.
We foster a culture of candor, transparency, service, proactive communication and a growth mindset, all aimed at supporting our clients’ needs. We seek trusted partnerships with organizations that share our values, prioritizing open dialogue and a win/win mindset.
Together, we ensure that IT security goals are not only met but exceeded, safeguarding business continuity every day. Our people are our greatest asset, unified by our mission to secure and serve our customers and frustrate the hackers.
The Way Forward – TorchLight Blog
-

Enterprise Business and Ransomware
The manufacturing industry has embraced automation and digitization as timelines have gotten tighter and business continuity has become essential. These aspects, along with the high-value data that manufacturing enterprises own (intellectual property, trade secrets, etc.) have made these types of companies more attractive cyber attack targets. Keep your supply chain running smoothly by protecting against…
-

Manufacturing and Ransomware
The manufacturing industry has embraced automation and digitization as timelines have gotten tighter and business continuity has become essential. These aspects, along with the high-value data that manufacturing enterprises own (intellectual property, trade secrets, etc.) have made these types of companies more attractive cyber attack targets. Keep your supply chain running smoothly by protecting against…
-

Healthcare and Ransomware
For the past several years, healthcare systems and hospitals have been high-profile victims of ransomware and other attacks. Find out what vectors for ransomware the healthcare sector faces.
-

SUEX, Crypto, and Ransomware
This year, the cryptocurrency platform SUEX was the first to be identified and sanctioned by the U.S. Government for its role in the ransomware payment chain, but it will likely not be the last. Here’s what you should know about SUEX and other cryptocurrencies.
-

Email Security in Ransomware Defense
Email security is an essential first step in patching vulnerabilities and protecting your business from malware and ransomware threats.
-

The Evolution of Ransomware
Over the past 40 years, the threat of ransomware has grown exponentially from initial generalized threats to targeted and specialized takedowns. New technology and the organization of perpetrators have evolved, and ransomware demands have never been higher.
-

The Seven Steps in the Ransomware Kill Chain
Ransomware can be a large concern for businesses – it compromises resources critical to operation and locks them in an encrypted environment until a ransom is paid. While every business should be aware of ransomware, not all understand the many steps involved in a full attack.
-

Channel Daily News Podcast with TorchLight’s Bo Wheeler
Bo Wheeler, Chief Revenue Officer at TorchLight, recently appeared on the Channel Daily News podcast with Don Witt to speak about the company, its mission, and the cybersecurity protection it provides for its customers.
-

Current Trends in Ransomware
Ransomware has been around almost as long as companies, institutions, and governments have been reliant on customer and constituent data. But there are ups and downs in popularity, tactics, and targets that can affect your company’s risk profile.
-

Log4j Critical Vulnerability
The critical vulnerability CVE-2021-44228 against log4j was released with zero-day exploitation actively occurring. If a device/application uses Java and logs any string relying on user input, it is vulnerable, and an attacker can run anything they wish on the system.
