Describe the environment without exposing it
List workplace platforms, cloud providers, approximate users and devices, operating regions and critical services. Include identity and endpoint products, current SIEM or SOC arrangements and supplier boundaries. Do not post tenant IDs, live addresses, credentials or incident evidence in these forms.
Map responsibility before selecting coverage
| Activity | Decisions to record |
|---|---|
| Configuration | Who approves, implements, verifies and can roll back a change? |
| Alert handling | Who triages each source, during which hours, and who receives an escalation? |
| Containment | Who can suspend an account, isolate a device or restrict a workload? |
| Programme | Who accepts risk, funds remediation and reports to management? |
Turn “managed” into a defined service
Specify operating hours and time zones, included data sources, event volumes, exclusions and dependencies. Separate acknowledgement, investigation and containment targets. Establish how coverage begins, source failures are detected and new platforms enter scope.
Agree acceptance and exit before onboarding
Define what must be demonstrated: working access, supported log sources, a successful escalation exercise, named decision makers and usable reporting. Agree how credentials, configurations, retained evidence and open actions transfer at exit.
Build your services RFP to match your platforms and support needs, or send an enquiry with your NDA or RFP.
Prepare a brief before the scoping call
Describe the technology you use, your existing security support and the outcomes you want. Review relevant service options, clarify operating responsibilities, then send the RFP with your NDA.
Use the free managed cybersecurity services brief builder to record objectives, assessment areas, constraints and NDA preferences. Review the proposed scope, then send it directly to Atlant Security through the contact form.

