Frequently Asked Questions

Common questions about Emberline services, onboarding, managed security, disaster recovery, and support.

How long does onboarding typically take?

Onboarding timelines depend on your environment size and complexity, but generally take 2-4 weeks from contract to first detection. Initial assessment and tool deployment happen in the first week. We prioritize speed while ensuring proper baseline configuration and avoiding disruption to your operations.

What happens if you detect a security incident?

Our SOC team initiates our incident response protocol immediately: (1) containment — we isolate affected systems to prevent spread, (2) investigation — we analyze the scope and root cause, (3) communication — you receive status updates every 30 minutes until resolution. You also have a dedicated incident commander who coordinates response and serves as your single point of contact throughout the incident.

Can I run Emberline services alongside my existing tools?

Yes. We integrate with most SIEM, EDR, and cloud platforms. We don't require you to rip-and-replace your existing stack. In many cases, we improve the value of tools you already own by tuning detections, improving alert quality, or coordinating responses across multiple systems.

How often are recovery plans tested?

We recommend quarterly recovery testing — this ensures your team stays sharp and your plans stay current. Tests are realistic and include failover to secondary systems, communication with stakeholders, and full validation of critical applications. We provide detailed reports on what worked and what needs improvement.

What countries and regions do you support?

Emberline serves U.S. organizations remotely and through coordinated service coverage across North America. We have SOC operations and infrastructure teams based in the United States and coordinate with partner organizations for regional support. If you have specific geographic or data residency requirements, we can discuss options during scoping.

Do you offer managed services, staffing augmentation, or both?

We offer managed services — this means we own the 24/7 monitoring, threat detection, and response. We don't rent you staff. However, we also offer fractional leadership (part-time CISO or compliance lead) as a standalone service or bundled with managed services, depending on your needs.

How do you handle compliance and audit requirements?

Our security assurance team helps you build and maintain compliance programs for SOC 2, HIPAA, NIST, ISO 27001, and other frameworks. We create audit-ready documentation, validate controls, and participate in auditor discussions. You maintain responsibility for compliance, but we help ensure your security and infrastructure controls support your compliance obligations.

What if you detect a false alarm or alert fatigue?

Alert quality matters. Our detection engineers continuously tune our systems to reduce false positives. If we're generating too many alerts or missing important ones, we work with your team to refine detection logic. We use machine learning and behavioral analytics to distinguish genuine threats from normal activity.

Can you help with reporting to my board or regulators?

Yes. We provide executive dashboards, threat summaries, and audit-ready reporting. For our Resilience Plus clients, we offer fractional CISO services that include board-level communication, incident briefings, and strategy development. We help you explain security posture, incident status, and compliance progress in language your stakeholders understand.

What if I want to leave or switch to another provider?

We believe in earning your continued partnership. There's no lock-in or long-term contract requirement. If you want to transition to another provider, we provide full cooperation: data exports, documentation handoff, and support through the transition period. We'd rather have clients who choose to stay.

How do you stay current with emerging threats?

Our detection engineering team monitors threat intelligence feeds, participates in security communities, and continuously updates our detection logic. We also learn from incidents across our client base — patterns we see at one organization help us protect others. Your threat model evolves, and so does our monitoring.

Do you provide penetration testing or vulnerability assessment?

We offer vulnerability management and periodic security assessments as part of our Security Operations service. These include network scanning, configuration review, and risk prioritization. We can also coordinate or conduct red team exercises for organizations that want more adversarial-style testing.

What happens if there's a data breach? Who's liable?

Our contracts include appropriate liability limitations and insurance. We're responsible for the security controls we provide and maintain. You retain responsibility for your overall security program and incident response. In the event of an incident, we work collaboratively with your legal and insurance teams to understand what happened and how to prevent recurrence.

Can Emberline help with compliance to healthcare, financial, or other regulations?

Yes. We work with organizations subject to HIPAA (healthcare), PCI-DSS (payment cards), GLBA (financial), and other regulatory frameworks. We help you implement controls required by your framework, prepare for audits, and maintain ongoing compliance. Compliance is collaborative — you own regulatory obligations, we help you meet them.

How do you price services? Is there a minimum contract?

We price based on your organization's size, risk profile, and service requirements. There's no one-size-fits-all pricing. We provide detailed scopes and pricing after understanding your needs. Minimum engagements vary by service, but we're happy to discuss options that fit your budget and timeline.

Still have questions?

Reach out to our team. We're happy to discuss how Emberline can help your organization.