A Fortify 24x7 brand. Security and continuity built around clinical work.Client sign inReach an engineer
Care Secure Systems
A
Wing A / Detection and response

An alert at two in the morning helps only if somebody is awake to read it.

Ransomware does not wait for the practice to open. It arrives at the hour when nobody is looking, encrypts what it can reach, and leaves a note where the schedule used to be. These six lines put a behavioral agent on every managed machine, feed what it sees into one correlated stream, and place people in front of that stream around the clock. What separates the lines is not how much they see. It is what happens next.

SentinelOneFluency24x7 monitoring
6 lines / endpoints and nodes / three levels of response
Lines in this wing6
ProductsSentinelOne and Fluency
Counted asEndpoint or node
Choice that mattersResponse level

Watching is the easy half

A detection product on its own produces a queue. Somebody has to work the queue, and in a fourteen person practice that somebody is usually the office manager who also handles payroll, the fax line, and the patient who is unhappy about a copay. The queue does not get worked. It gets muted.

What we sell here is the working of the queue. The SentinelOne agent detects behavior rather than matching a list of known files, which is what catches the attacks that arrive freshly compiled. Fluency then holds and correlates activity across sources, so an analyst opening a case sees the sequence around an event instead of the event alone.

The line you pick decides what happens at three in the morning

Managed detection notifies. Someone reads the alert, judges it, and contacts you with what they found and what they recommend. That is the right shape for a practice with an on-call technical person and a tolerance for a phone call.

The extended tier widens the picture to take in servers, cloud workloads, network activity, and directory events, with hunting continuing overnight. The plus tier goes one step further and lets the operations team remediate directly rather than waiting for a callback. That last difference sounds small on a price list and is enormous at four in the morning on a holiday weekend.

Buying the notify tier and expecting containment is the single most common disappointment in this category. Choose deliberately.
Lines in this wing

Line detail and rates

Each figure here is read live out of billing. Whatever you pick sits waiting on the side panel while you keep reading down the page.

Fortify-MDRLine detail

Managed Detection and Response

SentinelOne agent with round the clock monitoring

A behavioral endpoint agent on every machine you enroll, watched continuously by an operations team that reads what it produces. When something matters, a person contacts you with the finding and a recommendation rather than a dashboard link.

  • Behavioral detection on Windows, macOS, and Linux, not signature matching alone.
  • Monitoring and alerting run continuously, including nights, weekends, and holidays.
  • Findings arrive with context: what ran, where it came from, and what it touched.
ProductSentinelOne, with monitoring by Fortify 24x7
ReachesWindows, macOS, and Linux endpoints you enroll
WatchContinuous monitoring and alerting
ResponseNotification and written recommendation
Best suited toReception, clinical rooms, and the back office
Counted asOne protected endpoint, charged monthly
Loadingper protected endpoint
charged monthly, in advance
QTY
Fortify-XDRLine detail

Extended Detection and Response

SentinelOne Complete with cross layer visibility

The wider version. Detection stops being an endpoint-only conversation and starts including servers, cloud workloads, network activity, and directory events, with threat hunting running through the night against the whole picture.

  • Visibility across endpoints, servers, cloud workloads, network, and directory.
  • Continuous threat hunting rather than waiting for an alert to fire on its own.
  • Behavioral analytics for accounts and entities, which is where takeover shows up.
ProductSentinelOne Complete, with Fluency correlation
ReachesEndpoints plus server, cloud, network, and directory sources
WatchContinuous monitoring with active hunting
ResponseNotification, guidance, and coordinated action with your team
Best suited toMulti-site groups and anywhere with servers or cloud workloads
Counted asOne protected endpoint, charged monthly
Loadingper protected endpoint
charged monthly, in advance
QTY
Fortify-XDR+Line detail

Extended Detection with SOC Remediation

The tier where the operations team acts without waiting for you

Everything the extended tier covers, with the authority to remediate identified events directly. Nobody has to reach a practice owner at four in the morning to get permission to isolate a machine that is actively encrypting a share.

