Security advisory, testing and AI operations
Your security function, without the hire.
Varstel gives you a security lead on retainer, fixed-price testing when you need it, and an operations agent that watches your PSA and RMM so you don't have to.
Built for UK managed service providers with ten to sixty staff, and the businesses they look after.
Three things, done properly
Everything Varstel sells is one of these. Each is scoped in writing, priced before work starts, and delivered by the same person you spoke to.
AI operations agent
An assistant that lives in your Teams or Telegram, knows your PSA and RMM, tells you what needs attention before you ask, and drafts the replies. It never acts on its own. I run one for my own business every day and will show you it working before you commit to anything.
-
Pilot
One PSA or RMM, Telegram, a weekly brief, three watchers and drafted replies. For the owner only.
-
Standard
PSA and RMM together, Teams or Telegram, six watchers, drafted replies and a coverage view of which client devices lack EDR, backup or patching. Owner and technicians.
-
Full
PSA, RMM, EDR, backup and mail. Everything in Standard plus client renewal clocks and monthly client summaries, for the whole team.
Read-only credentials only. The agent drafts and flags; a person sends and fixes. You own the box, the code and the credentials from handover.
Security advisory and testing
A named security lead for your MSP on a monthly retainer, backed by fixed-price assessments you can resell to your own clients. Twelve-month term, sixty days' notice, no surprises.
-
Foundation
Monthly vulnerability review across your client estate, a written report you can white-label, and email advisory with a two-business-day response.
-
Partner
Everything in Foundation, plus a quarterly external assessment of one nominated client, Cyber Essentials readiness guidance, maintained policy templates and one client-facing call a month as your security lead.
-
Principal
Everything in Partner, with quarterly external assessments of up to three clients, an annual internal and Active Directory assessment, a half-day staff workshop and next-business-day advisory.
Fixed-price packages
-
External vulnerability assessment
The external attack surface of one organisation, a report, and a remediation call.
-
Cyber Essentials readiness
Gap analysis against Cyber Essentials and CE Plus, a remediation plan and evidence-pack guidance. Annual.
-
Active Directory security review
Configuration and attack-path review for one domain, with prioritised fixes.
-
ISO 27001 gap analysis
Control-by-control gap analysis and a prioritised roadmap.
-
Insurer questionnaire support
Complete and evidence a cyber-insurance renewal questionnaire. Annual.
-
Incident readiness tabletop
A half-day tabletop exercise and a review of your incident response plan. Readiness, not response.
Automation and integration
The glue between your PSA, RMM and security tooling. Sold on its own when you are not ready for an agent, and as the first phase of every agent build.
-
Client onboarding and offboarding
The process every MSP does by hand and gets slightly wrong each time, automated end to end.
-
Security reporting automation
A monthly client security report generated from the tools you already run.
-
PSA, RMM and security integration
Ticket enrichment, alert routing and evidence into your compliance tool. Priced per integration.
How I work
- Signed written authorisation, every time
- No testing starts without a signed authorisation that names the systems, the dates and the people. Verbal permission and a line in an email are not authorisation.
- Read-only by design
- Anything I build for you runs on read-only credentials. It cannot change your systems or your clients' systems, and that is the reason you can trust it near them.
- Drafts, never sends
- Ticket replies, client updates, remediation steps. Everything is drafted for a person to read and send. Nothing goes out on its own.
- No on-call, no monitoring, no incident response
- Varstel is not a managed security service. I help you get ready, find what is wrong and fix it in order. I do not sit on a pager.
About
I'm Abraham Ndimele, a practising security operations engineer based in Kent. I hold the OSCP and SSCP and spend my working week running detection, vulnerability management and security tooling for a large estate, which means the findings I write go to people who have to act on them.
Varstel is how I make that experience available to MSPs that need a security lead but cannot justify the hire. It is one person by design. You speak to the engineer, and the engineer does the work.
Contact
Tell me a little about your MSP and what is prompting the conversation. I reply personally, usually within two business days.