ManagedCyberDefence.
For companies that cannot afford to stand still — a named pod of engineers who know your environment, watching it around the clock, authorised to act before you have to ask.
- 0 min
- Critical alert triageA named analyst — not an autoresponder — acknowledges every P1 within fifteen minutes, around the clock.
- 0×7×365
- Live SOC coverageFollow-the-sun rotation across two operations centres. No overnight queue that gets read at 9am.
- < 0 days
- Time to full coverageFrom signed order to complete telemetry, tuned detections and a documented response runbook.
- 0 pod
- One team, start to finishThe engineers who onboard you are the engineers who defend you. No handover to a stranger in month two.
01What we run
Seven disciplines, operated as one grid
Security fails at the seams between tools and teams. We run these together so nothing falls between them — take the whole grid, or the parts you cannot staff.
Extended Detection & Response
One correlated view of endpoints, network, cloud workloads, identity and applications — watched around the clock by analysts who are authorised to act, not just to email you.
Defend02AI & API Security
The two surfaces growing fastest in most companies. We inventory every API and model integration — including the ones nobody documented — then put real controls around what they can read and what they can do.
Defend03Unified Endpoint Management
Every laptop, phone and server enrolled, hardened, patched and provably compliant — Windows, macOS, Linux, iOS, Android and ChromeOS, managed from one place.
Control04Identity & Access Management
Identity is the real perimeter. We design and run the access layer — single sign-on, phishing-resistant MFA, privileged access and joiner-mover-leaver automation across every application you run.
Control05Zero Trust, Cloud & Supply-Chain Risk
Verify every request, shrink what a compromised account can reach, and extend the same standard to the third parties already inside your network.
Control06Compliance Automation
Certification and regulatory work run as an engineering project — evidence collected continuously from your systems, controls mapped across frameworks at once, and someone beside you in the audit room.
Assure07AI Process Automation
The repetitive half of how your company runs, handed to machines — workflows, support triage, document processing and reporting, built and operated with the same engineering discipline as the security work.
AutomateDefendContinuous watch over the surfaces attackers actually use.
ControlThe identity, devices and access that shrink the attack surface.
AssureProof — for your board, your customers and your regulator.
AutomateThe repetitive work your people should not be doing by hand.
02The Grid Model
Four moves, in order, every time
Security programmes stall when they start in the middle. We map before we harden, harden before we watch, and rehearse the response before we need it.
- 01
Map
You cannot defend a network you have never drawn.
We start with two weeks of discovery: every asset, identity, cloud account, third-party connection and data flow. Not a questionnaire you fill in — telemetry we collect ourselves. Most engagements surface a meaningful number of systems the client did not know were still running.
DeliverableAsset and identity inventory, data-flow map, ranked risk register
- 02
Harden
Fix the cheap things first, loudly.
We sequence remediation by exploitability against effort, so the first month removes the attack paths that a real intruder would actually use. Nothing goes on a roadmap without an owner and a date, and we do the work rather than handing you a list.
DeliverableHardened baselines, closed exposures, documented exception register
- 03
Watch
Continuous monitoring, tuned to your environment.
Telemetry flows into one correlated view and detections are written against how your business actually behaves. A finance tool that logs in from three countries is normal for you and suspicious for someone else — the rules should know the difference.
Deliverable24×7 SOC coverage, tuned detection library, live dashboards
- 04
Respond
Rehearsed, pre-authorised, and written down.
Containment actions are agreed before they are needed, so the response is measured in minutes. Every incident ends with a root-cause report and a change to the detection library, which is what stops the second occurrence.
DeliverableResponse runbook, tabletop exercises, post-incident reports
03Defence Pods
One team, one monthly fee, no surprise invoices
A pod is a named group of engineers assigned to you — sized by endpoints and identities rather than alert volume, so a noisy month never changes the price.
Sentinel
Continuous cover for a growing team.
- Best for
- Companies establishing their first real security function.
- Scope
- Up to 250 endpoints & identities
- Response
- 30-minute critical triage, business-hours advisory
- +24×7 managed detection & response
- +Endpoint management and hardening baselines
- +Identity hardening: SSO and MFA rollout
- +Monthly posture review with your leadership
- +Quarterly posture review against your cloud and endpoint baseline
- +Incident response hours included
Vanguard
Most chosenThe full grid, for companies selling to enterprises.
