Join our team and solve national security’s hardest problems
HOW THE PROGRAM WORKS
The operating cadence, the reporting leadership sees, the complete tier comparison and the compliance pathways each tier can support.
Fewer preventable incidents, disruptions and unmanaged gaps.
Give auditors, customers, insurers, and executives a clearer answer.
One partner operating IT and security through a measurable cadence.
THE BUSINESS PROBLEM
Regulated organizations need daily operations that reduce risk and a reporting model that shows whether the environment is actually improving.
01
Reduce downtime and operational disruption through proactive management, detection, response, backup and recovery.
02
Turn security activity into clear operational evidence for auditors, customers, insurers, and leadership.
03
Build a repeatable foundation that can withstand greater scrutiny, and focuses your efforts on growing your business.
EXECUTIVE SECURITY VIEW
Every month the same core operating measures are reported, so leadership can see how the environment is improving.
Measured monthly
Patch compliance
Visible
Status, aging and exceptions
Backup health
Tracked
Job success and recovery readiness
Identity protection
Enforced
MFA and access-control coverage
Security operations
Reported
Incidents, actions and closure
How the program works
The technology matters, but the product is the ongoing discipline: discover, harden, operate, measure and improve.
Step 1
Confirm the environment, business dependencies, current risks and contractual obligations.
Step 2
Deploy and enforce the agreed baseline across identity, devices, backup, monitoring and access.
Step 3
Manage the environment continuously through support, maintenance, detection, response and remediation.
Step 4
Report operational and security trends so leadership can see what changed and what comes next.
THREE service TIERS
Your operational reliance and compliance obligations determine the tier. Your environment size determines the final monthly investment.
For organizations that need dependable baseline IT and security hygiene without a formal compliance program.
Best for low-complexity environments establishing a controlled baseline.
MOST COMMON
For IT-reliant organizations that need broader visibility, stronger controls and recurring executive reporting.
Best for growing organizations, when faced with insurer pressure and for early compliance readiness.
For regulated and high-consequence environments where audit evidence and deeper security operations are required.
Best for defence, critical operations and organizations under formal scrutiny.
Compliance pathways
MalleumOne operates the IT and security foundation. Formal readiness, evidence, assessment and certification work depends on the client’s contract, information type and jurisdiction.
MalleumOne can be configured to support Canadian Program for Cyber Security Certification readiness. Level 2 delivery requires an Elite environment plus separately scoped architecture, evidence and implementation work.
Cybersecurity Maturity Model Certification requires a separate FedRAMP-oriented architecture for organizations handling or protecting Controlled Unclassified Information CUI.
Canadian and US obligations apply independently. Architecture, residency, administration and evidence decisions must be evaluated for each environment.
Requirements are set by each municipality, agency or board through its own procurement rules, contract terms and data-residency requirements rather than one national framework. MalleumOne is scoped and evidenced to match what the RFP or contract calls for.
MalleumOne can support organizations with finance-related compliance obligations, including environments that need to align with PCI requirements or ISO-based control frameworks. Specific readiness, assessment, evidence and certification activities are scoped separately based on the applicable standard, business context and audit requirements.
WHAT LEADERSHIP CAN SEE
The technology matters, but the product is the ongoing discipline: discover, harden, operate, measure and improve.
Status, aging and unresolved exceptions.
Job success, failures and recovery readiness.
MFA, access controls and non-compliant events.
Training participation and phishing-risk trends.
Alerts, incidents, containment and outcomes.
Open risks, ownership, progress and next actions.
Frequently Asked Questions
MalleumOne is a security-first managed IT service for organizations where uptime, security, and compliance are non-negotiable. One accountable team manages day-to-day IT, security operations, reporting, and ongoing improvement to mitigate operational and contractual risk.
MalleumOne is a managed service, not a bundle of software: clients get an accountable operating team, a recurring service cadence, and defined outcomes. It is built around a managed detection and response platform as the primary layer of protection, supported by remote monitoring and management, network monitoring, security awareness training, and password management tooling.
MalleumOne delivers a defined service cadence and 24/7 security oversight for uninterrupted peace of mind.
MalleumOne is built for organizations in highly regulated or high-consequence environments, where operational risk, security, and compliance carry serious consequences, including clients with internal IT who still need a partner to run a predictable operating cadence and produce evidence-ready reporting. It shows up most often in defence and aerospace contractors subject to CPCSC and/or CMMC requirements, financial services organizations such as wealth management firms, credit unions, boutique investment dealers, and mortgage brokerages, and municipal, government, and public sector organizations.
