Your security function,
without the hire.
Varstel gives you a security lead on retainer, fixed-price testing when you need it, and an operations agent that watches your PSA and RMM so you don't have to.
Built for UK managed service providers with ten to sixty staff, and the businesses they look after.
Three things, done properly
Everything Varstel sells is one of these. Each is scoped in writing, priced before work starts, and delivered by the same person you spoke to.
A named security lead for your MSP on a monthly retainer, backed by fixed-price assessments you can resell to your own clients. Twelve-month term, sixty days' notice, no surprises.
Foundation
Monthly vulnerability review across your client estate, a written report you can white-label, and email advisory with a two-business-day response.
- Monthly vulnerability review, whole estate
- White-label report in your branding
- Email advisory, two-business-day response
Partner
Everything in Foundation, plus a quarterly external assessment of one nominated client, Cyber Essentials readiness guidance, maintained policy templates and one client-facing call a month as your security lead.
- Everything in Foundation
- Quarterly external assessment, one client
- Cyber Essentials readiness guidance
- Policy templates, maintained
- One client-facing call a month, as your security lead
Principal
Everything in Partner, with quarterly external assessments of up to three clients, an annual internal and Active Directory assessment, a half-day staff workshop and next-business-day advisory.
- Everything in Partner
- Quarterly external assessments, up to three clients
- Annual internal and Active Directory assessment
- Half-day staff workshop
- Next-business-day advisory
External vulnerability assessment one organisation
The external attack surface of one organisation, a report, and a remediation call.
Cyber Essentials readiness annual
Gap analysis against Cyber Essentials and CE Plus, a remediation plan and evidence-pack guidance.
Active Directory security review one domain
Configuration and attack-path review for one domain, with prioritised fixes.
ISO 27001 gap analysis
Control-by-control gap analysis and a prioritised roadmap.
Insurer questionnaire support annual
Complete and evidence a cyber-insurance renewal questionnaire.
Incident readiness tabletop half day
A half-day tabletop exercise and a review of your incident response plan. Readiness, not response.
An assistant that lives in your Teams or Telegram, knows your PSA and RMM, tells you what needs attention before you ask, and drafts the replies. It never acts on its own. I run one for my own business every day and will show you it working before you commit to anything.
Pilot start here
One PSA or RMM, Telegram, a weekly brief, three watchers and drafted replies. For the owner only.
- One integration: your PSA or your RMM
- Weekly brief every Monday morning
- Three watchers of your choice
- Drafted replies for you to review and send
- Read-only credentials, held by you
Standard most MSPs
PSA and RMM together, Teams or Telegram, six watchers, drafted replies and a coverage view of which client devices lack EDR, backup or patching. Owner and technicians.
- PSA and RMM, correlated
- Daily brief, plus alerts as they happen
- Six watchers
- Coverage view: EDR, backup, patching per device
- Technician access with per-person briefs
Full whole team
PSA, RMM, EDR, backup and mail. Everything in Standard plus client renewal clocks and monthly client summaries, for the whole team.
- Five integrations: PSA, RMM, EDR, backup, mail
- Renewal clocks per client and contract
- Monthly client summary you can forward
- Whole-team access
- Quarterly review of watchers with you
The glue between your PSA, RMM and security tooling. Sold on its own when you are not ready for an agent, and as the first phase of every agent build.
Client onboarding and offboarding
The process every MSP does by hand and gets slightly wrong each time, automated end to end.
- Accounts, groups, licences, RMM enrolment, PSA records
- Offboarding that actually removes everything
- A checklist that runs itself and reports what it did
Security reporting automation
A monthly client security report generated from the tools you already run.
- Pulls from your RMM, EDR, backup and patching tools
- One report per client, in your branding
- Delivered to the PSA or your inbox on a schedule
PSA, RMM and security integration
Ticket enrichment, alert routing and evidence into your compliance tool. Priced per integration.
- Alerts become tickets with the context already attached
- Routing by client, severity and hours
- Evidence pushed to your compliance tool automatically
Four rules I don't bend
Signed written authorisation, every time
No testing starts without a signed authorisation that names the systems, the dates and the people. Verbal permission and a line in an email are not authorisation.
Read-only by design
Anything I build for you runs on read-only credentials. It cannot change your systems or your clients' systems, and that is the reason you can trust it near them.
Drafts, never sends
Ticket replies, client updates, remediation steps. Everything is drafted for a person to read and send. Nothing goes out on its own.
No on-call, no monitoring, no incident response
Varstel is not a managed security service. I help you get ready, find what is wrong and fix it in order. I do not sit on a pager.
One person, by design
I'm Abraham Ndimele, a practising security operations engineer based in Kent. I hold the OSCP and SSCP and spend my working week running detection, vulnerability management and security tooling for a large estate, which means the findings I write go to people who have to act on them.
Varstel is how I make that experience available to MSPs that need a security lead but cannot justify the hire. It is one person by design. You speak to the engineer, and the engineer does the work.
Start a conversation
Tell me a little about your MSP and what is prompting the conversation. I reply personally, usually within two business days.
Or email info@varstel.co.uk.
Your details are used only to reply to you.