Security advisory, testing and AI operations

Your security function, without the hire.

Varstel gives you a security lead on retainer, fixed-price testing when you need it, and an operations agent that watches your PSA and RMM so you don't have to.

Built for UK managed service providers with ten to sixty staff, and the businesses they look after.

One engineerthe person you speak to does the work
Read-only, alwaysnothing I build can change your systems
Priced before work startsscoped in writing, every time
ops.your-msp.co.uk · read-only · example data
ClientEDRBackupPatching
Everything shown is a draft. Nothing is sent, changed or closed by the agent.
Watchers read your PSA and RMM on read-only credentials. Switch one on and the brief changes.
How an engagement runs

Four steps, the same every time

1

Scope in writing

A short call, then a one-page scope: systems, dates, people, deliverables. Nothing starts until you have signed it.

Scoped
2

Fixed price, before work

The price is in the scope. It does not move unless the scope does, and that needs your signature too.

Priced
3

Delivered by the same person

I do the work. No hand-off to a junior, no account manager between you and the engineer.

In progress
4

Handed over, owned by you

Reports you can white-label, code and credentials in your name, and a call to walk through what to do first.

Handed over
Services

Three things, done properly

Everything Varstel sells is one of these. Each is scoped in writing, priced before work starts, and delivered by the same person you spoke to.

An assistant that lives in your Teams or Telegram, knows your PSA and RMM, tells you what needs attention before you ask, and drafts the replies. It never acts on its own. I run one for my own business every day and will show you it working before you commit to anything.

Pilot start here

One PSA or RMM, Telegram, a weekly brief, three watchers and drafted replies. For the owner only.

Fixed build fee, then a monthly retainer
  • One integration: your PSA or your RMM
  • Weekly brief every Monday morning
  • Three watchers of your choice
  • Drafted replies for you to review and send
  • Read-only credentials, held by you

Standard most MSPs

PSA and RMM together, Teams or Telegram, six watchers, drafted replies and a coverage view of which client devices lack EDR, backup or patching. Owner and technicians.

Fixed build fee, then a monthly retainer
  • PSA and RMM, correlated
  • Daily brief, plus alerts as they happen
  • Six watchers
  • Coverage view: EDR, backup, patching per device
  • Technician access with per-person briefs

Full whole team

PSA, RMM, EDR, backup and mail. Everything in Standard plus client renewal clocks and monthly client summaries, for the whole team.

Fixed build fee, then a monthly retainer
  • Five integrations: PSA, RMM, EDR, backup, mail
  • Renewal clocks per client and contract
  • Monthly client summary you can forward
  • Whole-team access
  • Quarterly review of watchers with you
Read-only credentials only. The agent drafts and flags; a person sends and fixes. You own the box, the code and the credentials from handover.

A named security lead for your MSP on a monthly retainer, backed by fixed-price assessments you can resell to your own clients. Twelve-month term, sixty days' notice, no surprises.

Foundation

Monthly vulnerability review across your client estate, a written report you can white-label, and email advisory with a two-business-day response.

Monthly retainer
  • Monthly vulnerability review, whole estate
  • White-label report in your branding
  • Email advisory, two-business-day response

Partner

Everything in Foundation, plus a quarterly external assessment of one nominated client, Cyber Essentials readiness guidance, maintained policy templates and one client-facing call a month as your security lead.

Monthly retainer
  • Everything in Foundation
  • Quarterly external assessment, one client
  • Cyber Essentials readiness guidance
  • Policy templates, maintained
  • One client-facing call a month, as your security lead

Principal

Everything in Partner, with quarterly external assessments of up to three clients, an annual internal and Active Directory assessment, a half-day staff workshop and next-business-day advisory.

Monthly retainer
  • Everything in Partner
  • Quarterly external assessments, up to three clients
  • Annual internal and Active Directory assessment
  • Half-day staff workshop
  • Next-business-day advisory
Fixed-price packagesclick a package for details

External vulnerability assessment one organisation

The external attack surface of one organisation, a report, and a remediation call.

