Co-Managed Guardian
Guardian's monitoring, security operations and tooling behind your own IT team.
Who it is for
Businesses with in-house IT staff who want to keep the front line and hand security, servers and the network to TSR.
Co-Managed Guardian gives your internal IT team the same platform TSR runs for fully managed clients — 24×7 detection and response, log retention, DNS filtering, patching, monitoring and documentation — while your team keeps tier-1 support and administrative control. TSR looks after security, servers and the network, takes after-hours escalations and carries the security operations centre relationship. Your team gets the tools, the portal and an engineer to call, without giving up the parts of IT it already does well.
Inside the rate
- 24×7 managed detection and response by a staffed security operations centre
- Logs kept off the machine that generated them, and DNS filtering on and off the network
- Patching, configuration enforcement and zero-touch deployment for every endpoint
- Help desk and onsite support for security, servers and the network, plus a 24×7 on-call engineer
- Your team keeps user tickets, administrative rights and day-to-day decisions
- Shared ticket portal, monitoring console and documentation your team can work in
- Quarterly business review and vCIO planning alongside your IT lead
- Microsoft 365 security baseline maintained by TSR, with drift reported to your team
What it does not do
- User help desk. Your team owns tier-1 tickets; TSR's help desk covers security, servers and the network and takes escalations.
- Day-to-day administrative decisions. Your team keeps admin control; TSR maintains the security baseline and flags drift rather than overriding it.
- Incident remediation beyond the immediate response, which is time and materials per the TSR Services Guide.
- Migration projects, which are scoped and quoted separately.
Services with this package
Included in the rate
Co-managed IT
TSR works alongside your in-house IT team through the Co-Managed Guardian package: your people keep the front line, we add the platform, the security operations and the after-hours cover.
Learn moreManaged SOC
A staffed security operations center that watches your endpoints, network and cloud around the clock and acts when something is wrong.
Learn morevCIO
A TSR executive who owns your technology roadmap, budget and vendor relationships, for businesses that need a CIO's judgement but not a full-time CIO.
Learn moreIT stack assessment
A 123-point review of your technology, from servers to spend, that tells you what to fix, what to keep and what to stop paying for.
Learn moreAvailable as add-ons
Pentest
A scoped, human-led attack on your network, web applications and APIs so you find the gaps before someone else does.
Learn moreWeb app pentest
An OWASP-based, manual test of your web application or API, with a report your developers can act on within days.
Learn morevCISO
Security leadership on a monthly retainer for businesses that need a CISO's judgement without a CISO's salary.
Learn moreCompliance assessment
A gap analysis of your policies and controls against HIPAA, PCI DSS, SOC 2, ISO 27001, GDPR or CMMC, with a plan to close what is missing.
Learn moreCyber posture assessment
A one-time review of your technical and operational security that tells you what to fix first and why.
Learn morePrivate cloud
Dedicated virtual servers on hardware nobody else shares, sized to your workloads and managed by TSR.
Learn morePublic cloud
Move workloads to the public cloud, or run a mix of cloud and on-premises, with TSR planning the move and managing what follows.
Learn moreColocation
Rack your own servers in a Tier III data center with redundant power, cooling and carriers, instead of a closet at the office.
Learn moreVoIP
A cloud phone system with auto-attendant, call routing, voicemail-to-email and video meetings, sized to your users and locations.
Learn moreAI solutions
Practical AI and automation for your business, from a readiness assessment through a pilot to a system your team actually uses.
Learn moreWhat happens after you sign
Billing starts when the last workstream closes, not when the contract is signed.
1.Week 1
Discovery and the ownership split
We document the environment with your IT lead and agree, in writing, who owns tickets, admin rights, patch approval, vendor calls and after-hours. The default is that your team keeps tier-1 and admin and TSR takes security, servers, network and escalations. Device and user counts are reconciled so the billable number is agreed, not assumed.
2.Weeks 2–3
Endpoint security cutover
TSR onboards Defender for Business through Intune and deploys the detection agent; your team keeps its admin access and sees everything in the same console. Legacy antivirus is removed only after Defender is confirmed active on each device, and a test detection proves that alerts reach TSR.
3.Weeks 3–4
SIEM and DNS filtering enablement
Monitoring scope is agreed with your team, log sources are onboarded and forwarding verified, and DNS filtering rolls out with an initial policy your team can request changes to through the portal.
4.Weeks 4–5
Identity consolidation
TSR reviews the Entra ID baseline and proposes the changes; your team approves them and keeps global admin. MFA and Conditional Access are enforced, self-service password reset is enabled, and any standalone MFA product is retired once seats match headcount.
Built on
- MicrosoftMicrosoft 365, Entra ID, Intune and Defender for Business
- Blackpoint Cyber24×7 managed detection and response
- NinjaOneEndpoint monitoring, patching and remote support
- AutoElevatePrivilege management
- HuduDocumentation and credential vaulting
- Phin SecuritySecurity awareness training and phishing simulation
Co-Managed Guardian questions
How is the split decided?
At kickoff we write down who owns what: tickets, admin rights, patch approval, vendor calls and after-hours. The default is that your team keeps tier-1 and admin, and TSR takes security, servers, network and escalations.
Does our team get access to TSR's tools?
Yes. Your team works in the same ticket portal, monitoring console and documentation system as TSR's engineers, with access scoped to your environment.
What if our IT person is on leave?
TSR can cover tier-1 for an agreed period at the hourly rate in the TSR Services Guide, and the on-call engineer is already in place for after-hours.
Can we move to full Guardian later?
Yes. The platform is identical, so the change is a contract update and a help desk handover rather than a new onboarding.
Request a Co-Managed Guardian quote
User count, locations and whether you have IT staff today is enough for a first number. An engineer replies within one business day.
Prefer to talk? Call 262-292-2000.
The form is not available right now.
Email sales@tsrsolutions.com or call 262-292-2000 and an engineer replies within one business day.