FAQ
The questions enterprise buyers ask before engaging CyberZonic.
Straight answers on how engagements work, where we operate, how we handle data, and how pricing is shaped. If your question is not answered here, a scoping conversation is the fastest way to get a clear answer.
How we start and run work
Engagements
How does a typical engagement start?
Every engagement begins with a short, structured scoping conversation. We cover the environment, the pressure point driving the request, and what 'done' actually looks like. If we are the right fit, we follow up with a written scope brief and a commercial proposal with clear deliverables and exit criteria. If we are not the right fit, we say so at that stage — we would rather turn work down than over-promise.
What does a typical SOC engagement look like?
A SOC engagement usually runs through our six-phase methodology: Scope, Assess, Design, Build, Verify, Operate. In practice that means a posture assessment against your current Sentinel / Defender estate, a target operating model designed around your team's capacity, Sentinel analytics rules and playbooks built incrementally with change control, a verification phase with detection testing and a tabletop exercise, and a structured handover with an aftercare window. The goal is a capability your team can run — not a black box that depends on us.
How long do engagements usually take?
It depends on scope, but most focused engagements run between six and twelve weeks from scoping call to handover. Smaller assessments can complete inside three weeks. Larger transformation programmes are shaped as phased work so each phase delivers verifiable value before the next begins. We scope to the work that genuinely fits the window — if the ask is unrealistic, we say so before contracts are signed.
Can you work alongside our existing MSP or internal team?
Yes — this is one of the most common engagement shapes. We work as a specialist partner alongside an existing MSP or an internal security team, usually focused on an area where deeper Microsoft security expertise is needed (Sentinel detection engineering, Defender tuning, Entra identity hardening, governance uplift). We build to hand over, so the client's existing team remains the long-term owner.
Where and how we operate
Scope and geography
Do you work outside the UK?
Yes. CyberZonic is UK-based but engagements are delivered across Europe, the Middle East, and remote-first wherever a Microsoft-centric estate exists. Most delivery is remote with on-site visits for workshops, tabletops, or sensitive handover sessions. Where data residency or regulatory constraints apply, we shape delivery to respect them.
What sectors do you focus on?
Our strongest fit is in regulated or high-pressure operating environments: financial services, healthcare, technology, manufacturing, professional services, and public sector. The common thread is not the sector — it is the need for evidence-grade delivery, clear governance, and a capability the client's own team can run after we leave.
What is your relationship with Microsoft?
CyberZonic works across Microsoft and heterogeneous enterprise environments. We have deep delivery capability in Microsoft Sentinel, the Defender suite (MDE, MDI, MDO, MDC), Entra ID, Intune, Purview, and Azure security services, while architecture remains driven by client requirements, interoperability, governance, and operational ownership. Where Microsoft-native tooling is the right fit, we align delivery to relevant Microsoft security reference architectures and build capability the client can maintain.
How we handle client information and pricing
Data, security and commercials
How do you handle our data during an engagement?
Client data is treated with the same discipline we advise our clients to use. Access is least-privilege and time-bound. Evidence packs are stored in encrypted, access-controlled locations. Credentials are rotated on handover. Where possible we operate inside the client's own tenant under named accounts rather than moving data out. All handling is documented as part of the engagement, and a formal data handling note is included in every scope brief.
How is pricing structured?
Three commercial shapes: fixed-scope engagements for well-bounded work, retained support for ongoing monitoring or advisory needs, and tailored enterprise programmes for larger transformation work. Indicative entry points are published on the pricing page, but final pricing is always shaped to the real environment during scoping — we would rather price accurately once than guess twice.
Do you offer a retainer or ongoing support?
Yes. Many clients move from a delivery engagement into a retained support arrangement covering detection tuning, advisory hours, incident support, and periodic reviews. Retainer scope is always explicit — no open-ended 'trust us' arrangements — and the commercial model is shaped around actual operating need rather than a fixed package.
What happens if something goes wrong after handover?
Every engagement includes a defined aftercare window with a named escalation path. Problems that surface inside that window are handled under the original engagement, not as a new commercial. After the aftercare window, clients on a retainer get ongoing support; clients without a retainer can re-engage under a lightweight support arrangement. We do not disappear on invoice day.
Still have questions
A short scoping call is the fastest way to get a clear answer for your environment.
No commitment until both sides agree the fit is right.


