A Fortify 24x7 brand. The dispensary counter for healthcare technology.Sign inAsk us something
MediSafe Networks
Drawer I / Watch glass

Somebody watching the glass while the practice sees patients.

Nothing is handed over before it has been on a watch glass and up to the light. Six preparations do that to your endpoints. On the machine, an agent forms a view about behaviour. Correlation drags in whatever surrounded the event. And a case reaches an analyst who reads it, rather than a chart reaching you at nine in the morning.

SentinelOneFluencyThree response tiersStaffed around the clock
6 preparations / endpoint and node / notify or contain
Labels filed here6
Compounded onSentinelOne with Fluency
Measured byEndpoint, or cluster node
Read byFortify 24x7 analysts

Choosing between the three tiers

These are not good, better and best. They are three answers to a single question: how much would you like somebody else deciding for you at four in the morning? Managed detection puts the agent down and gives you an analyst who reads the case. The layered tier adds Fluency, which is what lets a login in one system and a process start in another be read as the same event. The response tier adds our hand on the switch.

The first two tiers are usually right wherever an IT person answers a telephone at night. Where the honest answer about who is watching after six is nobody at all, look hard at the response tier: a machine left infected until Monday is a notification with silence at the far end.

A machine sitting infected until Monday is a notification with nothing at the other end.

What a detection actually looks like here

Something gets convicted on a machine in the billing office. That endpoint comes off the network immediately while somebody is being woken, because isolating costs almost nothing and waiting costs a great deal. An analyst then opens the case, works out what the process was attempting, looks for the same shape elsewhere on your estate, and writes down a verdict.

If it is a false positive we say so plainly and tune it, and the tuning is written down so the next person to look understands why the rule reads the way it does. If it is real, what happens next depends on the tier you bought and the policy we agreed at scoping, never on an analyst improvising.

Labels in this drawer

What is filed here, and what each one costs

Billing supplies these figures directly. Add something and it stays on your script, untouched, for the rest of the page.

Fortify-MDRFormula

Managed Detection and Response

SentinelOne on the machine, our analysts behind it

The agent takes up residence on a workstation or a server and forms a view about behaviour, not about whether a filename appears somewhere on a list. Convict something and the alert goes to an analyst already on shift, rather than into a mailbox nobody at the practice has a spare minute for between patients.

  • Watches process behaviour on Windows, macOS and Linux, so a first-of-its-kind file is still judged on what it tries to do.
  • Convicted activity is isolated on the machine automatically while a human is being woken.
  • An analyst reads the case, decides whether it is real, and writes down the reasoning.
  • Front desk machines, clinical laptops and the server holding the practice management database are the usual first fit.
Made up forReception, clinical and back office machines carrying patient records
Acts onProcess behaviour, scripts, and memory activity on the endpoint itself
Shelf lifeNotes and evidence remain filed for the paid life of the line
Dispensed bySentinelOne. There is a Fortify 24x7 analyst on it at any hour
Counter-checkedA written verdict follows each conviction, and it keeps
Weighingper protected endpoint
counted per machine, charged monthly
QTY
Fortify-XDRFormula

Extended Detection Across Layers

SentinelOne with Fluency correlating around it

The same agent, plus Fluency drawing in signal from the places an endpoint cannot see: the identity provider, the firewall, the mail tenant. One suspicious sign-in stops being a shrug and becomes part of a sequence with a beginning and an end.

  • Fluency keeps sources side by side so a login, a download and a process start read as one story.
  • Retention long enough that a question asked three weeks late still has an answer.
  • Useful the moment a practice runs more than one building or more than one identity source.
  • Notification tier: our analysts investigate and advise, and containment stays your call.
Made up forGroups with several sites, several identity sources, or an auditor asking
Acts onEndpoint telemetry stitched to identity, network and mail records
Shelf lifeCorrelation holds long enough to answer a question asked late
Dispensed bySentinelOne beside Fluency, the pair of them run by Fortify 24x7
Counter-checkedA timeline can be lifted out whole and quoted in a write up
Weighingper protected endpoint
counted per machine, charged monthly
QTY
Fortify-XDR+Formula

Extended Detection with Response

SentinelOne with Fluency, and our hand on the switch

Everything the layered tier gathers, with the authority to act on it. Where the evidence leaves no doubt, our analysts cut the machine off, stop the process and put back what it changed, none of which waits on somebody answering a telephone at two in the morning.

