Co-Managed
Security
Managed Nerds · Service

Keep your IT.
We'll cover security.

Co-managed Huntress for teams under 50.

24/7 threat detection and response from Huntress, managed by us. When something goes wrong at 2am, we take the call and handle it so you don't have to wake up. Built for businesses under 50 employees that already have IT help.

The Problem

Good IT isn't the same as good security.

Your IT person keeps the lights on. They set up laptops, fix email, and get the printer talking again. That's a full-time job.

Security is a different job. Attackers don't break in at 2pm on a Tuesday while someone's watching. They log in with a stolen password at 3am, set up an email forwarding rule, and wait for an invoice to come through. Catching that takes people watching around the clock and knowing what "normal" looks like.

Most small businesses don't have that. And the ones who try to buy enterprise security tools directly run into a wall pretty fast.

By the numbers

Small business is where ransomware lands.

88%

of breaches at small and mid-sized businesses involved ransomware, compared with 39% at large organizations.

Source: Verizon 2025 DBIR SMB snapshot (PDF) →
~1 in 3

hacking-related breaches at small businesses came down to stolen credentials, making it one of the top ways in.

Source: Verizon 2025 DBIR SMB snapshot (PDF) →
277%

year-over-year jump in attackers abusing remote access tools, the same ones IT people use every day.

Source: Huntress 2026 Cyber Threat Report →
Why not just buy it yourself?

Enterprise security has a minimum order.

Huntress is one of the best-regarded security platforms for small businesses. But if you buy it directly, Huntress requires at least 50 seats per product. A 15-person office can't get in the door.

Even if you could, buying the software is the easy part. Huntress's own pricing page says it straight: the direct price doesn't include deployment, integration, or acting on what their security team sends over. When their analysts find something at 3am, the report lands in someone's inbox with a list of things to do. Somebody has to do them.

That's the gap we fill. Through us, there's no seat minimum. And we're the somebody, even at 3am.

Source: Huntress pricing, seat minimums and what's not included →
Which path fits you?
Under 50 people

Co-managed Huntress through us. No minimums. We run it, we take the alerts, we handle the response.

Contact Us
50+ people, buying direct

You're big enough to go straight to Huntress. Start with their free trial.

Start a Huntress trial ↗
50+ people, buying through a reseller

Want to run Huntress in-house but buy it through a partner? We're an authorized Huntress reseller.

Ask Us to Be Your Reseller
What's covered

Five layers. One team watching them.

Endpoint protection

Huntress Co-Managed EDR

Every computer and server gets a lightweight agent that watches for how attackers actually behave: hiding tools that survive a reboot, moving between machines, or starting to encrypt files. Huntress analysts investigate around the clock. If a machine is compromised, it gets cut off the network in minutes, and we handle the cleanup, day or night. Microsoft Defender antivirus is managed too, at no extra cost.

Login and email protection

Huntress Co-Managed ITDR

Most breaches now start with a stolen login, not a virus. This watches your Microsoft 365 or Google Workspace accounts for logins from places your people have never been, stolen sessions that skip past MFA, sneaky inbox forwarding rules, and shady apps someone clicked "Allow" on. When it finds a compromised account, the attacker gets kicked out and the account gets locked, fast. Then we sort out what they touched.

Microsoft 365 hardening

Huntress Co-Managed ISPM

Microsoft 365 ships with a lot of security settings turned off. This turns on a hardened set of settings based on the CIS benchmark (things like blocking old login methods and requiring MFA everywhere), tests them first so nothing breaks, and puts them back if anyone changes them. We handle the exceptions and the "why can't I log in" calls. Microsoft 365 only for now, and it works best on Business Premium.

Security awareness training

Huntress Co-Managed SAT

Short, animated episodes your team will actually finish, plus practice phishing emails so they learn what the real ones look like. People who click get quick coaching on the spot. Completion and phishing-test results get tracked, so there's something to show your insurance carrier or auditor when they ask. Compliance tracks are available for PCI, NIST 800-171, and more.

Log monitoring and retention

Huntress Co-Managed SIEM

Your computers, firewall, and cloud accounts all keep logs. Most businesses never look at them until something goes wrong, and by then they're gone. This pulls the security-relevant logs into one place, keeps them for a year or longer, and has analysts watching them for signs of an attack. When an auditor, insurance carrier, or investigation asks for records, they're there.

Who does what

You keep your IT. Here's the split.

Your IT person or provider
  • Day-to-day support: laptops, printers, passwords
  • New hires, software installs, network gear
  • Microsoft 365 or Google Workspace admin
  • Backups
Managed Nerds
  • Deploy and manage Huntress and our remote management agent on every device
  • Take the call on every Huntress alert, 24/7, including 2am
  • Triage, isolate, and remediate so you don't have to wake up
  • Microsoft 365 hardening, exceptions, and drift
  • Log collection and retention
  • Security training setup and reporting
  • Incident advisor: what happened, what to do, who to call
  • Plain-English security reporting, pulled whenever you need it

If your IT provider is a company, we'll work with them directly. We're not trying to take their job. If you'd rather hand off everything, our IT support service covers the day-to-day too.

When something goes wrong

The alert goes off. Then what?

  1. Huntress catches it.

    Their analysts confirm it's real and flag it.

  2. We take the call.

    Day or night, 2am included. Our team picks up the phone, not you.

  3. We triage and contain it.

    We isolate the affected computer or lock the compromised account and stop the attacker's access.

  4. We clean it up.

    Password resets, MFA re-registration, removing what the attacker left behind, and checking who else got hit.

  5. You wake up to a plain-English summary.

    What happened, what we did, and anything you need to decide. Not a ticket number and a to-do list.

