Nothing is handed over before it has been on a watch glass and up to the light. Six preparations do that to your endpoints. On the machine, an agent forms a view about behaviour. Correlation drags in whatever surrounded the event. And a case reaches an analyst who reads it, rather than a chart reaching you at nine in the morning.
These are not good, better and best. They are three answers to a single question: how much would you like somebody else deciding for you at four in the morning? Managed detection puts the agent down and gives you an analyst who reads the case. The layered tier adds Fluency, which is what lets a login in one system and a process start in another be read as the same event. The response tier adds our hand on the switch.
The first two tiers are usually right wherever an IT person answers a telephone at night. Where the honest answer about who is watching after six is nobody at all, look hard at the response tier: a machine left infected until Monday is a notification with silence at the far end.
Something gets convicted on a machine in the billing office. That endpoint comes off the network immediately while somebody is being woken, because isolating costs almost nothing and waiting costs a great deal. An analyst then opens the case, works out what the process was attempting, looks for the same shape elsewhere on your estate, and writes down a verdict.
If it is a false positive we say so plainly and tune it, and the tuning is written down so the next person to look understands why the rule reads the way it does. If it is real, what happens next depends on the tier you bought and the policy we agreed at scoping, never on an analyst improvising.
Billing supplies these figures directly. Add something and it stays on your script, untouched, for the rest of the page.
The agent takes up residence on a workstation or a server and forms a view about behaviour, not about whether a filename appears somewhere on a list. Convict something and the alert goes to an analyst already on shift, rather than into a mailbox nobody at the practice has a spare minute for between patients.
| Made up for | Reception, clinical and back office machines carrying patient records |
|---|---|
| Acts on | Process behaviour, scripts, and memory activity on the endpoint itself |
| Shelf life | Notes and evidence remain filed for the paid life of the line |
| Dispensed by | SentinelOne. There is a Fortify 24x7 analyst on it at any hour |
| Counter-checked | A written verdict follows each conviction, and it keeps |
The same agent, plus Fluency drawing in signal from the places an endpoint cannot see: the identity provider, the firewall, the mail tenant. One suspicious sign-in stops being a shrug and becomes part of a sequence with a beginning and an end.
| Made up for | Groups with several sites, several identity sources, or an auditor asking |
|---|---|
| Acts on | Endpoint telemetry stitched to identity, network and mail records |
| Shelf life | Correlation holds long enough to answer a question asked late |
| Dispensed by | SentinelOne beside Fluency, the pair of them run by Fortify 24x7 |
| Counter-checked | A timeline can be lifted out whole and quoted in a write up |
Everything the layered tier gathers, with the authority to act on it. Where the evidence leaves no doubt, our analysts cut the machine off, stop the process and put back what it changed, none of which waits on somebody answering a telephone at two in the morning.
| Made up for | Practices with nobody on call and machines that cannot sit infected |
|---|---|
| Acts on | The endpoint directly: isolate, terminate, roll back, then report |
| Shelf life | Whatever was done, and whatever was undone, files with the case |
| Dispensed by | SentinelOne, acted on by Fortify 24x7 against a policy you signed |
| Counter-checked | Each intervention carries a name, and the note reaches you |
Health technology companies and larger billing operations run their own clusters. This line puts the same behavioural agent on each node so a compromised container is caught where it runs, not inferred later from a billing anomaly.
| Made up for | Health software teams and billing platforms running their own clusters |
|---|---|
| Acts on | Container runtime behaviour and node level process activity |
| Shelf life | Evidence on the node stays while the node stays covered |
| Dispensed by | SentinelOne on the node, read by Fortify 24x7 analysts |
| Counter-checked | Coverage is squared against your cluster inventory monthly |
Detection at the node, with the cluster laid alongside everything else Fluency is holding. A service account misbehaving inside a cluster then gets read against identity and network records instead of on its own.
| Made up for | Clusters carrying patient data or claims traffic worth reconstructing |
|---|---|
| Acts on | Node telemetry correlated with identity, network and endpoint records |
| Shelf life | What the container did survives the container |
| Dispensed by | SentinelOne and Fluency at the node, operated by Fortify 24x7 |
| Counter-checked | The correlated sequence exports cleanly for an investigation |
The cluster tier that lets our analysts intervene. Where a workload is plainly hostile the node is contained and the process stopped under the response policy you signed, and the note explaining it is waiting when your platform engineer next looks.
| Made up for | Clusters that would cause real harm if left running compromised |
|---|---|
| Acts on | The node itself: contain, terminate, then hand back a written account |
| Shelf life | Response records file with the case and stay while you subscribe |
| Dispensed by | SentinelOne, with Fortify 24x7 acting to the signed policy |
| Counter-checked | Every action is signed, then squared with your platform team |
Detection is measurement and judgement. It is not prevention, and telling you otherwise would set you up to be surprised at the worst possible time.
Heads up: card statements show FORTIFY 24X7 - MediSafe Networks is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.