There is no tier that skips security. Every client receives 24×7 SOC-backed security monitoring, remote monitoring and management for covered devices, basic network monitoring, business-hours remote help desk support as defined in the Statement of Work, security awareness training, a hardened productivity and email suite, MFA enforcement, full-disk encryption, web content filtering, monitored mailbox and file cloud backup, operational dashboards, hardware lifecycle tracking, identity lifecycle management, and a designated MalleumOne Account Manager.
The tiers share a common security floor. What changes is monitoring depth, reporting cadence, and how far the compliance-readiness story goes, though compliance work itself is not limited to any one tier. Essential is best for low IT-reliance environments with no formal compliance driver. Professional is best for IT-reliant organizations that need stronger visibility, governance, and executive reporting. Elite is best when a compliance obligation outweighs headcount or IT-reliance, including anticipated CPCSC Level 2 requirements, CUI-handling primes, and regulated financial institutions.
The right tier is selected based on the client’s operational risk, reliance on IT, reporting expectations, and the strength of evidence they need to support regulatory, contractual, insurance, or customer-driven obligations. Essential fits organizations that need a managed security and IT baseline. Professional fits organizations that rely more heavily on IT and need stronger governance, visibility, and recurring reporting. Elite fits high-consequence or highly scrutinized environments where deeper oversight, stronger evidence readiness, and executive-level visibility are required. Environment size helps determine the final monthly investment, but user count alone should not determine the tier.
No, MalleumOne does not guarantee a compliance or certification outcome. Compliance add-ons are available at any tier, including a compliance and governance platform for asset-centric scoping, gap analysis, evidence collection, remediation tracking, continuous monitoring, and formal reporting for CMMC, CPCSC and other frameworks; vulnerability management and scanning; documentation support; and penetration testing. Formal compliance readiness, documentation, and remediation services are separately scoped and quoted. Where an independent assessment, attestation, validation, or certification is required, that work is performed by an appropriately qualified third party.
Yes. MalleumOne can support both fully outsourced and co-managed operating models. Responsibilities, access, escalation paths, and approval workflows are agreed during onboarding and documented in the Statement of Work and the Malleum Responsibilities and Escalation Matrix, which is shared with every client and sets out who owns what, Malleum versus client, across every service line.
Onboarding is milestone-driven rather than tied to a fixed calendar. After signing, Malleum confirms scope, gathers required information, documents the environment, activates the managed service components, validates the security baseline, and moves into the recurring operating cadence once agreed checkpoints are complete. This includes discovery and documentation, service activation, security baseline validation, governance and reporting setup, and service kickoff. There is a one-time implementation/onboarding fee, billed separately from the ongoing monthly service.
Included in the managed service are ticket creation and severity validation, telemetry review, escalation to the SOC where confirmed, coordination with designated contacts, and standard remediation within the managed toolset, such as endpoint isolation, containment, quarantine, and blocking malicious indicators. Full ransomware event management, forensic acquisition and analysis, eradication planning across the environment, recovery program management, and insurer or legal coordination require a separate incident-response engagement.
Buying security and IT platforms directly does not create an operating model. MalleumOne adds deployment, administration, monitoring, escalation, remediation coordination, reporting, governance, vendor management, and a dedicated point of accountability. The tools support the service model, but the product is the operating cadence: measurable risk reduction, operational continuity, and compliance evidence that improves over time.
Yes. A client can begin with the tier that matches its current operating needs and move to deeper governance, reporting, and security operations as its environment and obligations evolve. Any change in scope or pricing is documented through the applicable commercial process.
The standard agreement does not include major infrastructure redesign or network architecture overhaul, physical hardware procurement outside the approved hardware partner program, application development or custom software support, ERP or line-of-business application administration, formal compliance audit preparation, assessments or third-party penetration testing, on-site support unless expressly included in the Statement of Work, data migration projects or cloud-tenant migrations, vendor contract negotiation or third-party SaaS management outside the managed stack, staff augmentation or embedded IT staffing, or infrastructure work such as network and firewall management, server management, and site-level backup, which are priced separately per site or per server rather than folded into the per-user fee.
After-hours coverage is limited to security monitoring and escalation for covered services. Help desk support is available during business hours, as defined in the Statement of Work. On-site support can be made available at any tier and billed at time-and-materials rates, unless expressly included in the Statement of Work.
START WITH CLARITY
Schedule a call with our team to confirm the appropriate tier, compliance pathway and next steps for your organization.
Schedule a call with our team to confirm the appropriate tier, compliance pathway and next steps for your organization.