Skip to content
3PS
CRITICAL RESPONSE TALK TO 3PS
3PS LOCK / 3PS

CONNECT THE CONTROLS.
OWN THE STACK.

3PS Lock connects security tools to the people responsible for managing them. The annual engagement defines technical ownership, escalation, and reporting; the separately scoped stack supplies the agreed controls.

500+ customers served.
Backed by 100+ professionals and technical resources across our delivery network.

THE SECURITY STACK

One operating model across the controls.

Keep suitable existing tools or source missing coverage through 3PS. The scope connects alerts, policy changes, vendor support, and recovery to the business environment.

Endpoint and email

Manage endpoint protection and email filtering together so phishing, malware, user risk, and containment responsibilities are coordinated.

Identity and Microsoft 365

Review Secure Score, risky sign-ins and users, conditional access, mailbox rules, MFA exceptions, mail flow, privileged access, and session controls.

Servers and workloads

Prioritize domain controllers, backup servers, file shares, and clinical or production applications according to their business dependencies.

Network and firewall

Review firewalls, switching, wireless, remote access, segmentation, DNS, and exposed services around the access and movement paths they permit.

Execution control

Scope allowlisting, ringfencing, PowerShell and script controls, and policy exceptions where the operating requirements support tighter execution controls.

Backup and recovery evidence

Connect backup integrity, restore checks, recovery order, and application validation with the security program.

THE WORK IN MOTION

Controls need an operating team.

RESPONSIBILITY ACROSS THE STACK

Close the gaps between the tools.

An endpoint alert, a stolen identity session, a firewall change, and a backup decision may belong to different consoles. They still need one coordinated response.

Connect the signals

Bring email, identity, endpoint, network, backup, vendor, and business context into the investigation.

Define authority before action

Establish who can revoke sessions, isolate hosts, block indicators, change policies, and approve recovery work.

Keep the response record

Track observed facts, actions, open questions, validation, and the next owner. A deployed product is not evidence that each responsibility is covered.

STACK PLANNING FIGURES

Technical ownership and tool costs are separate.

3PS Lock is scoped above an annual 3PS engagement. The final quote accounts for existing licenses, products, device and user counts, response requirements, and the systems in scope.

Annual engagement

Readiness starts at $5,000/month with an annual commitment from $60,000/year. The agreement defines the people, work, review cadence, and escalation responsibilities.

Endpoints and users: $17/month

Planning figure for a standard 3PS-sourced endpoint protection and email filtering bundle. A 25-user minimum applies; count endpoints or users, whichever is higher. Product tier, volume, and existing licenses affect the quote.

Servers: $25/server/month

Planning figure for protected server workloads, visibility, and the agreed management scope. Critical-system responsibilities are defined separately.

Switches and APs: $15/device/month

Planning figure for visibility and management of switches and access points across the locations in scope.

Firewalls: $125/firewall/month

Planning figure for firewall management, review, change awareness, and exposure-control work.

Execution control: scoped

Allowlisting, ringfencing, and script controls are quoted around the required policies, exceptions, and rollout.

Stack charges are monthly and additional to the annual engagement. The quote confirms MDR, archiving, DLP, advanced identity, compliance requirements, existing licenses, volume, and any resulting changes to the planning figures.

EXISTING OR 3PS-SOURCED TOOLS

Keep the tools that fit the environment.

Supported technology discussions

Bring the Microsoft Defender, Entra, Microsoft 365, CrowdStrike, SentinelOne, Bitdefender, Huntress, Darktrace, Proofpoint, Mimecast, Barracuda, Veeam, Datto, Fortinet, Meraki, UniFi, or comparable products in your environment. Compatibility, licensing, and support are confirmed for the proposed stack.

Bring your own tools

Define administrative access, alert and log access, vendor support, renewal visibility, and authority to tune policies before assigning operating responsibility.

Source the missing coverage

3PS can source tools where the existing stack is incomplete, expired, noisy, or unsuitable. Product and licensing costs are quoted separately from technical ownership.

ROLLOUT AND CONTINUING REVIEW

Start with the systems that matter most.

  1. 01

    Establish the baseline

    Document users, endpoints, servers, firewalls, switches, wireless, Microsoft 365, backups, vendors, and critical workflows.

  2. 02

    Prioritize the failure paths

    Review phishing, ransomware, failed restores, exposed remote access, identity abuse, vendor dependencies, and business application risks.

  3. 03

    Implement the agreed controls

    Keep suitable tools, replace gaps, configure policies, and validate the resulting access, visibility, and response paths.

  4. 04

    Review the monthly picture

    Report changes, relevant security activity, outstanding work, and investment priorities within the agreed reporting scope.

Bring rough user, endpoint, server, network-device and firewall counts, existing licenses, and the systems most important to the business. Coverage, policies, change authority, implementation, and commercial terms are agreed before rollout.

STRATEGY THROUGH OPERATIONS

LET’S DEFINE
THE NEXT MOVE.

Bring the objective, the environment, and what needs to change. We will connect the right disciplines around a defined engagement.

DISCUSS YOUR SECURITY STACK