Watch
A lightweight agent on each computer reports security events to us: sign-ins, programs starting, changes to system files, and everything your antivirus finds.
Managed detection and response for small businesses
We monitor your computers for attacks, contain threats before they spread, and explain what happened in plain language. Automation does the watching, so you pay for expertise only when it's needed.
Why this matters
A large company has a security team that notices when a laptop starts behaving strangely at two in the morning. A ten-person office usually has antivirus, a busy owner, and nobody whose job it is to look.
That gap is what attackers rely on: time. Hours or days in which stolen passwords are used, files are copied, and ransomware is prepared, all before anyone knows.
Our job is to close that gap. We notice early, we act quickly, and we tell you what happened.
What we do
A lightweight agent on each computer reports security events to us: sign-ins, programs starting, changes to system files, and everything your antivirus finds.
Every serious alert opens a case with the evidence attached: what ran, who ran it, whether it has been seen before, and whether it is known to be malicious.
We block attacking addresses and can cut a single computer off from the network while it is cleaned up. Everyone else keeps working.
You hear from a person: what happened, what we did, and what you need to do, if anything. There are no dashboards to learn.
In development: monitoring for Microsoft 365 accounts (suspicious sign-ins, hidden mail forwarding), a monthly security report for each client, and a client portal.
Automation, with judgement
Most of the work in security monitoring is repetitive: collecting events, opening a case, gathering evidence, carrying out a response and checking that it worked. We have automated all of it.
What we have not automated is judgement. Cutting a computer off stops an attack, and it also stops someone's work, so an analyst reviews the evidence and makes that call.
The result is a faster response than a person working alone could give, at a cost a small business can carry.
The agent reports suspicious activity the moment it happens.
With the computer, the user, and exactly what triggered it.
Has this been seen before? Is the file signed? Is it known to be malicious?
A person reviews the evidence and approves or declines containment.
The computer is cut off, and reports back that it is.
What happened, what we did, and what comes next.
Priced for small businesses
Traditional managed security is expensive for two reasons: commercial software licences charged per computer, and rooms full of analysts doing work by hand. We removed both.
Our platform is built on proven open-source security software, so there are no licence fees to pass on to you. Automation handles the routine work, so analyst time goes where it matters.
A flat monthly price per computer. Ask us for a quote; it takes one short conversation.
Getting started
A short conversation about your business, your computers and what worries you.
You get one installer made for your company. Run it on each computer; it needs no changes to your network.
Your computers start reporting in, and we filter out what is normal for your business.
From then on, when something is wrong, we contain it and contact you.
About us
[Founder background to be added: years in security, previous roles, certifications and training.]
We built Samson because the tools that protect large companies are out of reach for the businesses that need them most. The name is deliberate: strength where it counts, holding up what matters.
Every change to our platform is tested end to end on Windows, macOS and Linux, from alert to containment to release.
When we contain a threat, the computer itself reports back that the action was carried out.
Each computer connects out to us. We open no ports on your firewall and use no remote-access tools.
Each client has its own enrolment key. Remove the agent and our access is gone.
Common questions
Security events: who signed in, which programs ran, changes to system files and settings, and antivirus results. We do not collect the contents of your documents or email.
No, and it doesn't replace yours. Antivirus blocks known threats on one computer. We watch across all of them for the signs of an attack that gets past it, and we respond.
It loses its network connection except to us, so an attacker can no longer control it or spread from it. Once it is clean, we reconnect it remotely.
No. If you have an IT provider, we work alongside them. If you don't, we tell you plainly what needs doing.
The agent is designed to run quietly in the background. If you ever notice an effect, tell us and we will adjust it.
Yes. Removing the agent removes our access, and we delete your enrolment.
We're taking on a small number of first clients. Write to us and we'll set up a conversation: no sales script, no obligation.