You getScoped authorisation, external scan and manual verification, a report ranked by what to fix first, and a call to walk through it.Typical durationFive business days from authorisation to report.

Cyber Essentials readiness annual

Gap analysis against Cyber Essentials and CE Plus, a remediation plan and evidence-pack guidance.

You getControl-by-control gap analysis, a remediation plan in order, and guidance on the evidence pack the assessor will ask for.Typical durationTwo weeks, with one working session.

Active Directory security review one domain

Configuration and attack-path review for one domain, with prioritised fixes.

You getConfiguration review, attack-path analysis from a standard user, and prioritised fixes with the reasoning for each.Typical durationFive to eight business days.

ISO 27001 gap analysis

Control-by-control gap analysis and a prioritised roadmap.

You getAnnex A control-by-control assessment and a roadmap you can take to a certification body.Typical durationThree weeks.

Insurer questionnaire support annual

Complete and evidence a cyber-insurance renewal questionnaire.

You getEach answer completed with you, evidenced, and a short list of what would improve next year's answers.Typical durationTwo working sessions.

Incident readiness tabletop half day

A half-day tabletop exercise and a review of your incident response plan. Readiness, not response.

You getA scenario run with your team, a review of the plan against what actually happened in the room, and a written list of gaps.Typical durationHalf a day on site or remote, report within a week.

The glue between your PSA, RMM and security tooling. Sold on its own when you are not ready for an agent, and as the first phase of every agent build.

Client onboarding and offboarding

The process every MSP does by hand and gets slightly wrong each time, automated end to end.

Fixed price, optional maintenance
  • Accounts, groups, licences, RMM enrolment, PSA records
  • Offboarding that actually removes everything
  • A checklist that runs itself and reports what it did

Security reporting automation

A monthly client security report generated from the tools you already run.

Fixed price, optional maintenance
  • Pulls from your RMM, EDR, backup and patching tools
  • One report per client, in your branding
  • Delivered to the PSA or your inbox on a schedule

PSA, RMM and security integration

Ticket enrichment, alert routing and evidence into your compliance tool. Priced per integration.

Fixed price, optional maintenance
  • Alerts become tickets with the context already attached
  • Routing by client, severity and hours
  • Evidence pushed to your compliance tool automatically
How I work

Four rules

01

Signed written authorisation, every time

No testing starts without a signed authorisation that names the systems, the dates and the people. Verbal permission and a line in an email are not authorisation.

02

Read-only by design

Anything I build for you runs on read-only credentials. It cannot change your systems or your clients' systems, and that is the reason you can trust it near them.

03

Drafts, never sends

Ticket replies, client updates, remediation steps. Everything is drafted for a person to read and send. Nothing goes out on its own.

04

No on-call, no monitoring, no incident response

Varstel is not a managed security service. I help you get ready, find what is wrong and fix it in order. I do not sit on a pager.

About

Who you are dealing with

I'm Abraham Ndimele, a practising security operations engineer based in Kent. I hold the OSCP and SSCP and spend my working week running detection, vulnerability management and security tooling for a large estate, which means the findings I write go to people who have to act on them.

Varstel is how I make that experience available to MSPs that need a security lead but cannot justify the hire. It is one person by design. You speak to the engineer, and the engineer does the work.

OSCPOffensive Security Certified Professional
SSCPISC2 Systems Security Certified Practitioner
Kent, EnglandUK-based, UK hours
In practice dailydetection, vulnerability management and tooling for a large estate
Contact

Start a conversation

Tell me a little about your MSP and what is prompting the conversation. I reply personally, usually within two business days.

Or email info@varstel.co.uk.
Your details are used only to reply to you.

Please tell me your name.
That email doesn't look right.
0 / 4000
Please write at least a sentence.

Message received.

I reply personally, usually within two business days. If it's urgent, email info@varstel.co.uk.