How it works
From an event on your network to a decision you can act on
Six stages. The first three are automated, the last three involve a person - because the value of a security operation lies in the judgement, not in the alerting.
Connect
AutomatedAgents are deployed to your servers and workstations, and your network devices, firewalls and cloud workloads are configured to report in.
Onboarding begins with an inventory: what you actually run, what it does, and which systems the business genuinely cannot operate without. That inventory determines monitoring priority, because treating every asset as equally critical produces an alert stream nobody can triage.
A lightweight agent is deployed to each server and workstation. Network appliances, firewalls and cloud workloads are configured to forward their logs. Nothing is rebuilt and no infrastructure change is required.
Your organisation is created as an isolated tenant at this point, with its own agent group, its own data separation and its own access rules. Isolation is designed in at onboarding rather than added later.
Collect
AutomatedTelemetry is normalised into a consistent schema and retained according to the retention policy agreed for your organisation.
Events arrive in many formats. They are normalised into one consistent schema so that a Windows security event, a firewall log line and a Linux audit record can be compared and correlated rather than read separately.
Retention is set per organisation at onboarding, not left at a vendor default. Investigations frequently need to reach back further than anyone expects, and retention that was never deliberately chosen is usually too short.
Collection health is itself monitored. If a log source stops reporting, that raises an alert within one cycle - because a source that has quietly gone silent is indistinguishable from one with nothing to report, and the difference matters enormously.
Detect
AutomatedCorrelation and detection rules identify suspicious activity, enriched automatically with threat intelligence and asset context.
A maintained detection ruleset runs against the normalised stream, extended with rules written specifically for your environment. Detections are mapped to MITRE ATT&CK technique identifiers at the point they are authored, so coverage is measurable rather than assumed.
Qualifying events are enriched automatically before a person sees them: reputation lookups, threat intelligence matching, and the asset record for the affected host are all attached.
One canonical severity ladder governs the whole platform. A critical alert means the same thing on a dashboard, in an email and in your monthly report - which sounds obvious and is a common source of confusion in platforms assembled from multiple products.
Investigate
Analyst-ledAnalysts triage high-severity events, establish what actually happened, and eliminate false positives before anyone is contacted.
This is the stage that separates a managed service from an alerting tool. An analyst examines the event, looks at surrounding activity, checks the affected host and determines whether it represents genuine risk.
Where deeper investigation is needed, analysts can query the affected endpoint directly and collect forensic artefacts remotely - process lineage, network connections, persistence mechanisms - and establish whether the same indicator appears anywhere else in your estate.
Most alerts stop here, and that is the point. You are not contacted about activity that turned out to be a backup job, because working that out is our job rather than yours.
Respond
Analyst-ledConfirmed incidents are escalated through agreed channels with recommended containment actions. Destructive steps need your authorisation.
Confirmed incidents are escalated through the contacts, thresholds and channels agreed during onboarding, recorded in the platform rather than held in an analyst memory. When something happens at 02:00, the procedure already exists.
What reaches you is a substantiated finding: what happened, which systems are affected, what the evidence shows, and what we recommend doing about it.
Automated containment stays conservative by design. Blocking actions are short-lived and auto-expiring, and anything that would take a production system offline requires your explicit authorisation. An automated response that stops your business is a worse outcome than the incident it prevented.
Report
Analyst-ledMonthly reporting generated from case records, covering what happened, what it means and what to fix next.
Every escalation becomes a case, and every case receives a documented outcome. The monthly report is generated from those records rather than assembled by hand, so the figures reconcile with what actually occurred.
The report covers alert volumes by severity, incidents and their outcomes, vulnerability posture and its trend, the assets appearing most often in investigations, and the attack techniques most frequently observed against you.
It also states what is still outstanding: known gaps, residual risks and recommendations not yet actioned. A report that only contains good news is not a management document.
What this does not do
Monitoring is not prevention, and we will not pretend otherwise
Vanguard detects and responds. It does not stop every attack from starting, and no security operations platform truthfully can. What it changes is the interval between something going wrong and somebody competent knowing about it - which, in most incidents, is the difference between a contained event and a disclosed breach.
It also depends on coverage. A system that is not monitored is not protected, and an estate that has been partially instrumented has gaps we will tell you about rather than gloss over. Where a system genuinely cannot be instrumented, we say so and put compensating detection around it.
And it depends on you. Containment recommendations still need somebody to authorise them, patches still need to be applied, and the recommendations in your monthly report only reduce risk if they are actioned.
Get started
See the process against a real environment
A demonstration walks through these six stages using genuine detections, so you can judge the quality of the judgement rather than the quality of the slides.