Join our team and solve national security’s hardest problems

MalleumOne

HOW THE PROGRAM WORKS

The operating cadence, the reporting leadership sees, the complete tier comparison and the compliance pathways each tier can support.

Reduce operational risk

Fewer preventable incidents, disruptions and unmanaged gaps.

Produce credible evidence

Give auditors, customers, insurers, and executives a clearer answer.

Create accountability

One partner operating IT and security through a measurable cadence.

THE BUSINESS PROBLEM

Security cannot remain a collection of tools and good intentions

Regulated organizations need daily operations that reduce risk and a reporting model that shows whether the environment is actually improving.

01

Protect continuity

Reduce downtime and operational disruption through proactive management, detection, response, backup and recovery.

02

Prove the work

Turn security activity into clear operational evidence for auditors, customers, insurers, and leadership.

03

Support growth

Build a repeatable foundation that can withstand greater scrutiny, and focuses your efforts on growing your business.

EXECUTIVE SECURITY VIEW

The information leadership needs, measured monthly.

Every month the same core operating measures are reported, so leadership can see how the environment is improving.

MalleumOne reporting

Measured monthly

Patch compliance

Visible

Status, aging and exceptions

Backup health

Tracked

Job success and recovery readiness

Identity protection

Enforced

MFA and access-control coverage

Security operations

Reported

Incidents, actions and closure

How the program works

A practical operating cadence, not another dashboard

The technology matters, but the product is the ongoing discipline: discover, harden, operate, measure and improve.

Step 1

Discover

Confirm the environment, business dependencies, current risks and contractual obligations.

Step 2

harden

Deploy and enforce the agreed baseline across identity, devices, backup, monitoring and access.

Step 3

Operate

Manage the environment continuously through support, maintenance, detection, response and remediation.

Step 4

Prove progress

Report operational and security trends so leadership can see what changed and what comes next.

THREE service TIERS

Choose the operating depth your business requires

Your operational reliance and compliance obligations determine the tier. Your environment size determines the final monthly investment.

Essential

For organizations that need dependable baseline IT and security hygiene without a formal compliance program.

Best for low-complexity environments establishing a controlled baseline.

PROFESSIONAL

MOST COMMON

For IT-reliant organizations that need broader visibility, stronger controls and recurring executive reporting.

Best for growing organizations, when faced with insurer pressure and for early compliance readiness.

ELITE

For regulated and high-consequence environments where audit evidence and deeper security operations are required.

Best for defence, critical operations and organizations under formal scrutiny.

Compliance pathways

managed service and compliance engagement - appropriately scoped

MalleumOne operates the IT and security foundation. Formal readiness, evidence, assessment and certification work depends on the client’s contract, information type and jurisdiction.

Canadian DND / CPCSC

MalleumOne can be configured to support Canadian Program for Cyber Security Certification readiness. Level 2 delivery requires an Elite environment plus separately scoped architecture, evidence and implementation work.

US DoD / CMMC

Cybersecurity Maturity Model Certification requires a separate FedRAMP-oriented architecture for organizations handling or protecting Controlled Unclassified Information CUI.

Dual jurisdiction

Canadian and US obligations apply independently. Architecture, residency, administration and evidence decisions must be evaluated for each environment.

Municipal and public-sector procurement

Requirements are set by each municipality, agency or board through its own procurement rules, contract terms and data-residency requirements rather than one national framework. MalleumOne is scoped and evidenced to match what the RFP or contract calls for.

Finance industry compliance

MalleumOne can support organizations with finance-related compliance obligations, including environments that need to align with PCI requirements or ISO-based control frameworks. Specific readiness, assessment, evidence and certification activities are scoped separately based on the applicable standard, business context and audit requirements.

WHAT LEADERSHIP CAN SEE

Security progress translated into business evidence

The technology matters, but the product is the ongoing discipline: discover, harden, operate, measure and improve.

Patch compliance

Status, aging and unresolved exceptions.

Backup health

Job success, failures and recovery readiness.

Identity hardening

MFA, access controls and non-compliant events.

Security awareness

Training participation and phishing-risk trends.

Detection and response

Alerts, incidents, containment and outcomes.

Remediation priorities

Open risks, ownership, progress and next actions.

Frequently Asked Questions

Clear answers before the engagement starts

MalleumOne is a security-first managed IT service for organizations where uptime, security, and compliance are non-negotiable. One accountable team manages day-to-day IT, security operations, reporting, and ongoing improvement to mitigate operational and contractual risk.

MalleumOne is a managed service, not a bundle of software: clients get an accountable operating team, a recurring service cadence, and defined outcomes. It is built around a managed detection and response platform as the primary layer of protection, supported by remote monitoring and management, network monitoring, security awareness training, and password management tooling.

MalleumOne delivers a defined service cadence and 24/7 security oversight for uninterrupted peace of mind.

