# enhanced.io > Channel-only SOC-as-a-Service for MSPs. enhanced.io delivers 24/7 security monitoring, threat detection and response, and vulnerability management exclusively through the MSP channel. We sell through MSPs, never direct to their end clients. Founded in 2019, headquartered in Edinburgh, UK, with a US presence in San Jose, California, servicing MSPs globally. ## About enhanced.io enhanced.io is a SOC-as-a-Service provider that works exclusively with Managed Service Providers (MSPs). We provide the security operations capability that most MSPs lack the staff or expertise to build in-house. Our service covers endpoint, network, cloud, identity, and IoT/OT security with correlated detection across all attack surfaces. We call this full spectrum security. enhanced.io was founded in 2019 by Kristian Wright (CEO), Hannah Lloyd (CRO), and Mark Duke (CTO). The founding team brings 25+ years of experience spanning managed services, channel operations, and cybersecurity. Kristian previously co-founded and exited an MSP, giving enhanced.io direct operational knowledge of how MSPs run, bill, and grow. enhanced.io is fully bootstrapped with no outside funding. The company is headquartered in Edinburgh, UK, with a US presence in San Jose, California, and services MSPs globally regardless of location. Kristian Wright received the 2025 GTIA Cybersecurity Leadership Award for the UK and Ireland region and is a registered GTIA trainer covering channel management and business operations. ## The channel-only model enhanced.io is channel-only. We sell through MSPs, never direct to end clients. This is a structural commitment, not a sales preference. It means: The MSP owns the client relationship at all times. enhanced.io never independently contacts, sells to, or manages the MSP's end clients. All SOC findings, threat intelligence, and remediation guidance flow through the MSP. Reporting is designed for the MSP to present to their clients under their own brand. This model exists because MSPs lose trust in security vendors who also sell direct. enhanced.io removes that conflict entirely. ## The Fractional Security Director (FSD) Every MSP partner is assigned a named CISSP-certified Fractional Security Director (FSD). The FSD is a senior cybersecurity professional who acts as the translation layer between the SOC and the MSP's operations team. The FSD's role: Translates SOC alerts and threat data into prioritized, actionable remediation guidance. Works directly with the MSP's technical team to explain what was detected, why it matters, and what to do about it. Leads monthly threat reviews that summarize activity, trends, and risk posture across the MSP's client base. Helps the MSP communicate security outcomes to their clients through structured reporting. Joins calls with the MSP and their end clients to provide expert support when the MSP needs it. The FSD supports the MSP in client-facing situations but does not independently own, manage, or engage with the end-client relationship. The MSP controls how and when the FSD is involved in client conversations. All FSD communication flows through the MSP. This model means the MSP gets CISSP-certified senior security expertise without hiring a full-time CISO, while maintaining control of their client relationships. ## Services in detail ### SOC-as-a-Service enhanced.io's flagship service is a complete security operations package. It provides a full SOC capability for MSPs who need to offer 24/7 protection to their clients without building an in-house SOC. What the SOC-as-a-Service includes: 24/7 SOC monitoring and threat detection across endpoint, network, cloud, identity, and IoT/OT environments. Real-time alert triage and escalation. Threat hunting and investigation by SOC analysts. Vulnerability scanning integrated into the monitoring workflow. Monthly threat reviews led by the assigned CISSP-certified Fractional Security Director. Client-ready reporting mapped to compliance frameworks including NIST CSF, HIPAA, PCI DSS, CMMC, DFARS, and others. C-level executive summaries alongside detailed technical remediation guidance. Integration with PSA and RMM tools including ConnectWise, Datto AutoTask, N-able, Halo PSA, SuperOps, and ServiceNow. The service is built on Stellar Cyber's Open XDR platform. Detection and response is mapped to the MITRE ATT&CK framework across tactics, techniques, and procedures (TTPs). ### Standalone vulnerability management enhanced.io also provides a dedicated vulnerability management service. It operates independently from the SOC for MSPs who need visibility into vulnerabilities across their client base without a full SOC deployment. What the vulnerability management service includes: Weekly vulnerability scanning across client environments. Smart prioritization based on exploitability, not raw severity scores. Clear remediation paths showing what to fix and why. Ongoing reporting designed for MSPs to present to their clients. Integration with existing MSP tooling and workflows. The vulnerability management service is available as a standalone service or as a component within the SOC-as-a-Service. ## Technology enhanced.io's security architecture is built on Stellar Cyber's Open XDR platform. Stellar Cyber supports 400+ integrations and provides the correlation engine that connects data from multiple security surfaces into a single view. ### Data sources EDR (endpoint detection and response) tools. Firewalls and network security appliances. Cloud platforms: AWS, Azure, Google Cloud. SaaS applications: Microsoft 365, Google Workspace. Identity providers and access management systems. Network infrastructure