24/7 monitoring & response · for K-12 districts

Guardian

security operations center for districts

Analysts watching every device and your network, all night and all summer, with the authority to stop an attack.

Nearly a third of what Guardian catches arrives outside school hours. A district is staffed roughly 07:30 to 15:30 on about 180 days a year. Attackers know that.

24/7/365 analystsWe isolate, not just alertReported per buildingMinutes, not tickets
Guardian · overnightTue 02:14
Credential theft attempt on a serverDISTRICT-DC01 · svc_backup · high confidenceContained
  • 02:10Detected
  • 02:11Analyst paged
  • 02:13Confirmed genuine
  • 02:14Host isolated, process killed, address blocked
  • 07:30Technology director briefed
What it isA managed security operations center: sensors on your endpoints and network edge, watched by analysts around the clock.
Who it is forAny district whose technology team goes home at night, over the weekend, and for two weeks in December.
What you getAn attack stopped while it is happening, and a plain-language finding with the evidence and the action already taken.

How it works

Four minutes, while the district slept.

1Detected

A service account tries to read every password on a server. Nothing legitimate does that. Sensors flag it.

2Confirmed by a person

An analyst is paged, looks, and confirms it is genuine. No auto-ticket, no alert queue for your team.

3Contained

The host is isolated, the process killed, the address blocked. Before anyone in the district is awake.

4You are briefed

At 07:30 your technology director gets the finding, the evidence and what was done. In plain English.

Inside Guardian

One night, as the console saw it.

Your team can watch everything we watch. Most districts read the monthly page and take the call when it matters.

LiveGuardian · district consoleTue 02:10 – 07:30

Buildings

North Elem388
Central HS1,204
East Elem366
West Middle612
South Elem1 isolated
Ridge Elem396

Coverage

Windows 2,988macOS 140Chromebook 1,010Servers 63Edge 6 sites

Live feed · South Elem · Tue

  • 02:10Credential dumping attempt on DISTRICT-DC01 by svc_backupLSASS memory read · high confidence · not a scheduled job
  • 02:11Analyst pagedJ.R. acknowledged in 40 seconds
  • 02:13Confirmed genuineProcess tree and network trace attached to case #4471
  • 02:14Contained — host isolated, process killed, 185.….14 blocked at the edgeRules of engagement: our authority, no call needed
  • 02:16Evidence sealedKept for your insurer and auditor
  • 07:30Briefing sent to the technology directorPlain English, what happened, what we did, what is left: nothing

This incident

4 mindetection to containment
Host isolated
Process killed
Address blocked
Account reset queued

Nobody in the district was awake. Nobody needed to be.

Left: every buildingStatus per school, and what is covered.
Centre: the feedEvery step, timestamped, in plain English.
Right: what we didActions taken on our own authority, and how fast.
Monthly report · Augustboard copy
84posture score, up from 71
3contained by us
1escalated to you
1,842
Alerts receivedmachines and sensors
26
Read by an analystthe rest filtered as noise
3
Genuine, containedevidence sealed

What the board reads: one page a month, per building.

Rules of engagementsigned 14 Aug
Isolate a workstation on confirmed credential theftOur authority, any hour
Block an external address at the edgeOur authority, any hour
Isolate a serverWe call first: technology director, then superintendent
Disable a user accountWe call first

Agreed once, in writing, before go-live.

What is included

Watching, acting, explaining.

Endpoint and network monitoring

Every workstation, server and the network edge, continuously. Nights, weekends, school breaks.

Authority to act

We isolate machines, kill processes and block addresses. You agree the rules of engagement once.

Organised by building

Alerts and reports grouped by school, so a principal sees their building and the board sees the district.

Analyst-confirmed alerts

Every alert is read by a person before it reaches you. You never triage a queue.

Evidence retained

Sealed evidence for every incident, kept for your insurer, auditor or state reviewer.

Quiet-hours coverage

Winter break, spring break and summer are when we watch hardest, because that is when the buildings are empty.

What you get to keep

Proof that somebody was watching.

A monthly one-pager

Per building. What was caught, what was done, what is left. Written for a board.

Incident records

Detection to containment, timestamped, with the evidence sealed.

A named engineer

You deal with the person who knows your network, not an account manager.

Questions districts ask

Before you call

Does Guardian replace our antivirus?

It builds on endpoint protection and adds the people. If you already run an EDR we can usually work with it; if not, we deploy one as part of the service.

What are the rules of engagement?

Agreed in writing before go-live: what we may isolate on our own authority, and what we call you about first.

Do you cover Chromebooks?

Guardian watches Windows, macOS and Linux endpoints and the network edge. Chromebook fleets are covered at the network level and through Google Workspace signals.

What happens during a school break?

Nothing changes. Coverage is 24/7/365 and breaks are when we expect the most activity.

Get started

Tell us what you are being asked to prove.

An insurance renewal, a state review, a board question. We will tell you which program answers it, or that none of them do. Straight answer, fixed quote, from the engineer who would do the work.

1-888-528-8948

Reply within one business day. No sales sequence, no mailing list.