How we work, and when you should choose somebody else.
We are not always the right answer. This page sets out the realistic alternatives, what each engagement scope covers, and what actually changes over a first year.
The honest summary. If you can sustain five or six security specialists internally, do that — it beats any outsourced arrangement. If you cannot, the real question is which provider actually tests its own work and shows you the result.
01 Three honest ways to solve this
We are not always the right answer. Below is a fair comparison of the realistic options for a typical 100–500 person organisation — including where building in-house genuinely wins.
| Consideration | Build in-house | Traditional IT provider | Xoopie |
|---|---|---|---|
| Round-the-clock cover | Needs 5–6 staff to sustain properly | Often business hours, with an on-call rota | 24×7 monitoring, incident line always answered |
| Who acts during an incident | Your team, whoever is awake | Usually alerts you and waits for instruction | We contain first, under pre-authorised actions |
| Recovery actually tested | Intended, rarely scheduled | Occasionally, if you ask | On a set cadence, measured and reported |
| Backup immutability | Achievable, needs deliberate design | Varies considerably by provider | Object Lock as standard on every tier |
| Log retention for audit | Storage cost usually forces short retention | Often 30 days, on the same estate | Up to 7 years, off-estate, tamper-evident |
| Evidence for auditors | Assembled manually before each audit | Assembled on request | Produced monthly whether asked or not |
| Deep institutional knowledge | Unmatched — they live in your business | Moderate, subject to account churn | Strong, but never equal to your own team |
| Control over priorities | Complete | Shared with their other clients | Defined by scope and service standards |
| Time to be operational | 6–12 months to hire and mature | 4–8 weeks | 4 weeks, staged, no downtime |
Your environment is genuinely unusual, security is core to your product rather than a supporting function, and you can sustain five or six specialists through leave, illness and resignation. A well-staffed internal team beats any outsourced arrangement. The failure mode is the one-person security team that becomes a single point of failure the moment they take a holiday.
You carry real regulatory or contractual exposure but cannot justify a full internal team — and you want the recovery, retention and evidence questions answered properly rather than assumed. We work best alongside a capable internal IT function, not as a replacement for one.
02 Three defined scopes
Each is a scope rather than a package to be negotiated upwards later. We issue a fixed proposal against a written scope after one discovery conversation — no procurement theatre, no six-week sales cycle.
Scope A · Essentials
For organisations with capable internal IT who need the fundamentals covered properly. Endpoint protection across all devices, nightly immutable backup at Standard recovery objectives, Microsoft 365 and Google Workspace backup, monthly vulnerability scanning, patch management, business-hours support, and the monthly evidence report.
Scope B · Protect Most engagements
The complete picture — monitoring, logs, storage and recovery run together as one accountable service. Everything in Essentials, plus continuous security monitoring and response, SIEM with 90-day hot log retention, a seven-year immutable compliance archive, Advanced recovery objectives, cloud object storage, half-yearly recovery testing, a 24×7 incident line, and a named engineer on your account.
Scope C · Assure
For regulated workloads where downtime or data loss carries statutory, contractual or clinical consequences. Everything in Protect, plus Premium recovery objectives with replication, an air-gapped backup copy, quarterly recovery testing with failback, compliance programme support, board-level reporting and priority on-site response.
Billed the way your estate is shaped. Per user, per device or as a fixed monthly retainer — whichever reflects your environment most fairly. Storage is charged on volume stored, with retrieval and egress included. Twelve-month agreements are standard, six-month pilots are available, and there are no setup fees.
03 What actually changes, and when
Providers are rarely specific about what improves and how quickly. Here is our honest expectation — including the fact that the first month usually makes things look worse before they look better.
| Period | What we are doing | What you will notice |
|---|---|---|
| Month 1 | Discovery, deployment, first restore test | More issues, not fewer |
| Months 2–3 | Detection tuning, patch backlog, log coverage | Alert volume drops sharply as noise is removed |
| Months 4–6 | Architecture fixes surfaced during discovery | Fewer repeat incidents; fewer surprises |
| Months 7–9 | Compliance evidence, second recovery test | Audits stop being fire drills |
| Months 10–12 | Optimisation, cost review, year-two roadmap | The conversation moves from firefighting to planning |
Month one looks bad
Discovery surfaces problems that were always there but unmeasured. A rising issue count in the first report is the system working, not failing.
Alerts fall, then plateau
Early tuning removes most noise quickly. After that, improvements come from architecture rather than configuration, and arrive more slowly.
Some findings need you
Where a fix needs budget, downtime or a business trade-off, it stays on the report with an owner until you decide — visible, not silently dropped.
04 Onboarding, week by week
Staged, agent-based and reversible at every point. You may stop at the end of any week and keep everything we have documented to that point. We have completed transitions without causing a business outage, and the method is why.
- Week 1 — Discovery. An inventory of assets, identities, network paths, existing tooling and what your current backups actually contain. The findings are yours whether or not you continue.
- Week 2 — Deployment. Agents, collectors and backup jobs rolled out in waves, scheduled outside your business hours, with rollback tested before each wave begins.
- Week 3 — Tuning and first restore. Detection tuned to your environment so alerts carry meaning. A full restore is run and the measured result given in writing.
- Week 4 — Cutover. We operate alongside your existing arrangement, compare coverage, close every gap, then assume ownership at a scheduled cutover with your sign-off.