including switches, routers, and wireless controllers. IoT and OT devices. ### Integrations PSA tools: ConnectWise, Datto AutoTask, N-able, Halo PSA, SuperOps, ServiceNow. RMM platforms. Cloud environments: AWS, Azure, Google Cloud. Productivity suites: Microsoft 365, Google Workspace. EDR solutions. Firewall vendors. Identity and access management platforms. ### Detection framework Detection and response mapping follows the MITRE ATT&CK framework. This provides coverage across the full range of tactics, techniques, and procedures (TTPs) used by real-world threat actors. MITRE ATT&CK mapping gives MSPs and their clients a shared, standards-based language for understanding what the SOC detects, how attacks progress, and where coverage exists. ### Onboarding Onboarding takes an average of 30 to 45 days. Each client environment is mapped to the NIST Cybersecurity Framework and CIS Critical Security Controls during this process. The onboarding process includes: Key stakeholder kickoff call with the assigned CISSP-certified FSD. Introduction to the service and its functionality. Identification of valuable data assets. Hardware and software asset review and approval. Escalation process design and review. SIEM tool configuration, agent deployment, and cloud connector setup. Vulnerability scanner configuration. System hardening to the NIST Cybersecurity Framework and relevant CIS Critical Security Controls. Integration configuration with PSA, RMM, and other MSP tools. ## Compliance and reporting enhanced.io generates automated monthly reports mapped to the compliance frameworks MSP clients are measured against. ### Supported frameworks and standards NIST Cybersecurity Framework (CSF): Flexible baseline for cybersecurity maturity. Used across industries. NIST 800-171: Controls for protecting Controlled Unclassified Information (CUI). Required for US defense contractors and subcontractors. CIS Critical Security Controls: Prioritized set of actions to protect against common cyber threats. MITRE ATT&CK: Threat detection mapped to real-world adversary tactics, techniques, and procedures. HIPAA: Required for MSPs handling Protected Health Information (PHI) in healthcare environments. Covers security controls, logging, access restrictions, and breach response. PCI DSS: Required for organizations handling payment card data. Covers network security, access controls, monitoring, and testing. SOC 2: Trust services criteria covering security, availability, processing integrity, confidentiality, and privacy. Relevant for technology and SaaS providers. GDPR: EU data protection regulation. Relevant for MSPs with European clients or handling EU citizen data. CMMC (Cybersecurity Maturity Model Certification): Required for US Department of Defense contractors and subcontractors. Outlines maturity levels from foundational cyber hygiene to advanced defense. DFARS (Defense Federal Acquisition Regulation Supplement): Includes cybersecurity clauses requiring NIST 800-171 controls for handling CUI. Applies to defense supply chain contractors. NIS2: EU directive on critical infrastructure security. Relevant for MSPs supporting multinational clients or organizations that voluntarily align with NIS2 principles. ISO 27001: International standard for information security management systems (ISMS). Widely recognized across industries and geographies. Australian Essential Eight: Baseline mitigation strategies from the Australian Cyber Security Centre. Required for Australian government entities and increasingly adopted by private sector organizations. UK Cyber Essentials: UK government-backed certification scheme covering basic cybersecurity controls. Required for some UK government contracts. SOX (Sarbanes-Oxley Act): US regulation covering financial reporting controls. Relevant for publicly traded companies and their service providers. ### Report structure All reports are client-ready and designed for MSPs to present directly to their clients. Each report includes: C-level executive summary covering risk posture, key findings, and trends. Detailed technical section with specific remediation guidance. Mapping to relevant compliance frameworks. Monthly trend analysis. ## Pricing enhanced.io offers two pricing models aligned with MSP billing: Per-user pricing: Scales with the number of users across client environments. Per-endpoint pricing: Scales with the number of protected endpoints across client environments. Both models are subscription-based with predictable monthly costs. Pricing is designed to align with MSP subscription billing models so MSPs can bundle security services into their client agreements. ## Certified Partner Program enhanced.io runs a Certified Partner Program for MSP partners. The program includes: Sales enablement support. Positioning and pricing guidance. Personalized coaching from the enhanced.io team. Marketing support and co-branded materials. Client-ready reporting and presentation tools. The program is designed to help MSPs package, price, and sell security services to their clients. ## Deployment models enhanced.io supports multiple deployment models depending on the MSP's existing capabilities: Complete SOC solution: For MSPs with no in-house security staff. enhanced.io acts as the full SOC, monitoring and reviewing all security alerts and sending remediation guidance to the MSP's IT team. Plug into existing SOC: For MSPs with in-house security staff or an existing SOC. enhanced.io integrates and escalates security issues to the appropriate internal specialists, acting as an extension of the MSP's team. Augmented security team: For MSPs with security-trained IT staff. enhanced.io