What is included
CaaS bundles the things a security team would do if you had one, and runs them on the regular cadence set in your contract:
- Vulnerability management. Continuous external scanning, scheduled internal scanning, triage of results, and coordination with whoever patches. We track time-to-fix and report it.
- Hardening and configuration. Microsoft 365 / Google Workspace, identity (MFA, conditional access, privileged accounts), endpoints, cloud accounts and network edge, worked through against CIS-style baselines and your own risk appetite.
- Policy and governance. The policy set your customers, auditors and NIS2/DORA require, written to be followed rather than filed, mapped to ISO/IEC 27001 controls.
- Awareness training. Short, role-specific sessions and phishing simulations; results feed the roadmap.
- Vendor and third-party risk. A review process for new suppliers and a re-review cycle for the ones that hold your data.
- Incident response retainer. A named engineer, agreed response times, a rehearsed runbook and post-incident reporting.
- Management reporting. Reporting and management reviews at the cadence set in your contract, in the language your board reads.
How we work
A named security lead owns your account and does not change without notice. CaaS engineering work — hardening, policy, remediation — is done by GlabIT engineers (round-the-clock monitoring, where you add the SOC service, is available under a contracted coverage model together with a partner SOC, as described on that page). Changes we make to your systems are logged, agreed in advance and made reversible wherever the platform allows; every recommendation comes with the reason and the risk of not doing it.
What CaaS is not
It is not a SOC. Monitoring, detection engineering and alert triage — with round-the-clock coverage available under a contracted model — are the SOC & managed detection service, which many CaaS clients add. It is also not a one-off audit: if you want a point-in-time view, start with a penetration test or a compliance gap assessment.