TSR Solutions Managed IT & security

Sentinel

Everything in Guardian, plus vCISO leadership, compliance tooling and the security add-ons included as standard.

Who it is for

Organisations with a regulator, auditor, insurer or customer that expects evidence of a security programme, not just controls.

Sentinel is for a business that has to prove its security posture, not just have one. It includes everything in Guardian, then adds vCISO leadership, a compliance assessment and management platform, an incident response platform with tabletop exercises, semi-annual disaster recovery testing and Microsoft 365 data loss prevention. Controls that are add-ons under Guardian — zero trust application control, a password vault, SASE, custom mobile device policies — are included. Scope is set per engagement because no two compliance obligations look the same.

Inside the rate

  • Everything in Guardian: monitoring, patching, help desk, identity, 24×7 detection and response
  • vCISO leadership that owns the security programme and speaks to your auditor
  • Compliance assessment and management platform with continuous evidence collection
  • Incident response plan, hosted response platform and tabletop exercises
  • Disaster recovery testing twice a year, with results documented
  • Microsoft 365 data loss prevention policies configured and reviewed
  • Zero trust application control, password vault, SASE and mobile device policies included
  • Backup and disaster recovery as a service for servers and workstations included

What it does not do

  • The certificate itself. Sentinel builds and runs the programme and gathers the evidence; the audit opinion and any certification come from your assessor.
  • Incident remediation beyond the immediate response. The same boundary as Guardian applies; cleanup is time and materials.
  • Custom software development or secure code review of your own applications.
  • Migration projects, which are scoped and quoted separately.

Services with this package

Included in the rate

Available as add-ons

What happens after you sign

Billing starts when the last workstream closes, not when the contract is signed.

  1. 1.Week 1

    Discovery and scoping

    We learn how your business runs before we touch anything. Engineers document the network, inventory every device and account, review the current backup and security posture, and note any compliance obligations. The device and user counts we agree here are the counts you are billed on.

  2. 2.Weeks 2–3

    Endpoint security cutover

    Defender for Business is onboarded through Intune to the TSR baseline and the detection agent is deployed to every device. Legacy antivirus is removed only after Defender is confirmed active on that machine, and alert routing into TSR is proven with a test detection before we rely on it.

  3. 3.Weeks 3–4

    SIEM and DNS filtering enablement

    We agree which devices and network segments are monitored, then onboard the log sources and verify that logs are leaving each machine. DNS filtering rolls out with an initial category and threat policy that follows laptops off the office network.

  4. 4.Weeks 4–5

    Identity consolidation

    We check the Entra ID baseline for MFA coverage, Conditional Access and self-service password reset, close the gaps, and retire any standalone MFA product once its seats are reconciled to headcount. Inactive licensed accounts are dealt with so you stop paying for people who have left.

Built on

  • MicrosoftMicrosoft 365, Entra ID, Intune and Defender for Business
  • Blackpoint Cyber24×7 managed detection and response
  • NinjaOneEndpoint monitoring, patching and remote support
  • AutoElevatePrivilege management
  • HuduDocumentation and credential vaulting
  • Phin SecuritySecurity awareness training and phishing simulation

Sentinel questions

Which frameworks does Sentinel support?

The ones Wisconsin businesses most often meet: HIPAA, SOC 2, CMMC and NIST CSF, plus cyber-insurance questionnaires. The compliance platform maps controls to whichever framework applies and tracks evidence against it.

Is a vCISO the same as a vCIO?

No. The vCIO plans your technology and budget. The vCISO owns the security programme, its policies and its risk register, and represents it to auditors and insurers. Sentinel includes both.

Why is Sentinel quoted rather than priced per user?

Compliance scope varies with the framework, the number of systems in scope and how much evidence already exists. TSR scopes it after a discovery call so the rate reflects the actual work.

Can we start on Guardian and move to Sentinel?

Yes. Sentinel is Guardian plus the governance layer, so the technical platform is already in place. The upgrade adds the vCISO, the compliance and incident response platforms and DR testing.

Request a Sentinel quote

User count, locations and whether you have IT staff today is enough for a first number. An engineer replies within one business day.

Prefer to talk? Call 262-292-2000.