Under attack right now? Active incident line — +1 480-999-0030 · Report an incident

Services · Statement of coverage

Everything a security department does, scoped in writing.

Each engagement is scoped in writing, delivered by a certified practitioner, and documented like the audit deliverable it often is. Here's what we cover.

SVC-MSS

Managed security services

Panthryx as your ongoing security department, for firms that need real expertise without an internal department.

Full details →

  • Google Workspace, Microsoft 365 & Entra ID
    hardening and administration
  • Conditional access design and enforcement
  • Identity and email threat monitoring
  • Password manager deployment and rollout
  • An expert who already knows your environment
SVC-IR

Incident response & forensics

Business email compromise, ransomware, and account takeover, handled end to end: containment first, evidence always, and a clear account of what happened and what information was exposed.

Full details →

  • Immediate containment of compromised accounts
  • Google Workspace and Microsoft 365 forensic timeline:
    sign-ins, rules, OAuth grants
  • Evidence preservation suitable for counsel and insurers
  • Root-cause findings and a written incident report
  • Ransomware containment and recovery coordination
  • DDoS resilience guidance and implementation
    for public-facing platforms
  • Post-incident hardening
SVC-RA

Comprehensive risk assessment

The starting point for most engagements: a full picture of your technology, organization, and exposure, with recommendations you own.

Full details →

  • Infrastructure and platform documentation
  • Roles, responsibilities, and access review
  • Vulnerability and risk analysis
  • Prioritized, plain-language recommendations
SVC-AUD

Auditing & compliance

Independent assessment and attestation led by a CISA-certified auditor, with documentation that stands up to review.

Full details →

  • Gap assessments and readiness programs
  • Policy and procedure development
  • Periodic auditing for ongoing compliance
NIST CSFISO 27001/27002HIPAAPCI DSSSOC 2CAIQ
SVC-RDY

Readiness & awareness

Your people are the widest attack surface. We prepare your people and your recovery plans before they're tested for real.

Full details →

  • Security awareness education and training
  • Phishing simulation exercises for your organization
  • Business continuity and disaster recovery planning
  • Tabletop exercises and incident rehearsal

Not sure where to start?

Start with the assessment. Keep the findings either way.

The risk assessment stands on its own: you get the documentation and recommendations whether or not you engage us for anything else.