IT Works Shield watches your environment around the clock, so a problem at 2am is handled at 2am rather than discovered the next morning.
Most organisations have some form of antivirus or endpoint protection in place, and most of it works well enough during the day when someone is watching. The gap opens after hours, on weekends and over the Christmas break, when an alert fires and nobody sees it until the next working day.
That gap is where the damage happens. An attacker who gets in on a Friday evening has the whole weekend to move through an environment before anyone notices.
Shield closes that gap. Detection and response run continuously, and the alerts that matter reach a person who can act on them.
Two things get attacked most: the devices your people work on, and the accounts they sign in with. Shield covers both, because protecting one without the other leaves an obvious way in.
Continuous monitoring across Windows, macOS and Linux. Threats are isolated before they spread, and we find the persistent footholds that traditional antivirus consistently misses.
Monitoring of your Microsoft 365 environment for stolen session tokens, compromised accounts, rogue applications and hidden inbox rules. These are the attacks that walk straight past multi-factor authentication.
Your environment is watched around the clock by a dedicated security operations centre, with analysts actively hunting for attacker behaviour rather than waiting for an alarm to go off.
Every alert is validated before it reaches anyone, so you hear about real threats and not about noise.
Most organisations already have antivirus and multi-factor authentication in place, and assume that covers it. These are the things that get through anyway.
Attackers steal the session token that keeps someone signed in, then load it into their own browser. No password needed, and multi-factor authentication never gets asked. Shield detects the takeover and shuts it down.
A malicious app quietly connected to your Microsoft 365 tenant can extract data and keep access long after a password change. Shield finds them and removes them.
Silent forwarding rules are a hallmark of business email compromise, often set up weeks before the invoice fraud lands. Shield spots them and reverses them.
The mechanisms attackers leave behind so they survive a reboot or a password reset. This is the gap traditional antivirus leaves open, and it is where Shield spends most of its attention.
Decoy files placed quietly across your environment trigger the moment encryption begins, so containment starts in minutes rather than after the damage is done.
Your external footprint is checked for the exposures attackers look for first, before they find them.
Not every organisation needs the same depth of coverage. A twenty person business and a council with insurance and audit obligations are solving different problems, so Shield comes in three levels.
Most organisations start at Advanced. It is the level we recommend by default because it covers the things that come up most often.
Foundational protection for organisations that need reliable cover without complexity.
Active defence for organisations where downtime or a breach would cause real disruption.
Full visibility for organisations with compliance, insurance or audit obligations to satisfy.
Shield is priced on the number of people and systems you need covered, so the cost scales with the size of your organisation rather than sitting at a fixed rate that suits nobody. A team of fifteen pays for fifteen. A team of two hundred pays for two hundred, at a better rate per person.
Shield Complete also takes into account how many systems feed logs into the platform, since log volume varies a lot between organisations.
Add people and the cost moves with you. There is no step change or renegotiation when you grow.
Larger environments cost less per person. If you are over a hundred users, that difference is meaningful.
One monthly figure, agreed up front, covering the level you have chosen. Onboarding and baseline setup are included, not billed separately.
We will give you a firm number once we know how many people you need to cover and which level suits your obligations. That is usually a fifteen minute conversation.
This is the question worth asking any security provider, and the answers vary more than you would expect.
Shield includes 24/7 monitoring and automated containment as standard, delivered through a dedicated security operations centre that runs around the clock. When a threat is confirmed it is isolated immediately, whatever the hour, and a clear incident report follows.
IT Works is your local team. We configure the environment, tune it to how your organisation actually works, review the reporting with you and handle anything that needs a conversation rather than a ticket.
Where organisations differ is what happens in the hours after containment. Some are comfortable picking things up the following morning, knowing the threat is already contained. Others want someone from IT Works engaged immediately, at any hour, working the incident and keeping them informed.
That second option is available as an addition to any level. We keep it separate and priced separately so you can see exactly what it costs and decide whether you need it, rather than paying for it quietly inside a bundle.
Plenty of providers can sell you a security product. The difference shows up in what happens around it.
For managed clients, the team reviewing your security is the same team that supports your people and manages your systems. There is no handover and no explaining your setup to a stranger mid incident.
IT Works holds SMB1001:2025 Gold certification and is working through SOC 2 Type II. When your insurer, auditor or board asks how your provider is assessed, there is a documented answer.
Monthly reporting written to be read by people who are not technical, so you can take it into a board meeting without translating it first.
Shield is built on the Huntress managed security platform, chosen because it was designed for organisations of your size rather than scaled down from an enterprise product. See the technologies we work with.
If you are not sure what you currently have in place, start with our free Security Health Check. Twelve questions, no obligation, and a clear picture of where your gaps are.
If you already know you need 24/7 cover, talk to us and we will size it for your organisation.
We use cookies to improve your security and experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
You can find more information in our Cookie Policy and Privacy Policy.