Managed Security · Fractional security team

Your security team. Without the headcount.

A full security function — engineering, monitoring, and response — delivered as a monthly block of specialist hours, scoped to your actual risk. For companies that need real security depth but cannot yet justify hiring a full in-house team.

50 · 100 · 150+
Specialist hours per month, matched to your risk profile
Audit-first
We assess before we recommend a block — no blind commitment
Engineering-led
Built and run by senior security engineers, not resold monitoring

You need a security team. You cannot yet hire one.

01

Hiring is slow and expensive

A single senior security engineer is a six-figure cost and months of recruiting. A full function — SOC, identity, vulnerability, response — is several hires you cannot make at once.

02

Your risk does not wait

Identity compromise, unpatched exposure, and unmonitored endpoints are live today. Regulated buyers and partners ask for security maturity before you have built it.

03

Tools are not a team

Buying an EDR or a GRC platform gives you software, not judgment. Someone senior still has to engineer detections, triage alerts, and decide what matters.

Start with an assessment. Then the right block of hours.

Step 02

Your recommended block

Monthly · 50 / 100 / 150+ hours

The roadmap becomes the plan. We recommend a monthly block of specialist hours, spent where your risk is highest — detection engineering one month, identity hardening the next. Not a fixed checklist.

Step 03

Ongoing security function

Continuous · Reviewed quarterly

Monitoring, response, hardening, and evidence — delivered every month, reported transparently. A re-assessment each year refreshes the roadmap and shows how far your posture has moved.

A complete function, drawn down as you need it.

01

Fractional Security Lead

Strategy · Roadmap · Buyer Security Questionnaires

Senior security leadership without a full-time hire. We own the roadmap, set priorities, and stand behind you in the security reviews your enterprise prospects and partners run before they sign.

  • Security program strategy and quarterly roadmap
  • Vendor and third-party risk oversight
  • Security questionnaire and due-diligence support
02

Detection & Response

MDR · Detection Engineering · MITRE ATT&CK

Threat detection and response built on engineered detection coverage — not resold alert monitoring. We write and version detection logic, triage what matters, and act on confirmed threats.

  • Monitoring with detection coverage mapped to MITRE ATT&CK
  • Alert triage and confirmed-threat response
  • Incident-readiness runbooks and escalation paths
03

Identity & Access

IAM · Lifecycle Automation · Access Reviews

The place most breaches begin. We automate the identity lifecycle so provisioning and offboarding take minutes, and orphan accounts and privilege creep stop accumulating.

  • RBAC across Okta, Google Workspace, Microsoft 365
  • Provisioning and deprovisioning automation
  • Periodic access reviews with audit-ready trails
04

Vulnerability Management

Assessment · Prioritization · Remediation Guidance

Continuous visibility into where you are exposed, with the noise filtered out. We scan, validate findings, and hand your team a prioritized remediation plan tied to real business risk.

  • Recurring vulnerability assessment cycles
  • Validated, deduplicated findings — not raw scanner output
  • Prioritized remediation guidance and tracking
05

Audit-Readiness & Evidence

DORA · GDPR · ISO 27001 · Evidence Automation

We implement the security controls regulated frameworks expect, and automate the evidence your auditors ask for — produced continuously, not assembled the week before an audit.

  • Control implementation aligned to DORA Art. 6-8 and ISO 27001
  • Continuous evidence pipelines for your audit window
  • Your compliance function and auditors attest — we build the controls and the evidence
06

Hardening & Awareness

Endpoint Hardening · Phishing Simulation · DLP

The hygiene layer that quietly closes the most common entry points: managed endpoint protection, configuration hardening, and human-risk reduction run as an ongoing program.

  • Managed endpoint detection and configuration hardening
  • Phishing simulation and awareness, designed to respect EU data rules
  • Data-protection (DLP) policy configuration and tuning

Three blocks. The assessment recommends yours.

Foundation
Small teams establishing a security baseline.
50 specialist hours / mo
Starting at€8,000 / mo
12-month engagement · billed monthly
  • Monitoring with engineered detection coverage
  • Monthly configuration hardening
  • Recurring vulnerability assessment
  • Identity hygiene and access reviews
  • Monthly posture report + review call
  • Business-hours support
Book your assessment
Scale
Organisations that need a near-complete security function.
150+ specialist hours / mo
TailoredCustom
Scoped to your environment
  • Everything in Operate, plus
  • Dedicated lead engineer
  • Roadmap and program ownership
  • Fastest response SLA tier
  • On-demand access to the team
  • Bridge into bespoke engineering projects
Talk to us

Visible work. No black box.

REPORT

Posture report

A monthly report showing what we did, what changed, and how your risk posture moved over time.

VISIBILITY

Shared visibility

You see what we see. Findings, actions, and open items tracked transparently, not hidden behind a service desk.

SLA

Defined response

A response-time SLA stated for your tier, so you know what happens when something needs a human decision.

REVIEW

Roadmap reviews

Regular reviews and an annual re-assessment that re-scores your maturity and refreshes the plan.

What we run. Where your compliance function leads.

WingsGRC delivers

  • Security engineering, monitoring, and response
  • Identity, detection, vulnerability, and hardening programs
  • Control implementation aligned to DORA, GDPR, and ISO 27001 requirements
  • Continuous, audit-ready evidence as a system output

Stays with your compliance and legal partners

  • Regulatory interpretation and legal advice
  • Compliance attestation and audit sign-off
  • Formal conformity assessments
  • Commodity L1 alert monitoring resold without detection engineering

We are a security engineering team. We implement controls and prepare evidence; your compliance function and independent auditors attest.

Start with the assessment.

A focused 30-minute call first. No slides, no sales pitch — a discussion of what you are trying to protect and whether a managed block is the right fit. If it is, the assessment scopes exactly how many hours your risk warrants. We work with a limited number of organisations at a time.

Email [email protected]
Based in Holland, Amsterdam · Available globally
Response time Within 24 hours