- Best for
- Teams with certification deadlines and enterprise customers.
- Scope
- Up to 1,000 endpoints & identities
- Response
- 15-minute critical triage, 24×7 advisory
- +Everything in Sentinel
- +Cloud posture management across all accounts
- +Zero trust access and privileged access management
- +Compliance programme: ISO 27001, SOC 2 or DPDP
- +Continuous API discovery and posture monitoring
- +Security automation and playbook engineering
- +Named security lead in your leadership meetings
Citadel
Regulated, high-consequence environments.
- Best for
- Financial services, healthcare and critical operations.
- Scope
- Unlimited scope, dedicated pod
- Response
- 15-minute critical triage, dedicated on-call bridge
- +Everything in Vanguard
- +Dedicated analyst pod assigned to your account only
- +Threat hunting on a fixed monthly cadence
- +Supply-chain and third-party risk programme
- +Regulatory reporting workflows (RBI, SEBI, CERT-In)
- +Third-party and supply chain risk programme
- +Board-level reporting and audit representation
Pricing follows a scoping call, and the full figure is on the table before you sign. Compare the pods in detail
04Industries
Different regulators, different attackers, different first move
The controls that matter most depend on what you run and who supervises you. These are the sectors we work in most often.
SaaS & Technology
Your security posture is now part of your sales cycle.
SOC 2 Type IIISO/IEC 27001Fintech & BFSI
Regulated, targeted, and expected to prove it monthly.
RBI Cyber Security FrameworkSEBI CSCRFE-commerce & D2C
Peak season is also open season.
PCI DSS v4.0DPDP Act 2023Healthcare & Life Sciences
Downtime here is measured in patients, not in rupees.
DPDP Act 2023HIPAAEdTech
Minors’ data, seasonal load, and a very public brand.
DPDP Act 2023COPPALogistics & Manufacturing
Where the network stops, the line stops.
IEC 62443ISO/IEC 2700105Insights
What our engineers are writing about
The DPDP Act in practice: what actually changes for your engineering team
Most DPDP coverage is written for lawyers. This is the version for the people who will have to build it — consent plumbing, retention, breach clocks and the parts that touch your database schema.
22 July 2026
Identity is the perimeter now, and most breaches prove it
Attackers stopped breaking in some time ago — they log in. A look at why identity controls outperform almost every other security investment, and how to sequence the work.
30 June 2026
The alerts that should never reach a human
Analyst burnout is a detection engineering problem wearing a staffing costume. What we automate, what we deliberately do not, and how to tell the difference.
18 May 2026
05
The things people ask before they sign
01We already have an internal IT team. Where does KnightGrid fit?
Most of our clients have capable IT teams — what they do not have is a rota of analysts watching alerts at 3am on a Sunday. We take on continuous monitoring, detection engineering and incident response so your team keeps building. Your engineers stay in the loop through a shared channel and get the same dashboards we use.
02Do you replace our existing security tools?
Rarely. We are tool-agnostic and would rather make the stack you have earn its licence. We connect to your existing EDR, identity provider, cloud accounts and firewalls, then tell you honestly which tools are pulling their weight and which are shelfware you can cancel.
03How does pricing work?
A flat monthly fee per Defence Pod, sized by endpoint and identity count rather than by alert volume — so a noisy month never produces a surprise invoice. AI process automation work is scoped and quoted separately. You get the full price before you sign anything.
04What happens during an actual incident?
Our runbook triggers the moment a P1 is confirmed: containment actions we are pre-authorised to take, a live bridge with your named contacts, hourly written updates, and a full root-cause report within five working days. Incident response hours are included in every pod — we do not sell you the fire and then invoice the extinguisher.
05Can you help us pass a customer security review or an audit?
Yes, and it is one of the most common reasons companies call us. We run the gap assessment, write the policies, fix what the evidence shows is broken, and sit with you through the audit. For Indian companies we cover DPDP Act 2023 obligations alongside ISO 27001 and SOC 2.
06Where is our data stored?
Telemetry for Indian clients stays in Indian regions by default. We will document exactly what is collected, where it lives and how long it is retained before onboarding starts — and we will sign a DPA that says so.
Next step
Find out what an attacker would find first.
Twelve questions, four minutes, and a scored read of where your defences actually stand — or skip it and talk to an engineer directly.