MITG
How we work

From signature to steady state

Onboarding begins at signature with discovery of your environment. MITG connects to the platforms in scope, establishes a weekly review and a real-time escalation channel with your IT team, and completes an initial security baseline. Monitoring is operational before the baseline completes.

Swipe to see the full timeline
Signature
Baseline complete, steady state begins
Discovery
Scope set
Monitoring
Live, and ongoing
Weekly review & escalation channel
Weekly, with your IT team
Initial baseline
Baseline findings into the register

Timing depends on scope and on your IT team’s availability, and is set during discovery.

The Service Lead

Every engagement has a dedicated, accountable MITG Service Lead, confirmed in writing before work begins. The Service Lead is a certified practitioner from MITG’s CISO office, not an account manager, and the relationship is direct: the architects, engineers, and analysts in your environment are your points of contact.

Your environment stays yours

MITG delivers on platforms you already own, in your own environment, whether that is one tenant or many. Telemetry, configurations, and tuning remain yours.

Your providers can stay

Existing providers do not need to be removed for MITG to be accountable. Where providers are already in place, MITG works alongside them and coordinates their capabilities where appropriate: MITG brings your platforms, your providers, and your internal team into one accountable program.

How engagements are structured

Defined services, clear accountability, and a simple commercial structure: one master agreement, a schedule of your services and counts, and a service description for each service line in scope. Transaction services, such as diligence and sell-side work, are priced per engagement.

Schedule an introduction
Pricing basis Recurring managed services: users and assets.
True-up Quarterly, in either direction.
Rate protection Rates fixed for the contracted term.
Estimate A budgetary estimate follows an introductory call, based on your user and asset counts.

Incident response carries no separate retainer, and no hour caps for clients running both Security Governance & Engineering and Managed Threat Response. Work performed by third parties, such as carrier-assigned forensics and counsel, and the rebuilding of systems or restoration of data, sit outside the program. MITG coordinates that work.