  6. We help you with the hard calls.

    Does your cyber insurance need to be notified? Do you need an outside forensics firm? Are there notification obligations for customer data? We help you figure out who to call and in what order. (We're not attorneys, so anything with a legal deadline gets confirmed with your counsel.)

  7. We close the gap.

    Whatever let them in gets fixed so it doesn't happen twice.

Nobody plans for a breach. But you can plan who picks up the phone at 2am. That's us.

Need licenses too? We can handle that.

Co-managed clients can also buy their other business software licenses through us, so it's one less vendor and one less bill to track. (Your IT person keeps managing them.)

Microsoft 365 licensingGoogle Workspace licensingAdobeNinjaOne backups
Who this is for

A good fit if this sounds like you.

Good fit
  • Under 50 employees
  • You have IT help already and want to keep it
  • Your cyber insurance, a client, or a regulation is asking about EDR, MFA, log retention, or training
  • You want a real person to call if something goes wrong
Probably not a fit
  • You need someone for everyday IT support too. That's IT Support.
  • You have 50+ people and your own security team
How it works

Protected in about two weeks.

01
Reach out
Fill out the contact form. We follow up to learn what you have, who handles IT, and what you're worried about.
Day 1
02
Setup
We install the Huntress agent and our remote management agent on every device, set up a dedicated break-glass admin account in your Microsoft 365 or Google Workspace, connect your log sources, and start Microsoft 365 hardening in test mode so nothing breaks.
Week 1
03
Lock it down
Hardening goes live, training kicks off, and we walk you and your IT person through what happens if an alert fires.
Week 2
04
Ongoing
24/7 monitoring and incident response, plus a plain-English security report whenever you want one.
Ongoing
FAQ

Questions we get a lot.

What does "co-managed" mean?

You keep whoever handles your everyday IT. We take ownership of your security tools and incident response. We work alongside your IT person or provider, not instead of them.

Is there a long-term contract?

No. It's month-to-month.

How much does it cost?

It depends on how many people and devices you have. Pricing is flat and monthly with no seat minimums. Send us a message through the contact form and we'll give you a quote.

Can't I just buy Huntress myself?

If you have 50 or more seats per product, yes. You can start a free trial directly with Huntress, or buy through us as your authorized Huntress reseller. Either way, your team deploys it and acts on what their security team sends. Under 50 seats, Huntress requires going through a partner like us, and we do that work for you.

Can I buy other software through you?

Yes. Co-managed clients can buy Microsoft 365, Google Workspace, Adobe, and NinjaOne backups through us. We sell the licenses; your IT person keeps managing those tools. Our co-management covers Huntress only. Handy if you need a Microsoft 365 Business Premium upgrade to get the full Microsoft 365 hardening.

Do you co-manage Huntress SIEM?

Yes. We connect your log sources, act on anything the security team flags, and pull records when an auditor or insurance carrier asks.

Do I have to switch IT providers?

No. That's the point. If you ever want full IT support too, we offer that, but it's not required.

What do you need access to?

Two things.

On your computers and servers: we install two small agents, the Huntress agent and our remote management agent. Huntress can spot an attack and cut a computer off the network, but some cleanup has to be done hands-on, like undoing changes the attacker made, removing software, or restarting the machine. Our remote management agent lets us do that right away, at 2am if needed, without anyone at your office touching the computer.

In your Microsoft 365 or Google Workspace: we need our own admin account. For Microsoft 365 that's a dedicated global admin "break-glass" account; for Google Workspace it's a super admin account. It's reserved for security work, so when an account gets compromised we can lock it down, reset it, and clean up after the attacker without waiting on anyone. It's also how we apply the Microsoft 365 hardening settings.

We'll coordinate the setup with your IT person.

Why do you need your own remote management agent if Huntress is already installed?

Huntress finds and contains the threat. Fully cleaning it up sometimes takes hands-on work on the machine. Our agent is how we do that remotely and fast, so a compromised laptop doesn't sit isolated until someone's in the office.

Will this slow down our computers?

Both agents are lightweight. Most people never notice they're there.

What Microsoft 365 license do I need?

Login monitoring works on any Microsoft 365 or Google Workspace plan. For the full Microsoft 365 hardening, Business Premium (or a plan with Entra ID P1) is recommended, because some of the most important security settings require it. We'll tell you if an upgrade is worth it.

Do you support Google Workspace?

Yes for login and email monitoring, endpoint protection, and training. Microsoft 365 hardening is Microsoft-only for now.

Does this replace my antivirus?

It works with Microsoft Defender, which is built into Windows, and Huntress manages Defender for you at no extra cost. If you're paying for a separate antivirus, we'll talk about whether you still need it.

What happens if you find something at 2am?

We take the call. When Huntress flags something after hours, our team triages it and takes action: isolating the computer, locking the compromised account, and cleaning up. You don't have to wake up. In the morning you get a plain-English rundown of what happened and what we did.

Will this help with cyber insurance?

Many cyber insurance applications ask about endpoint detection and response, MFA, and security training. This covers all three, and we can give you documentation for your application. Your carrier makes the final call on coverage.

Is this HIPAA, PCI, or CMMC compliant?

No tool makes you compliant by itself. This service covers several common requirements (monitoring, MFA enforcement, training, incident response) and gives you records to show for it. We'll talk through what your specific requirements need.

What happens if we cancel?

It's month-to-month, so you can stop anytime. We'll remove the agents and disconnect your accounts. Microsoft 365 hardening settings stay in place, so you keep the protection.

Month-to-month · No seat minimums
Your IT's handled.
Let's handle security.

Send us a message through the form. We'll look at what you have, tell you where the gaps are, and give you a straight answer on whether this makes sense for you.

Contact Us →