Case Study A True 24/7 SOC for MSSPs: Ever Nimble The Client Ever Nimble is an award-winning managed services provider (MSP) and managed security services provider (MSSP) with over 100 staff and offices in Perth, Melbourne, Gold Coast, Swansea (UK), and Calgary (CA). They deliver a complete range of cyber security and IT solutions, serving clients across industries spanning mining, financial services, law firms, and aged care. Customer Challenges Standing out in a crowded market, with more MSPs adopting a cyber-first approach Finding a true 24/7 SOC solution without needing to invest millions or build a platform The ThreatDefence Solution Responsive and reliable 24/7 SOC A wide breadth of integrations, including custom integrations Support from seasoned cyber security experts, including advanced support during incident response and investigations The Shift to an MSSP Model: Finding the Right 24/7 SOC Partner Ever Nimble had always been a cyber-first MSP, and early on it was a key point of difference that allowed them to lead the way. When competitors started catching up, they knew it was time for change to maintain their competitive edge. The solution was to transition from a cyber-focused MSP to a true MSSP model – so they could deliver end-to-end IT support, cloud services, and strong cyber security for customers. To kick off this process, they reviewed their cyber security stack against MSSP offerings and noticed a big gap was a 24/7 Security Operations Centre (SOC). While their offices in Perth and Swansea allowed them to offer extended support hours, they weren’t delivering continuous, around-the-clock cyber security monitoring. They saw that larger MSSPs were operating SOCs effectively, but the in-house platforms those organisations had built were expensive and unrealistic to replicate. Chris Morrissey, Ever Nimble’s Founder, CEO, and Managing Director, says: “These MSSPs had built systems with software like Splunk, which would have cost millions of dollars that we didn’t have.” From here, Ever Nimble went to market to find a partner that could deliver 24/7 monitoring for all clients, operating on a scalable monthly model and ingesting every single log source. The latter was a key requirement, and something that not all SOC solutions could offer. Chris explains: “Often we see companies claiming they have 24/7 monitoring, but they’re really just monitoring a laptop or an email account, they’re not monitoring the firewall, cloud systems, switches, or Wi-Fi points – any application that can provide logs.” The search for a true SOC partner involved in-depth research that initially focused on American vendors. While these vendors appeared to be leading the way, on closer inspection their offering didn’t match the hype, and Chris changed up his approach. “I decided to look beyond the large global vendors and focus on providers with an ambitious vision. That’s when I found ThreatDefence, who were Sydney based. When I reached out to them, I spoke to the COO straight away. This was a good sign to me, because we were on a growth journey ourselves and we found a partner with strong alignment in ambition and direction.” ThreatDefence also met Ever Nimble’s non-negotiable criteria for selecting a software vendor: a clear commitment to innovation. Chris comments: “I wanted to see a roadmap that had some good recent development but also some forward thinking and planning. ThreatDefence were not only able to show me everything they’d built recently, but also everything they were planning to build. To me that’s non-negotiable, because there are some great products out there but in cyber security without constant development, redevelopment, and new features, hackers will get one step ahead. It’s important that any software we pick stays at the forefront.” Smooth, Expert-Led Onboarding Once onboarding got underway, Ever Nimble allocated an internal champion who worked closely with the ThreatDefence team to map out a plan and swiftly roll out the 24×7 SOC capability. Chris says: “The endpoint and Microsoft 365 deployments were very quick. If you have something like Intune or an RMM software, you can deploy ThreatDefence within a day.” Staying true to their promise, the ThreatDefence team integrated all required systems within weeks. This flexibility and readiness to adapt was a significant win for Ever Nimble, demonstrating the advantage of working with a partner that listens to their customers’ needs and genuinely wants to support requirements. As a result, Ever Nimble saved significant time and cost, while enhancing the security services delivered to their clients. Chris comments: “If we had to build those ourselves, it would have taken years.” Not All SOCs Are Equal Ever Nimble has been using the solution since 2022, ensuring they can deliver true SOC capabilities. Chris comments: “A big problem in our industry is that not all SOCs are equal. A lot of people think they’ve got 24/7 monitoring, but all it means is there’s a bit of software sending an alert somewhere that someone might look at. If you look at some of the big breaches in Australia recently, alerts