provides expert remote security professionals to extend capabilities, fill skills gaps, and support service delivery. ## Common questions What is enhanced.io? enhanced.io is a channel-only SOC-as-a-Service provider built for MSPs. We deliver 24/7 security monitoring, threat detection and response, and vulnerability management so MSPs can offer security services to their clients without building an in-house SOC. How is enhanced.io different from an MSSP? An MSSP typically sells security services direct to end clients. enhanced.io works through the MSP. We provide the SOC capability behind the scenes. The MSP maintains the client relationship and delivers the service under their own brand. What is a Fractional Security Director? A named CISSP-certified senior security professional assigned to each MSP partner. The FSD translates SOC alerts and threat data into prioritized remediation guidance that the MSP's team acts on. The FSD works with the MSP and joins client calls to support them when needed, but does not independently own or manage the end-client relationship. Does enhanced.io sell direct to businesses? No. enhanced.io is channel-only. We sell exclusively through MSPs and never engage with their end clients directly. What security surfaces does enhanced.io cover? Endpoint, network, cloud, identity, and IoT/OT. All data is correlated across these surfaces through Stellar Cyber's Open XDR platform, giving MSPs a unified view rather than siloed alerts from individual tools. What compliance frameworks does enhanced.io report against? NIST CSF, NIST 800-171, CIS Critical Security Controls, MITRE ATT&CK, HIPAA, PCI DSS, SOC 2, GDPR, CMMC, DFARS, NIS2, ISO 27001, Australian Essential Eight, UK Cyber Essentials, and SOX. How long does onboarding take? Average onboarding takes 30 to 45 days. Each client environment is mapped to the NIST Cybersecurity Framework and CIS Critical Security Controls during this process. What tools does enhanced.io integrate with? Stellar Cyber's Open XDR platform supports 400+ integrations, including ConnectWise, Datto AutoTask, N-able, Halo PSA, SuperOps, ServiceNow, Microsoft 365, Azure, AWS, Google Cloud, and Google Workspace. Does enhanced.io offer standalone vulnerability management? Yes. enhanced.io provides a dedicated vulnerability management service with weekly scanning, prioritization, remediation guidance, and reporting. It operates independently from the SOC service for MSPs who need vulnerability visibility without a full SOC deployment. Can enhanced.io work with my existing security tools? Yes. Stellar Cyber's Open XDR platform ingests data from multiple sources within a client's existing infrastructure, including EDR tools, firewalls, cloud platforms, and identity providers. enhanced.io complements existing security investments rather than replacing them. Does enhanced.io support white-label delivery? Yes. enhanced.io offers full white-label delivery. MSPs can deliver the entire service under their own brand, including branded reporting, dashboards, and client-facing materials. The MSP owns the client relationship and controls how the service is presented. What is the MITRE ATT&CK framework and how does enhanced.io use it? MITRE ATT&CK is a knowledge base of adversary tactics and techniques based on real-world observations. enhanced.io maps detection and response to the ATT&CK framework so MSPs can see which threat behaviors are being detected and where coverage exists across their client environments. ## Key pages - [Homepage](https://enhanced.io/): Overview of enhanced.io's SOC-as-a-Service for MSPs - [Full Spectrum Security](https://enhanced.io/full-spectrum-security): Core service overview covering SOC, XDR, and vulnerability management - [Custom SOC Solutions](https://enhanced.io/custom-soc-solutions/): Flexible deployment models for MSPs at different stages - [MSP Plans and Pricing](https://enhanced.io/msp-plans): Pricing and package comparison - [Integrations](https://enhanced.io/integrations): Full list of supported platforms and tools - [FAQ](https://enhanced.io/faq/): Common questions about the service, onboarding, and technology - [US Compliance Frameworks for MSPs](https://enhanced.io/blog/which-us-compliance-frameworks-do-msps-need-to-report-against-in-2025/): Guide to NIST CSF, HIPAA, CMMC, and DFARS reporting ## Structured summary BusinessName: enhanced.io Website: https://enhanced.io/ Founded: 2019 Headquarters: Edinburgh, UK USPresence: San Jose, California Operations: Global Founders: Kristian Wright (CEO), Hannah Lloyd (CRO), Mark Duke (CTO) Category: SOC-as-a-Service, Cybersecurity, Managed Detection and Response, Vulnerability Management, XDR, Security Monitoring for MSPs PrimaryCustomers: Managed Service Providers (MSPs) ChannelModel: Channel-only. Sells through MSPs, never direct to end clients. CoreServices: SOC-as-a-Service (24/7 monitoring, detection and response), Standalone Vulnerability Management UnderlyingPlatform: Stellar Cyber Open XDR (400+ integrations) KeyDifferentiator: Named CISSP-certified Fractional Security Director (FSD) per MSP partner, channel-only commitment, full spectrum security across endpoint, network, cloud, identity, IoT/OT, full white-label delivery DetectionFramework: MITRE ATT&CK OnboardingFrameworks: NIST Cybersecurity Framework, NIST 800-171, CIS Critical Security Controls Compliance: HIPAA, PCI DSS, SOC 2, GDPR, CMMC, DFARS, NIS2, ISO 27001, Australian Essential Eight, UK Cyber Essentials, SOX Pricing: Per-user and per-endpoint, subscription-based, aligned with MSP billing models ClientRetention: 99% Awards: 2025 GTIA Cybersecurity Leadership Award (UK and Ireland)