Security advisory, testing and AI operations

Your security function, without the hire.

Varstel gives you a security lead on retainer, fixed-price testing when you need it, and an operations agent that watches your PSA and RMM so you don't have to.

Built for UK managed service providers with ten to sixty staff, and the businesses they look after.

Start a conversation

Three things, done properly

Everything Varstel sells is one of these. Each is scoped in writing, priced before work starts, and delivered by the same person you spoke to.

AI operations agent

An assistant that lives in your Teams or Telegram, knows your PSA and RMM, tells you what needs attention before you ask, and drafts the replies. It never acts on its own. I run one for my own business every day and will show you it working before you commit to anything.

  • Pilot

    One PSA or RMM, Telegram, a weekly brief, three watchers and drafted replies. For the owner only.

    Fixed build fee, then a monthly retainer

  • Standard

    PSA and RMM together, Teams or Telegram, six watchers, drafted replies and a coverage view of which client devices lack EDR, backup or patching. Owner and technicians.

    Fixed build fee, then a monthly retainer

  • Full

    PSA, RMM, EDR, backup and mail. Everything in Standard plus client renewal clocks and monthly client summaries, for the whole team.

    Fixed build fee, then a monthly retainer

Read-only credentials only. The agent drafts and flags; a person sends and fixes. You own the box, the code and the credentials from handover.

Security advisory and testing

A named security lead for your MSP on a monthly retainer, backed by fixed-price assessments you can resell to your own clients. Twelve-month term, sixty days' notice, no surprises.

  • Foundation

    Monthly vulnerability review across your client estate, a written report you can white-label, and email advisory with a two-business-day response.

    Monthly retainer

  • Partner

    Everything in Foundation, plus a quarterly external assessment of one nominated client, Cyber Essentials readiness guidance, maintained policy templates and one client-facing call a month as your security lead.

    Monthly retainer

  • Principal

    Everything in Partner, with quarterly external assessments of up to three clients, an annual internal and Active Directory assessment, a half-day staff workshop and next-business-day advisory.

    Monthly retainer

Fixed-price packages

  • External vulnerability assessment

    The external attack surface of one organisation, a report, and a remediation call.

  • Cyber Essentials readiness

    Gap analysis against Cyber Essentials and CE Plus, a remediation plan and evidence-pack guidance. Annual.

  • Active Directory security review

    Configuration and attack-path review for one domain, with prioritised fixes.

  • ISO 27001 gap analysis

    Control-by-control gap analysis and a prioritised roadmap.

  • Insurer questionnaire support

    Complete and evidence a cyber-insurance renewal questionnaire. Annual.

  • Incident readiness tabletop

    A half-day tabletop exercise and a review of your incident response plan. Readiness, not response.

Automation and integration

The glue between your PSA, RMM and security tooling. Sold on its own when you are not ready for an agent, and as the first phase of every agent build.

  • Client onboarding and offboarding

    The process every MSP does by hand and gets slightly wrong each time, automated end to end.

    Fixed price, optional maintenance

  • Security reporting automation

    A monthly client security report generated from the tools you already run.

    Fixed price, optional maintenance

  • PSA, RMM and security integration

    Ticket enrichment, alert routing and evidence into your compliance tool. Priced per integration.

    Fixed price, optional maintenance

How I work

Signed written authorisation, every time
No testing starts without a signed authorisation that names the systems, the dates and the people. Verbal permission and a line in an email are not authorisation.
Read-only by design
Anything I build for you runs on read-only credentials. It cannot change your systems or your clients' systems, and that is the reason you can trust it near them.
Drafts, never sends
Ticket replies, client updates, remediation steps. Everything is drafted for a person to read and send. Nothing goes out on its own.
No on-call, no monitoring, no incident response
Varstel is not a managed security service. I help you get ready, find what is wrong and fix it in order. I do not sit on a pager.

About

I'm Abraham Ndimele, a practising security operations engineer based in Kent. I hold the OSCP and SSCP and spend my working week running detection, vulnerability management and security tooling for a large estate, which means the findings I write go to people who have to act on them.

Varstel is how I make that experience available to MSPs that need a security lead but cannot justify the hire. It is one person by design. You speak to the engineer, and the engineer does the work.

Contact

Tell me a little about your MSP and what is prompting the conversation. I reply personally, usually within two business days.

Thank you. Your message has been received and I will reply personally.

Or email info@varstel.co.uk. Your details are used only to reply to you.