Services · Service tiers
AlignCORE, AlignSHIELD, and AlignASSURE, explained.
Three service tiers and how they fit together: what each one includes, what it builds on, and what you can have on its own.
Choosing what you need
Start with what you need today. Add more as you grow.
Most organizations start with AlignCORE, our managed IT and security foundation, and add AlignSHIELD when they need deeper protection and recovery. AlignASSURE covers governance and compliance, with or without our managed IT.
Managed IT and security
Start here
AlignCORE
Need your IT run, supported, and protected?
Everyday IT support, monitoring, patching, and 24x7 security for every user and device. This is where almost every client starts.
See what’s included ↓Optional add-on
AlignSHIELD
Need to recover fast and prove you’re protected?
Full business continuity and disaster recovery, monthly security testing, secure remote access, logging, and a cyber warranty. Requires AlignCORE.
See what’s included ↓Two flavors
Fully Managed IT
No IT team? We become your IT department, and your staff call us directly.
Learn more →Governance and compliance
Works on its own
AlignASSURE
Need to meet a framework, satisfy auditors, or report risk to your board?
A governance, risk, and compliance program with vCISO leadership. Pair it with our managed IT, or keep your current IT provider.
See what’s included ↓Just need Microsoft 365 or Google Workspace secured? Both are available on their own, outside AlignCORE.
Microsoft 365 → Google Workspace →The foundation
AlignCORE
Support, monitoring, and protection for every user and device, delivered as Fully Managed or Co-Managed IT. Onboarding starts within 10 days and reaches steady-state operations in about 75.
Fully Managed IT
We become your IT department. Your staff reach our helpdesk directly, with onsite support when needed.
Learn more →Co-Managed IT
Your IT team stays in front of your people. We back them up with security, operations, and escalations.
Learn more →Frontline tier
Shared devices, kiosks, and shift workers get the same protection, monitoring, and patching, without individual helpdesk access.
VIP access
For co-managed clients, named executives can reach our helpdesk directly.
Security and threat detection
24x7 monitoring and response from our Five Eyes-based Security Operations Center, with XDR, MDR, EDR, and antivirus on every managed device
Advanced email security against phishing and impersonation
Zero trust application control that blocks malware and unauthorized software
A secure web gateway that filters malicious sites and enforces safe browsing
Annual endpoint penetration testing on a representative sample of devices, on request
Identity and access
Identity and access management with Microsoft Entra ID
Privileged access management and identity threat detection for high-risk accounts
An enterprise password manager and secure access vault with multi-factor authentication
Zero trust storage control and elevation control that stop unauthorized privilege escalation
Dark web monitoring for leaked credentials
User behavior analytics that catch business email compromise and insider threats
Network and data protection
Micro-segmentation and advanced firewall monitoring that limit how far a threat can move
Network access control that keeps unauthorized and unmanaged devices off your network
SaaS backup and file-level server backup
Support and operations
A dedicated CORE Team assigned to your organization
A 24x7x365 helpdesk, Network Operations Center, and Security Operations Center, reachable by phone, email, Microsoft Teams, Slack, chat, and text, with field engineers onsite when an issue needs hands-on work
Proactive monitoring and patching
Azure and Google Cloud management and cost optimization
Microsoft 365 and Google Workspace hardening and monitoring
Training and lifecycle
Ongoing security awareness training, phishing simulations, and productivity best practices for Microsoft 365 and Google Workspace
Device lifecycle management, procurement support, and refresh planning
Add-on to AlignCORE
AlignSHIELD
AlignSHIELD doesn’t replace anything in AlignCORE. It extends it with containment depth, recovery assurance, and financial protection. It requires AlignCORE, so everything above stays in place, including privileged access management, segmentation, network access control, and SaaS and file-level server backup.