  • Isolation, process termination and rollback run under a policy the two of us agree first.
  • The agreed rules say what may be done alone and what has to wait for your named contact.
  • Every action taken is logged with the time, the reason and the analyst who took it.
  • Fits practices with no in-house IT staff and clinical hours that leave nobody watching.
Made up forPractices with nobody on call and machines that cannot sit infected
Acts onThe endpoint directly: isolate, terminate, roll back, then report
Shelf lifeWhatever was done, and whatever was undone, files with the case
Dispensed bySentinelOne, acted on by Fortify 24x7 against a policy you signed
Counter-checkedEach intervention carries a name, and the note reaches you
Weighingper protected endpoint
counted per machine, charged monthly
QTY
Fortify-MDR-K8Formula

Managed Detection, Kubernetes Node

SentinelOne on the cluster node

Health technology companies and larger billing operations run their own clusters. This line puts the same behavioural agent on each node so a compromised container is caught where it runs, not inferred later from a billing anomaly.

  • Runs on the node, watching workloads and the runtime underneath them.
  • Counted per node, which is the number your platform team already knows.
  • Detections reach the same analysts who watch the rest of your estate.
  • Suits software teams inside healthcare, not the average clinic.
Made up forHealth software teams and billing platforms running their own clusters
Acts onContainer runtime behaviour and node level process activity
Shelf lifeEvidence on the node stays while the node stays covered
Dispensed bySentinelOne on the node, read by Fortify 24x7 analysts
Counter-checkedCoverage is squared against your cluster inventory monthly
Weighingper Kubernetes node
counted per node, charged monthly
QTY
Fortify-XDR-K8Formula

Extended Detection, Kubernetes Node

SentinelOne with Fluency, on the cluster node

Detection at the node, with the cluster laid alongside everything else Fluency is holding. A service account misbehaving inside a cluster then gets read against identity and network records instead of on its own.

  • Cluster signal correlated with identity, network and endpoint sources.
  • Retention that outlasts the pod, which is usually the problem with container evidence.
  • Notification tier: we investigate and advise, and you decide what happens next.
  • Charged by the node, so the invoice takes the shape the cluster already has.
Made up forClusters carrying patient data or claims traffic worth reconstructing
Acts onNode telemetry correlated with identity, network and endpoint records
Shelf lifeWhat the container did survives the container
Dispensed bySentinelOne and Fluency at the node, operated by Fortify 24x7
Counter-checkedThe correlated sequence exports cleanly for an investigation
Weighingper Kubernetes node
counted per node, charged monthly
QTY
Fortify-XDR+K8Formula

Response Tier, Kubernetes Node

SentinelOne with Fluency, and containment on the node

The cluster tier that lets our analysts intervene. Where a workload is plainly hostile the node is contained and the process stopped under the response policy you signed, and the note explaining it is waiting when your platform engineer next looks.

  • Containment on the node runs to an agreed policy, never to a hunch.
  • Every intervention carries a timestamp, a reason and a name.
  • The most expensive line here, and honestly the wrong one for most buyers.
  • Take it for clusters that touch protected health information directly.
Made up forClusters that would cause real harm if left running compromised
Acts onThe node itself: contain, terminate, then hand back a written account
Shelf lifeResponse records file with the case and stay while you subscribe
Dispensed bySentinelOne, with Fortify 24x7 acting to the signed policy
Counter-checkedEvery action is signed, then squared with your platform team
Weighingper Kubernetes node
counted per node, charged monthly
QTY
Read the label

Where this drawer stops

Detection is measurement and judgement. It is not prevention, and telling you otherwise would set you up to be surprised at the worst possible time.

  • It sees the machines carrying an agent. Take a sealed imaging console, an ageing analyser on an operating system nobody may touch, a private handset that never enrolled. None of them is covered, and buying more licences changes nothing. Such hardware wants a segment to itself plus a dated written decision, and we will draft that with you at the table.
  • It does not make anyone HIPAA compliant. What these six do is hold up technical safeguards inside a program you are running. None of them is an accreditation, and no such accreditation is for sale anywhere.
  • A response tier is bounded by the policy you signed. Our analysts contain what the agreed policy lets them contain. Where the evidence is ambiguous or the machine is clinically critical, we call your named contact instead of guessing on your behalf.
  • Backups are a separate purchase. Rollback goes exactly as far as the agent could see and no further. Dead drives, burnt servers, a tenant emptied by somebody leaving: the keeping jars own all of it, and nothing in this drawer stands in.
  • Alert volume is real work in the first fortnight. Odd behaviour is in the nature of clinical software. Budget a fortnight of tuning and two or three short conversations with us. Promises to the contrary are how a miserable opening month gets arranged.
NOTE 01

Heads up: card statements show FORTIFY 24X7 - MediSafe Networks is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.