were sent, they just weren’t being monitored.” Being backed by real security specialists has also provided peace of mind for both the Ever Nimble team and their customers. Chris says: “If your team aren’t watching, ThreatDefence are. When I’m pitching to customers I’ll often say there’s watchers watching the watchers. That gives our customers comfort that it’s not just us looking after them, it’s the ThreatDefence team as well.” An Intuitive Platform, Rapid insights, and Expert Support With the ability to reduce noise and alert fatigue, increase confidence, and shorten response times, the platform has earned the tick of approval from Ever Nimble’s team. Chris says: “From a technical capability, I always judge a product on the happiness of my team. I know they find it to be a very intuitive platform; there’s a lot of trust in it and it’s easy to use. There’s no shortage of data or alerts, and the ThreatDefence team gives us better context around what they’re telling us. When something is triaged and escalated to us, you know someone real has already looked at it. Our team can respond faster and more meaningfully, which is what I really love. My greatest fear as an MSP owner isn’t that we won’t receive the alert, it’s that we’ll receive so many that we’ll miss something. ThreatDefence gives me confidence we won’t miss something.” ThreatDefence also plays an important role when Ever Nimble onboards new customers. When a higher risk customer is identified, ThreatDefence is brought in early on, allowing issues to be spotted within hours of deployment. In addition, the partnership allows Ever Nimble to draw upon seasoned cyber security professionals when potentially malicious activity is detected. In one instance, a significant volume of data was observed moving across a customer’s AWS environment – from one region to another across the globe. Chris recalls: “Alerts were telling us this was happening, we were on it in ten minutes and we were concerned it was some sort of data exfiltration. We immediately engaged ThreatDefence to assist, and the team were incredible in confirming it was an internal AWS backup procedure – not a mass removal of data. It was great to have absolute experts who can step in immediately when you think there’s a potential issue.” A True SOC That Wins and Retains Customers The partnership has strengthened Ever Nimble’s commercial model, enhanced their value proposition, supported growth, and helped them win and retain customers. Chris says: “Commercially, ThreatDefence has helped us win some fantastic clients because of its breadth of capability, speed to deploy, extensive dashboards, and the fact that it’s co-manageable. If we win a client that’s got an IT manager we add them into the portal and they can see everything we can, and there are really good reports in there. It’s helped us win clients with sophisticated cyber security requirements time and time again. I’m very grateful to the ThreatDefence team for helping me to achieve a goal that was set by my board a few years ago, which was to truly set us apart from our competition.” With ThreatDefence continuously driving innovation and platform advancement, Ever Nimble can keep customers protected and resilient without placing additional strain on their internal teams. Chris notes: “I now know if we’d built an in-house solution from the start we’d have to keep developing. I see the enhancements that are coming in ThreatDefence every single month, especially around AI and automation, and we simply wouldn’t be able to keep up. Any MSP that thinks they can probably isn’t being realistic. We’ve got a big automation team, but do we want to build a SOC/SIEM solution as well? No, we wouldn’t do a good job. That’s one of my sayings – if you can’t do a good job, get a partner who can do it for you. ThreatDefence have been that partner.” As a result of partnering with ThreatDefence, Ever Nimble has closed the SOC gap in their solution stack, and can deliver enterprise-grade security for customers with great commercial and operational outcomes. Just as important as the platform itself is the team behind it. Chris reflects: “They’ve been easy to deal with over the years. That sounds simple, but finding cyber security providers that are easy to deal with in this day and age is becoming harder and harder. Great team, great support. Knowing ThreatDefence always has our back helps me sleep at night.” You Might Also Like ← → MSP Vigilant Asia Vigilant Asia is an award-winning Managed Security Service Provider operating a 24 x 7 x 365 Security Operations Centre, offering a full range of Cybersecurity solutions and services. MSP Klik Solutions Klik Solutions is a managed services provider (MSP) with headquarters in Baltimore, Maryland. Protect Your Organization With ThreatDefence Get Started
MSP Vigilant Asia Vigilant Asia is an award-winning Managed Security Service Provider operating a 24 x 7 x 365 Security Operations Centre, offering a full range of Cybersecurity solutions and services.
MSP Klik Solutions Klik Solutions is a managed services provider (MSP) with headquarters in Baltimore, Maryland.