Managed Cyber Protection is the service where Charter Technology Solutions owns the day to day security work: watching for threats, responding when one appears, training your staff, protecting your email, backing up your cloud, and finding the weak spots before someone else does.
CTS manages IT for Vermont Academy under the Total Care Package. That agreement covers day to day user support, the managed servers, the staff and student devices, the network and the internet connections across the Saxtons River campus, and offsite backup replication.
It does not carry a cyber program. Detection and response, security awareness training, advanced email protection and cloud backup of the Microsoft 365 tenant are a separate service, and neither Managed Cyber Protection nor Managed Cyber Advisory is part of what CTS provides to Vermont Academy today.
That is the whole reason for this page. Everything below describes the service itself, and what it would add on top of the support Vermont Academy already has. One distinction is worth naming early: Total Care covers student devices, while the cyber program is priced and delivered per staff account. Coverage of student accounts is a separate conversation rather than something either side should assume.
The slowest part of standing up a cyber program is usually the inventory: which devices are managed, who administers the tenant, how the network is laid out, what is already licensed.
At Vermont Academy all of that is already known, because CTS manages it. Scoping starts from a real picture rather than a questionnaire.
Most organizations already own some security tools. What they usually do not have is someone whose job it is to watch those tools at two in the morning, decide whether an alert is real, and act on it before it spreads.
That is what Managed Cyber Protection provides. CTS deploys the stack, monitors it continuously, investigates what it sees, and takes action on your behalf. You get a security operation without having to hire, staff, or run one.
For Vermont Academy it layers onto the support that is already running. The same people who manage the servers, the network and the devices would be working alongside a security operations team watching them, using access and inventory that already exist.
Four components, delivered as one program, priced per staff account and per campus at education rates.
A security operations center watching around the clock, 24 hours a day and 7 days a week. When something real is found it is investigated and contained, rather than forwarded to you as an alert.
This is the largest of the four, and it carries a set of things often sold separately:
Ongoing training for staff, with simulated phishing so the training is measured against real behavior rather than completion rates. Results are reported back to leadership.
A protection layer above what your mail platform does on its own, aimed at the attacks that get through: credential harvesting, impersonation of leadership, and invoice and payment fraud.
Independent backup of the data living in your Microsoft 365 or Google tenant, including mail, files and shared drives, so a deletion, a ransomware event or a departed account is recoverable.
Twenty five gigabytes of pooled storage per user is included, and more is available by the gigabyte.
Student accounts are outside it. The per-user program covers staff accounts. Protecting student accounts is a separate scoping conversation, not an assumption to make quietly on either side.
Digital forensics and incident response is not included. If an incident needs a formal forensic investigation, that is separate work. What the program does carry is the detection, the containment and the log history that a forensic investigation would start from.
Incident response planning is its own engagement. A written plan naming who decides, who is called, in what order and on what clock is a one time piece of work, listed with the other separately available components below.
The program starts with a scoped implementation, then settles into a recurring service.
Managed Cyber Protection is the operational half. Managed Cyber Advisory is the governance half. They are sold separately and many organizations take one before the other.
Managed Cyber Protection
Managed Cyber Advisory
The two are complementary rather than sequential. Advisory produces the written record that boards, auditors and cyber insurers ask for. Protection produces the monitoring and the response that closes what the record finds.
Every component can be bought on its own. The bundle exists because the pieces reinforce each other, not because they are locked together.
| Component | How it is counted |
|---|---|
| Managed Detection and Response, full | Per user |
| Managed Detection and Response, Core tier | Per user |
| Managed security awareness training | Per user |
| Managed advanced email protection | Per user |
| Outbound email protection and data loss prevention | Per user |
| Managed cloud backup | Per user, plus storage |
| SaaS management | Per user |
| Internal vulnerability management | Per asset |
| Internal vulnerability management, quarterly review | Per quarter |
| Extended security log retention beyond ninety days | Per month |
| Incident response plan development | One time |
Full against Core. Both carry the 24/7 security operations center, endpoint detection and response, cloud threat detection, and vulnerability management on workstations, servers and the external network. The Core tier drops the pieces that need equipment on your network or a place to keep history: local network threat monitoring, security log retention, DNS layer malware protection and lookalike domain monitoring. The full tier is what the program carries.
Components carry their own one time implementation where one applies. Current pricing for any line above is available from your CTS team.
Three conditions decide what is deliverable. Two of them are already met at Vermont Academy.
Detection and response on a laptop or desktop requires an agent on that machine. Staff and campus devices at Vermont Academy are already managed by CTS, so this condition is met. Any device outside that management, including personal machines, is outside endpoint coverage and we would rather say so now than have it found later.
Email protection, cloud backup and log retention attach to a tenant the school administers. That tenant is in place and under management, so this condition is met as well.
This is the open one. Schools are often already paying for a capability nobody turned on, and where that is true the right answer is configuration, not a second license. Scoping starts by reading what is deployed on the account today and subtracting it, which is work CTS can do before any quote exists.
Sachin Gujral, Chief Executive Officer, Charter Technology Solutions
Choosing between managed and professional services is really an ownership question: who owns IT after go live. A service owner closes the ticket when the user can work again, not when a response is sent.
Most security problems are ownership gaps rather than tooling gaps. An alert fired and nobody was assigned to read it. A backup existed and nobody verified it. A policy was written once and never reviewed.
Managed Cyber Protection is CTS taking ownership of that recurring work, with a named team and a reporting cadence, so the answer to who is watching is a person and not a product.