Guardian
security operations center for districtsAnalysts watching every device and your network, all night and all summer, with the authority to stop an attack.
Nearly a third of what Guardian catches arrives outside school hours. A district is staffed roughly 07:30 to 15:30 on about 180 days a year. Attackers know that.
- 02:10Detected
- 02:11Analyst paged
- 02:13Confirmed genuine
- 02:14Host isolated, process killed, address blocked
- 07:30Technology director briefed
How it works
Four minutes, while the district slept.
A service account tries to read every password on a server. Nothing legitimate does that. Sensors flag it.
An analyst is paged, looks, and confirms it is genuine. No auto-ticket, no alert queue for your team.
The host is isolated, the process killed, the address blocked. Before anyone in the district is awake.
At 07:30 your technology director gets the finding, the evidence and what was done. In plain English.
Inside Guardian
One night, as the console saw it.
Your team can watch everything we watch. Most districts read the monthly page and take the call when it matters.
Buildings
Coverage
Live feed · South Elem · Tue
- 02:10Credential dumping attempt on
DISTRICT-DC01bysvc_backupLSASS memory read · high confidence · not a scheduled job - 02:11Analyst pagedJ.R. acknowledged in 40 seconds
- 02:13Confirmed genuineProcess tree and network trace attached to case #4471
- 02:14Contained — host isolated, process killed, 185.….14 blocked at the edgeRules of engagement: our authority, no call needed
- 02:16Evidence sealedKept for your insurer and auditor
- 07:30Briefing sent to the technology directorPlain English, what happened, what we did, what is left: nothing
This incident
Nobody in the district was awake. Nobody needed to be.
What the board reads: one page a month, per building.
Agreed once, in writing, before go-live.
What is included
Watching, acting, explaining.
Endpoint and network monitoring
Every workstation, server and the network edge, continuously. Nights, weekends, school breaks.
Authority to act
We isolate machines, kill processes and block addresses. You agree the rules of engagement once.
Organised by building
Alerts and reports grouped by school, so a principal sees their building and the board sees the district.
Analyst-confirmed alerts
Every alert is read by a person before it reaches you. You never triage a queue.
Evidence retained
Sealed evidence for every incident, kept for your insurer, auditor or state reviewer.
Quiet-hours coverage
Winter break, spring break and summer are when we watch hardest, because that is when the buildings are empty.
What you get to keep
Proof that somebody was watching.
A monthly one-pager
Per building. What was caught, what was done, what is left. Written for a board.
Incident records
Detection to containment, timestamped, with the evidence sealed.
A named engineer
You deal with the person who knows your network, not an account manager.
Questions districts ask
Before you call
Does Guardian replace our antivirus?
It builds on endpoint protection and adds the people. If you already run an EDR we can usually work with it; if not, we deploy one as part of the service.
What are the rules of engagement?
Agreed in writing before go-live: what we may isolate on our own authority, and what we call you about first.
Do you cover Chromebooks?
Guardian watches Windows, macOS and Linux endpoints and the network edge. Chromebook fleets are covered at the network level and through Google Workspace signals.
What happens during a school break?
Nothing changes. Coverage is 24/7/365 and breaks are when we expect the most activity.
Get started
Tell us what you are being asked to prove.
An insurance renewal, a state review, a board question. We will tell you which program answers it, or that none of them do. Straight answer, fixed quote, from the engineer who would do the work.
Reply within one business day. No sales sequence, no mailing list.
