Charter Technology Solutions Vermont Academy
Prepared for Vermont Academy

Security operations, run for you, around the clock

Managed Cyber Protection is the service where Charter Technology Solutions owns the day to day security work: watching for threats, responding when one appears, training your staff, protecting your email, backing up your cloud, and finding the weak spots before someone else does.

Charter Technology Solutions  ·  Mission Critical IT  ·  charterts.com

Where this sits next to what CTS already runs

CTS manages IT for Vermont Academy under the Total Care Package. That agreement covers day to day user support, the managed servers, the staff and student devices, the network and the internet connections across the Saxtons River campus, and offsite backup replication.

It does not carry a cyber program. Detection and response, security awareness training, advanced email protection and cloud backup of the Microsoft 365 tenant are a separate service, and neither Managed Cyber Protection nor Managed Cyber Advisory is part of what CTS provides to Vermont Academy today.

That is the whole reason for this page. Everything below describes the service itself, and what it would add on top of the support Vermont Academy already has. One distinction is worth naming early: Total Care covers student devices, while the cyber program is priced and delivered per staff account. Coverage of student accounts is a separate conversation rather than something either side should assume.

Network switches, access points and managed laptops

The groundwork is already done

The slowest part of standing up a cyber program is usually the inventory: which devices are managed, who administers the tenant, how the network is laid out, what is already licensed.

At Vermont Academy all of that is already known, because CTS manages it. Scoping starts from a real picture rather than a questionnaire.

What the service is

Most organizations already own some security tools. What they usually do not have is someone whose job it is to watch those tools at two in the morning, decide whether an alert is real, and act on it before it spreads.

That is what Managed Cyber Protection provides. CTS deploys the stack, monitors it continuously, investigates what it sees, and takes action on your behalf. You get a security operation without having to hire, staff, or run one.

For Vermont Academy it layers onto the support that is already running. The same people who manage the servers, the network and the devices would be working alongside a security operations team watching them, using access and inventory that already exist.

What is included

Four components, delivered as one program, priced per staff account and per campus at education rates.

Managed Detection and Response

A security operations center watching around the clock, 24 hours a day and 7 days a week. When something real is found it is investigated and contained, rather than forwarded to you as an alert.

This is the largest of the four, and it carries a set of things often sold separately:

  • Endpoint detection and response on managed devices
  • Cloud threat detection and response
  • Network threat detection, with a site appliance for every 100 users
  • Vulnerability management across workstations, servers and the external network
  • Malware protection at the DNS layer, including remote filtering for Windows devices
  • Monitoring for lookalike domains registered against your name
  • Ninety days of security log retention, which is what makes it possible to answer how far an incident reached and when it started

Security awareness training

Ongoing training for staff, with simulated phishing so the training is measured against real behavior rather than completion rates. Results are reported back to leadership.

Advanced email protection

A protection layer above what your mail platform does on its own, aimed at the attacks that get through: credential harvesting, impersonation of leadership, and invoice and payment fraud.

Managed cloud backup

Independent backup of the data living in your Microsoft 365 or Google tenant, including mail, files and shared drives, so a deletion, a ransomware event or a departed account is recoverable.

Twenty five gigabytes of pooled storage per user is included, and more is available by the gigabyte.

What the program does not cover

Student accounts are outside it. The per-user program covers staff accounts. Protecting student accounts is a separate scoping conversation, not an assumption to make quietly on either side.

Digital forensics and incident response is not included. If an incident needs a formal forensic investigation, that is separate work. What the program does carry is the detection, the containment and the log history that a forensic investigation would start from.

Incident response planning is its own engagement. A written plan naming who decides, who is called, in what order and on what clock is a one time piece of work, listed with the other separately available components below.

How it gets stood up

The program starts with a scoped implementation, then settles into a recurring service.

  1. ScopeWe agree what is in the estate: users, sites, devices, cloud tenant, and what security tooling you already own and pay for. Anything you already have that covers a component, we configure rather than replace.
  2. DeployAgents go out to managed devices, the cloud and identity connectors are attached, mail protection is put in line, and backup is turned on. This is delivered as a defined project with a start and an end.
  3. TuneThe first weeks are spent removing noise so that an alert that reaches a human means something. Training and phishing simulation start in this window.
  4. RunCTS owns the monitoring, the response, the training cycle, the backup checks and the vulnerability reviews from that point on, and reports back to you on a regular cadence.

Protection and advisory are two different jobs

Managed Cyber Protection is the operational half. Managed Cyber Advisory is the governance half. They are sold separately and many organizations take one before the other.

Managed Cyber Protection

Runs your security operations

  • Detection and response, 24/7
  • Staff training with phishing simulation
  • Email protection above the platform default
  • Cloud backup of tenant data
  • Vulnerability scanning and review
  • Priced per user and per site
Managed Cyber Advisory

Owns your policies and risk posture

  • Twenty or more written security policies, branded to your organization, built and maintained
  • A risk register with tracked exceptions
  • A scheduled review of that register with your leadership, quarterly or monthly by tier
  • Included advisory time each year for the questions that come up
  • At the higher tier, an assigned cybersecurity advisor and an annual risk assessment
  • Priced as a flat monthly program

The two are complementary rather than sequential. Advisory produces the written record that boards, auditors and cyber insurers ask for. Protection produces the monitoring and the response that closes what the record finds.

A la carte

Every component can be bought on its own. The bundle exists because the pieces reinforce each other, not because they are locked together.

ComponentHow it is counted
Managed Detection and Response, fullPer user
Managed Detection and Response, Core tierPer user
Managed security awareness trainingPer user
Managed advanced email protectionPer user
Outbound email protection and data loss preventionPer user
Managed cloud backupPer user, plus storage
SaaS managementPer user
Internal vulnerability managementPer asset
Internal vulnerability management, quarterly reviewPer quarter
Extended security log retention beyond ninety daysPer month
Incident response plan developmentOne time

Full against Core. Both carry the 24/7 security operations center, endpoint detection and response, cloud threat detection, and vulnerability management on workstations, servers and the external network. The Core tier drops the pieces that need equipment on your network or a place to keep history: local network threat monitoring, security log retention, DNS layer malware protection and lookalike domain monitoring. The full tier is what the program carries.

Components carry their own one time implementation where one applies. Current pricing for any line above is available from your CTS team.

What the service needs from you

Three conditions decide what is deliverable. Two of them are already met at Vermont Academy.

Managed devices for endpoint coverage

Detection and response on a laptop or desktop requires an agent on that machine. Staff and campus devices at Vermont Academy are already managed by CTS, so this condition is met. Any device outside that management, including personal machines, is outside endpoint coverage and we would rather say so now than have it found later.

An administered cloud tenant

Email protection, cloud backup and log retention attach to a tenant the school administers. That tenant is in place and under management, so this condition is met as well.

An honest inventory of what you already own

This is the open one. Schools are often already paying for a capability nobody turned on, and where that is true the right answer is configuration, not a second license. Scoping starts by reading what is deployed on the account today and subtracting it, which is work CTS can do before any quote exists.

The question underneath all of this

Sachin Gujral, Chief Executive Officer, Charter Technology Solutions

Choosing between managed and professional services is really an ownership question: who owns IT after go live. A service owner closes the ticket when the user can work again, not when a response is sent.

Most security problems are ownership gaps rather than tooling gaps. An alert fired and nobody was assigned to read it. A backup existed and nobody verified it. A policy was written once and never reviewed.

Managed Cyber Protection is CTS taking ownership of that recurring work, with a named team and a reporting cadence, so the answer to who is watching is a person and not a product.