Cyber One Solutions logo.
Get Support

Our Technology

Our Technology Stack

Enterprise-Grade Tools, Purpose-Built for Protecting Your Business.

We do not cobble together cheap tools and call it a managed service. We evaluated every product in our stack for reliability, security depth, and vendor support. We also checked how well each one integrates with the rest of the environment. Here is what we use and why it matters.

Standardizing on a curated technology stack means our engineers know every tool deeply. We do not learn on your time. We deploy with confidence because we have deployed these exact tools hundreds of times.

Every number below reflects deliberate decisions about how we operate. We run each tool in our own environment before we ever deploy it for a client. As a result, our engineers have genuine hands-on depth in every platform we recommend.

9
Technology layers covered
35+
Vetted vendor solutions
100%
Tools deployed in-house first
0
Unvetted or untested tools
Technology by Layer

Every Layer of the Stack, Explained.

9 technology layers covering 36 vetted solutions. Expand any section to see the tools we deploy, why we chose them, and what they mean for your business.

Our Technology Stack

The platforms we run on, and the reasons we chose them.

Our technology stack is the set of tools our engineers use every day. We select each tool after a documented evaluation. We then review every product each year.

A stack that does not evolve becomes a liability, so we treat technology reviews as a standing commitment.

Principles behind tool selection.

We select tools based on operational reliability, integration depth, security posture, vendor stability, and total cost over a multi-year horizon.

We avoid products from vendors with a history of aggressive acquisition, product abandonment, or sudden pricing changes. Our goal is a stack clients can rely on for years.

Integration over individual features.

A tool that integrates well with the rest of the stack almost always beats a tool with slightly better features in isolation.

Our monitoring platform, ticketing system, documentation platform, security operations stack, and alerting pipeline all feed a single operational view. That integration produces a coherent service rather than a collection of disconnected point products.

Security of the stack itself.

The tools a managed service provider uses are a high-value target for attackers. A compromised provider tool can cascade across every client it touches.

We apply the same security discipline to our internal stack that we apply to client environments. That includes multi-factor authentication, privileged access management, segmented administrative access, and ongoing monitoring of our own vendor supply chain.

The categories of tooling behind a managed service.

A mature managed service is built from a small number of tool categories, each doing a distinct job. Remote monitoring and management (RMM) keeps an agent on every device for patching, monitoring, and remote access.

Endpoint detection and response (EDR) or managed detection and response (MDR) watches process behavior on the endpoint and reacts to threats that signature-based antivirus misses.

Alongside those sit backup and disaster recovery for recoverability, identity and access management for controlling who can reach what, and a professional services automation platform that tracks every ticket, contract, and service level.

Each category matters because a gap in any one of them becomes the weakest link across the whole environment.

Why EDR and MDR replaced traditional antivirus.

Traditional antivirus matches files against a list of known-bad signatures, which leaves it blind to novel and fileless attacks.

Endpoint detection and response instead watches how processes behave, flags suspicious activity in real time, and gives engineers a forensic timeline of an incident.

Managed detection and response adds a human review layer on top, so the highest-risk alerts get investigated by an analyst rather than sitting in a queue.

For a business without a full internal security team, that combination is the difference between catching an intrusion early and discovering it after the damage is done.

Why identity and backup anchor every other control.

Stolen credentials are the leading entry point for breaches, so identity controls such as multi-factor authentication, conditional access, and least-privilege permissions remove the single most exploited weakness first.

A strong identity layer limits how far an attacker can move even after a single account is compromised.

Backup is the final safety net. Image-based backups with off-site copies, encryption, and tested restores mean a ransomware event becomes a recovery exercise rather than a business-ending event.

Recovery time and recovery point objectives should be defined per business before an incident, not improvised during one.

Common Questions

Frequently Asked Questions

Can I see a list of the specific products in your stack?

Yes. We publish the primary tools by category on this page. We are also open about which products we use under non-disclosure for clients evaluating our operational maturity. The specific mix sometimes changes within a category.

We brief clients on any material tool change before it affects their environment.

Do you resell the tools in your stack to clients?

Some tools are client-facing and resold transparently, such as endpoint protection, email security, and backup. Others are internal operational tools included in the managed service fee. We clearly distinguish between the two in every proposal.

What backup and disaster recovery platform does Cyber One Solutions use?

We use Acronis for business continuity and disaster recovery.

Acronis provides image-based backup with AES-256 encryption, bare-metal restore capabilities, cloud backup with off-site replication, and automated backup verification so we know backups are recoverable before a disaster occurs.

Recovery time and recovery point objectives are defined per client based on their specific business requirements and tolerance for downtime.

What helpdesk and ticketing platform does Cyber One Solutions use?

We use HaloPSA as our professional services automation and ticketing platform. Every client request, incident, change, and contract is tracked in HaloPSA with defined SLAs and response time targets. This gives clients a consistent support experience.

It also gives our engineers full visibility into every client environment, open tickets, and service history. SLA compliance is tracked and reported from the same platform.

What is the difference between antivirus and EDR?

Traditional antivirus compares files against a database of known threats, so it only catches attacks that have already been seen and cataloged.

Endpoint detection and response (EDR) instead monitors how programs behave on a device, which lets it flag suspicious activity even when the specific threat is brand new or fileless.

EDR also records a forensic timeline of an incident so engineers can understand exactly what happened and contain it. We deploy EDR-class endpoint protection across managed devices for that behavioral coverage rather than relying on signatures alone.

What is an RMM and why does a managed service provider need one?

RMM stands for remote monitoring and management.

It is the agent-based platform that lets a provider see the health of every managed device, apply operating system and application patches automatically, run scripts, and connect remotely to fix issues without a site visit.

Without an RMM, a provider is reacting to problems after users report them rather than catching them early. It is the visibility layer that makes proactive, consistent support possible across every endpoint in an environment.

How often does Cyber One Solutions review its technology stack?

We review every product in the stack at least once a year, and we re-evaluate a category sooner if a vendor changes direction, pricing, or reliability. A stack that never changes eventually becomes a liability as threats and platforms evolve.

Each review weighs operational reliability, integration depth, security posture, vendor stability, and total cost over a multi-year horizon. When we make a material change that affects a client environment, we brief the client before it takes effect.