Service lines
All servicesSecurity Governance & Engineering
SGE
Strategy, governance, and security engineering delivered as one operating function.
Managed Threat Response
MTR
Coordinated detection and response across endpoint, identity, email, cloud, and network environments.
Threat Exposure Management
TEM
Continuous discovery of managed and unmanaged devices, with operating system and application vulnerabilities tracked through remediation.
Regulated Enclave
ENC
Monitoring, response, security engineering, and compliance support for a CMMC enclave.
Cyber Due Diligence
CDD
Pre-close and post-close cyber assessment of acquisition targets.
Sell-Side Transaction Readiness
SSR
Preparing your company’s security program and IT documentation for sale, with support through buyer diligence and closing.
Sectors served
Private equity
Manufacturing
E-commerce
Automotive
Advertising
Healthcare
Veterinary care
Apparel
Transportation
Home services
Industrial services
Your environment, supported by MITG
Build on your existing platforms
MITG uses your existing security platforms where they meet service requirements. TEM includes a discovery platform provided and operated by MITG.
Your tenant
Work is performed inside your own environment.
Your data
You retain ownership of your telemetry, configurations, and tuning.
Why MITG
| MITG | Build in-house | Other providers: what to verify |
|
|---|---|---|---|
| Scope | Governance, security engineering, threat response, and exposure management coordinated as one program. | Staff the required leadership, governance, engineering, and operations capabilities, or supplement them with outside services. | Which functions are delivered together, and which require separate services or providers? |
| Fit with your team | Works under your existing security leader, or provides leadership through MITG’s CISO office when needed. | Define the leadership structure, recruit the necessary roles, and manage the team. | Will the provider execute under your security leader’s direction, provide leadership where needed, or only deliver a defined operational service? |
| Coverage hours | Tuned automation investigates and contains at all hours. MITG analysts review every automated action. Analysts and engineers are staffed through extended weekday hours and on call at other times. | Plan staffing, shifts, and on-call or external support for the coverage required. | What is automated, what receives human review, and what human staffing and response commitments apply outside business hours? |
| Incident response | Hands-on containment and remediation with no separate retainer. No hour caps for clients running both Security Governance & Engineering and Managed Threat Response. | Maintain the skills and capacity to investigate and respond; arrange outside expertise where needed. | Does the service stop at notification or containment? Are investigation, remediation, retainers, and response hours included? |
| Remediation follow-through | A shared register tracks findings, owners, target dates, and progress. MITG reviews progress weekly and coordinates follow-up through resolution. | Assign and manage remediation ownership, cross-team dependencies, progress tracking, and closure. | Who tracks findings after an alert or report, coordinates with IT, and follows through to resolution? |
| Continuity and direct access | A dedicated Service Lead, a second senior leader, and the wider MITG team. Direct access to the practitioners doing the work. | Build backup coverage and retain knowledge through hiring, documentation, and cross-training. | Is delivery backed by named accountable roles and practitioner access? What happens when the primary contact is unavailable? |
| Time to value | Onboarding begins at signature without a recruiting cycle. Monitoring starts before the initial security baseline is complete. | Recruit and onboard the required roles, then establish the operating processes and coverage. | When does monitoring start, and when do engineering, governance, and other contracted capabilities become operational? |
| Compliance and audit | Compliance assessment and remediation oversight, tabletop exercises, insurer questionnaires, and control evidence through Security Governance & Engineering. | Maintain the necessary framework expertise and capacity for evidence, reviews, and follow-up. | Which compliance and audit activities are included, and which require another service or separate fees? |
| Your tooling and work products | Works in your environment and uses existing platforms where they meet requirements. TEM includes a discovery platform. You retain ownership of work products, configurations, and telemetry. | Select, license, integrate, operate, and maintain the tools; retain the work products in your environment. | Who owns the tenant, configurations, telemetry, and work products? What remains available if the engagement ends? |
| Cost and predictability | Recurring services priced by user and asset counts. Monthly or annual billing; terms start at 12 months. Counts adjust quarterly, up or down; rates are fixed for the contracted term. | Budget for salaries, benefits, recruiting, training, management, tooling, and any outside specialist support. | Compare the full scope and pricing basis, including engineering, response hours, compliance support, retainers, and additional charges. |
The table describes the full MITG program; delivery follows the service lines in scope. Alternative delivery models vary by team, provider, and contract. Compliance and audit support is delivered under Security Governance & Engineering. Response with no separate retainer and no hour caps applies to clients running both Security Governance & Engineering and Managed Threat Response. Transaction services are priced per engagement.
The team behind the program
Every engagement is led by a dedicated Service Lead, backed by a second senior leader and specialists across architecture, governance, engineering, threat analysis, and incident response. All are US-based, full-time MITG employees.
Request an introduction
MITG has operated as its clients’ security organization since 2006.