Financial protection
A cyber warranty of up to $500,000, provided by Cork, to help with recovery costs after a qualifying cyber incident
Secure remote access
Secure Access Service Edge (SASE) and Zero Trust Network Access (ZTNA) that enforce identity-driven security policies for remote and hybrid teams
Continuous vulnerability testing
Automated monthly penetration testing of every Windows and macOS endpoint, with actionable reporting
Logging and visibility
SIEM, IDS/IPS, and firewall logging, with enterprise-grade security event monitoring and compliance-ready audit trails
Business continuity and disaster recovery
Full business continuity and disaster recovery for every endpoint and server, so whole systems can be restored after ransomware, device failure, or accidental data loss
This goes beyond the SaaS and file-level server backup included in AlignCORE
Stands on its own
AlignASSURE
Our governance, risk, and compliance program. It stands on its own and serves as the governance authority for your environment, whoever runs your day-to-day IT. Your organization owns its risk decisions; we facilitate, draft, maintain, and report. We help you demonstrate alignment; we do not provide compliance attestation or certification.
Phase 1: Security Risk Assessment
A calibrated picture of the three to five scenarios that could actually hurt your organization, with loss estimates in ranges
An external review of your public footprint and an internal vulnerability and asset baseline
A vendor and third-party screen, plus an inventory of AI tools and unsanctioned apps
Compliance applicability, a control-gap crosswalk, and a cyber insurance alignment review
A prioritized, costed roadmap sequenced by risk reduced per dollar, presented in a read-out for leadership
Delivered as soon as 30 days after we receive your inputs
Phase 2: Program stand-up
A governance platform of record with your framework baseline, risk register, and evidence library
A risk register with named owners and a signed risk appetite statement
A plan of action and milestones with owners and dates
An incident response plan with escalation paths and a recovery order for each critical system
A program charter, cadence calendar, and launch roadmap
Targeted for 60 to 90 days after the risk assessment read-out
Phase 3: Ongoing program
Quarterly security briefings with a program scorecard and a board-format view where applicable
A living risk register, with every risk acceptance signed and reviewed before it expires
Incident readiness, including an annual tabletop walkthrough with leadership
Third-party risk management and AI governance with an attested acceptable-use policy
Client-specific threat advisories
An evidence library with freshness tracking
Human-risk metrics from your awareness platform
Audit readiness with an annual pre-audit gap check, and an annual re-baseline
Frameworks
Built around one primary framework, such as CIS Controls, NIST CSF, HIPAA, SOC 2, ISO 27001, GDPR, or CMMC Level 1, with more added one at a time
A dedicated federal track covers CMMC Level 2, NIST SP 800-171, and NIST SP 800-53
The governance platform and policy development are included, and everything the program produces is yours to keep
Also available on its own
Services that fit any tier, or none.
Microsoft 365 security
Tenant hardening, 24x7 monitoring, and fast response to compromised accounts. Included in AlignCORE, or on its own.
Learn more →
Google Workspace security
Daily configuration scanning, app and sharing controls, and 24x7 monitoring. Included in AlignCORE, or on its own.
Learn more →
IT Strategy and Advisory
Roadmaps, budgets, AI strategy, and board briefings. Built into AlignCORE, AlignSHIELD, and AlignASSURE, or available as standalone advisory.
Learn more →
Questions
How the tiers work together.
Do we need AlignCORE to add AlignSHIELD?
Yes. AlignSHIELD is an add-on that builds on AlignCORE, so everything in AlignCORE stays in place and AlignSHIELD adds advanced security, deeper controls, and financial protection on top.
Can we have AlignASSURE without managed IT?
Yes. AlignASSURE stands on its own. Many organizations start with governance and compliance and add managed IT later, or never.
What’s the difference between Fully Managed and Co-Managed?
Both deliver AlignCORE. With Fully Managed IT, we are your IT department and your staff contact us directly. With Co-Managed IT, your IT team supports your people and we back them up with security, operations, and escalations.
Can we get Microsoft 365 or Google Workspace security on its own?
Yes. Both are included in AlignCORE, and both are available on their own for organizations that need their tenant or Workspace secured and managed.
How is pricing structured?
AlignCORE and AlignSHIELD are priced per user, per month, and AlignASSURE is scoped around your primary framework. Each tier appears as its own line in your proposal, so you can see exactly what you’re paying for.
Not sure which combination fits?
Tell us where you are today, and we’ll recommend the right mix, including when you don’t need all of it.