  • The operations team remediates what it identifies, instead of ringing you first.
  • Isolation, process termination, and rollback where the platform supports it.
  • The action taken is written up afterwards, in the order it happened.
ProductSentinelOne Complete, with Fluency correlation
ReachesEndpoints plus server, cloud, network, and directory sources
WatchContinuous monitoring with active hunting
ResponseDirect remediation of identified events
Best suited toPractices with no technical staff available overnight
Counted asOne protected endpoint, charged monthly
Loadingper protected endpoint
charged monthly, in advance
QTY
Fortify-MDR-K8Line detail

Managed Detection for Kubernetes Nodes

The same watch, applied to containerized workloads

For groups running container workloads, usually behind a patient portal, an analytics pipeline, or a home-grown integration between systems. Priced per node rather than per endpoint because that is the unit a cluster is built from.

  • A SentinelOne agent built for Kubernetes nodes rather than desktops.
  • Continuous monitoring and alerting on the same schedule as the endpoint line.
  • Most single-site practices never need this. Buy it only if you run a cluster.
ProductSentinelOne for Kubernetes
ReachesKubernetes nodes you enroll
WatchContinuous monitoring and alerting
ResponseNotification and written recommendation
Best suited toGroups running containerized workloads of their own
Counted asOne kubernetes node, charged monthly
Loadingper Kubernetes node
charged monthly, in advance
QTY
Fortify-XDR-K8Line detail

Extended Detection for Kubernetes Nodes

Cross layer detection where the workload lives in containers

The extended tier applied per node. Cluster activity joins the same correlated stream as your endpoints and cloud accounts, so an analyst is not switching consoles halfway through working out what happened.

  • SentinelOne Complete for Kubernetes, with hunting across the wider estate.
  • Cluster telemetry correlated alongside endpoint, cloud, and directory sources.
  • Sized per node, which is how cluster capacity is actually planned.
ProductSentinelOne Complete for Kubernetes
ReachesKubernetes nodes plus the correlated wider estate
WatchContinuous monitoring with active hunting
ResponseNotification, guidance, and coordinated action
Best suited toClinical software teams and analytics platforms
Counted asOne kubernetes node, charged monthly
Loadingper Kubernetes node
charged monthly, in advance
QTY
Fortify-XDR+K8Line detail

Kubernetes Detection with SOC Remediation

Direct action on cluster nodes

The remediation tier for containerized workloads. Identified events get acted on by the operations team at the node, on the same terms as the endpoint plus tier.

  • Direct remediation at the node by the operations team.
  • Joined to everything else you run rather than treated as a separate island.
  • Written up afterwards with the actions listed in sequence.
ProductSentinelOne Complete for Kubernetes
ReachesKubernetes nodes plus the correlated wider estate
WatchContinuous monitoring with active hunting
ResponseDirect remediation of identified events
Best suited toProduction clusters with no overnight engineering cover
Counted asOne kubernetes node, charged monthly
Loadingper Kubernetes node
charged monthly, in advance
QTY
Included scope

What you get on these lines

  • Agent deployment help and the first round of tuning against your clinical software.
  • Continuous monitoring by people, on every day of the year.
  • A written record of events, in sequence, whenever something happens.
  • Retention and search across correlated activity through Fluency.
Honest scope

Where this wing stops

This category is sold almost everywhere as though it abolishes bad days. It does not, and the edge deserves to be drawn precisely.

  • Detection is not prevention. A behavioral agent is genuinely good at catching and halting activity underway. What it cannot promise is that nothing ever starts. Allowlisting in Wing B and backup in Wing F exist because that promise cannot be made.
  • We see exactly what the agent sees. An enrolled machine is covered. A personal laptop nobody enrolled, a tablet in a treatment room that never took an agent, and the internals of your electronic health record vendor cloud are all outside this line.
  • The response level is a real choice, not a marketing tier. Managed detection notifies. The plus tiers act. If nobody at the practice is reachable overnight, buying the notify tier means an alert waits until morning.
  • Tuning takes weeks, not hours. Clinical and dental software does unusual things to a file system. The first two weeks involve teaching the platform which of those things are normal for you.
  • We do not decide whether something is a reportable breach. We hand over evidence and a timeline, fast and in detail. The four factor assessment and every notification deadline sit with the privacy officer and whoever advises the practice legally.
  • The three cluster lines are priced by node, and most practices need none of them. If you do not run a cluster, skip those three lines entirely. We would rather say so here than sell you capacity you cannot use.
NOTE 01

Heads up: card statements show FORTIFY 24X7 - Care Secure Systems is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.