MalleumOne is built for organizations in highly regulated or high-consequence environments, where operational risk, security, and compliance carry serious consequences, including clients with internal IT who still need a partner to run a predictable operating cadence and produce evidence-ready reporting. It shows up most often in defence and aerospace contractors subject to CPCSC and/or CMMC requirements, financial services organizations such as wealth management firms, credit unions, boutique investment dealers, and mortgage brokerages, and municipal, government, and public sector organizations.

There is no tier that skips security. Every client receives 24×7 SOC-backed security monitoring, remote monitoring and management for covered devices, basic network monitoring, business-hours remote help desk support as defined in the Statement of Work, security awareness training, a hardened productivity and email suite, MFA enforcement, full-disk encryption, web content filtering, monitored mailbox and file cloud backup, operational dashboards, hardware lifecycle tracking, identity lifecycle management, and a designated MalleumOne Account Manager.

The tiers share a common security floor. What changes is monitoring depth, reporting cadence, and how far the compliance-readiness story goes, though compliance work itself is not limited to any one tier. Essential is best for low IT-reliance environments with no formal compliance driver. Professional is best for IT-reliant organizations that need stronger visibility, governance, and executive reporting. Elite is best when a compliance obligation outweighs headcount or IT-reliance, including anticipated CPCSC Level 2 requirements, CUI-handling primes, and regulated financial institutions.

The right tier is selected based on the client’s operational risk, reliance on IT, reporting expectations, and the strength of evidence they need to support regulatory, contractual, insurance, or customer-driven obligations. Essential fits organizations that need a managed security and IT baseline. Professional fits organizations that rely more heavily on IT and need stronger governance, visibility, and recurring reporting. Elite fits high-consequence or highly scrutinized environments where deeper oversight, stronger evidence readiness, and executive-level visibility are required. Environment size helps determine the final monthly investment, but user count alone should not determine the tier.

No, MalleumOne does not guarantee a compliance or certification outcome. Compliance add-ons are available at any tier, including a compliance and governance platform for asset-centric scoping, gap analysis, evidence collection, remediation tracking, continuous monitoring, and formal reporting for CMMC, CPCSC and other frameworks; vulnerability management and scanning; documentation support; and penetration testing. Formal compliance readiness, documentation, and remediation services are separately scoped and quoted. Where an independent assessment, attestation, validation, or certification is required, that work is performed by an appropriately qualified third party.

Yes. MalleumOne can support both fully outsourced and co-managed operating models. Responsibilities, access, escalation paths, and approval workflows are agreed during onboarding and documented in the Statement of Work and the Malleum Responsibilities and Escalation Matrix, which is shared with every client and sets out who owns what, Malleum versus client, across every service line.

Onboarding is milestone-driven rather than tied to a fixed calendar. After signing, Malleum confirms scope, gathers required information, documents the environment, activates the managed service components, validates the security baseline, and moves into the recurring operating cadence once agreed checkpoints are complete. This includes discovery and documentation, service activation, security baseline validation, governance and reporting setup, and service kickoff. There is a one-time implementation/onboarding fee, billed separately from the ongoing monthly service.

Included in the managed service are ticket creation and severity validation, telemetry review, escalation to the SOC where confirmed, coordination with designated contacts, and standard remediation within the managed toolset, such as endpoint isolation, containment, quarantine, and blocking malicious indicators. Full ransomware event management, forensic acquisition and analysis, eradication planning across the environment, recovery program management, and insurer or legal coordination require a separate incident-response engagement.

Buying security and IT platforms directly does not create an operating model. MalleumOne adds deployment, administration, monitoring, escalation, remediation coordination, reporting, governance, vendor management, and a dedicated point of accountability. The tools support the service model, but the product is the operating cadence: measurable risk reduction, operational continuity, and compliance evidence that improves over time.

Yes. A client can begin with the tier that matches its current operating needs and move to deeper governance, reporting, and security operations as its environment and obligations evolve. Any change in scope or pricing is documented through the applicable commercial process.

The standard agreement does not include major infrastructure redesign or network architecture overhaul, physical hardware procurement outside the approved hardware partner program, application development or custom software support, ERP or line-of-business application administration, formal compliance audit preparation, assessments or third-party penetration testing, on-site support unless expressly included in the Statement of Work, data migration projects or cloud-tenant migrations, vendor contract negotiation or third-party SaaS management outside the managed stack, staff augmentation or embedded IT staffing, or infrastructure work such as network and firewall management, server management, and site-level backup, which are priced separately per site or per server rather than folded into the per-user fee.

After-hours coverage is limited to security monitoring and escalation for covered services. Help desk support is available during business hours, as defined in the Statement of Work. On-site support can be made available at any tier and billed at time-and-materials rates, unless expressly included in the Statement of Work.

START WITH CLARITY

Find the right operating model before an incident, audit or contract forces the decision

Schedule a call with our team to confirm the appropriate tier, compliance pathway and next steps for your organization.

Schedule a call

Schedule a call with our team to confirm the appropriate tier, compliance pathway and next steps for your organization.