The short answer
AgileSECURE is built using Guardz as one of its core components. Guardz is a cyber security platform made for managed service providers, and we run it on its Ultimate plan with the full suite in use. That means identity threat detection on Microsoft 365, Check Point email security, SentinelOne endpoint protection, cloud file-sharing controls, staff awareness training and phishing simulation, dark web and external exposure monitoring, and 24/7 managed detection and response by human analysts.
Guardz is not the whole of AgileSECURE. The other core components are Microsoft 365 backup and email archiving through Dropsuite from NinjaOne, Microsoft 365 security configuration, and the governance and review work, all run by Agile IT every day and measured against the SMB1001 framework.
Naming the platform matters because "we use a security suite" tells you nothing. A named platform, on a named plan, lets you check what is actually switched on, compare it with what you were quoted elsewhere, and ask sharper questions of anyone who looks after your technology, us included.
Who Guardz is
Guardz was founded in 2022 by Dor Eisner and Alon Lavi, and operates from Miami and Tel Aviv. It sells only through managed service providers, and it was built for small and medium businesses from the start rather than cut down from an enterprise product. It has raised US$84 million to date, including a US$56 million Series B in June 2025 in which SentinelOne, the endpoint security company whose technology sits inside the Ultimate plan, was one of the investors. Guardz has been available to Australian MSPs since February 2024 and now has local channel staff here.
We explained the reasons we chose it in why we chose Guardz Ultimate for Microsoft 365. This piece is the reference version: what is inside the platform, and where its edges are.
What the Ultimate plan includes
Guardz sells three paid plans, Pro, Ultimate and Elite. Every plan shares the same core controls. What changes as you step up is the depth of the endpoint and email engines, and whether a 24/7 analyst team is watching. Pro does not include managed detection and response at all, which is why we do not build on it. Ultimate is the first plan where people, not just software, are on the other end of an alert.
Inside AgileSECURE, every Ultimate module is in use:
- Identity threat detection and response. Watches Microsoft 365 sign-ins and account behaviour for impossible travel, unfamiliar sign-ins, MFA bypass, stolen session tokens, suspicious inbox and forwarding rules, and risky app permissions. It can suspend the user, revoke their sessions and force a password reset.
- Email security, powered by Check Point. Guardz embedded Check Point's Harmony Email engine in November 2025. It connects to Microsoft 365 through the API, with no change to your mail routing, and checks for phishing, impersonation, business email compromise and malicious links and attachments. We covered the change in Guardz Ultimate now uses Check Point for email security.
- Endpoint detection and response, powered by SentinelOne. Behaviour-based protection on each device, with the ability to isolate a machine, kill a process, quarantine a file and roll back changes after ransomware.
- 24/7 managed detection and response. Guardz runs its own security operations centre, staffed by human analysts working follow-the-sun shifts across North America, Europe and the Asia-Pacific region. Endpoint and identity detections that are judged malicious go to that team, who can quarantine, isolate or suspend. What they are allowed to do is agreed in advance, not decided in the middle of an incident.
- Cloud data protection. Finds SharePoint and OneDrive files shared publicly or externally, and flags excessive permissions and third-party app grants, with the ability to fix them through the API.
- Security awareness training and phishing simulation. Scheduled training for staff and realistic simulated phishing campaigns, so the human layer is tested rather than assumed.
- Exposure monitoring. Dark web monitoring for leaked credentials on your domain, scanning of your external footprint (domains, IP addresses and cloud assets), and a secure browsing extension that flags malicious sites and unsafe browser extensions.
All of it reports into one console, grouped by person rather than by tool, so a suspicious sign-in, an odd inbox rule and an alert on that person's laptop show up as one story rather than three.
Why one platform instead of five separate tools
Guardz published The 2026 State of MSP Threat Report in April 2026. It draws on telemetry from MSP-managed small business environments over 180 days, September 2025 to February 2026, across North America, EMEA and the Asia-Pacific region. Its central argument is that attackers are now logging in rather than breaking in, and that attacks cross layers. In the words of Elli Shlomo, Guardz's head of security research, "identity, email, endpoint, and cloud signals are chaining together".
The numbers in the report, all Guardz's own, show how that plays out:
- Roughly 28 to 30 per cent of sign-in attempts failed, a steady background of password spraying and credential stuffing rather than one-off campaigns.
- 89 per cent of monitored small businesses had at least one user with a confirmed credential compromise at any point in time.
- Session hijacking, where an attacker steals the token issued after a successful MFA sign-in, grew about 23 per cent and was the fastest-growing identity attack. We explained how that works in MFA session cookie hijacking.
- Inbox rules remained the number one way attackers stay hidden inside a compromised mailbox, forwarding invoice and payment emails and deleting the evidence. Confirmed business email compromise losses the team analysed ranged from $140,000 to $1.5 million.
- Abuse of legitimate remote management tools made up 26 per cent of endpoint threats, because that traffic looks like normal IT support.
Read together, a single attack can start with a leaked password, move to a hijacked session, set up an inbox rule, and end with a fraudulent payment or ransomware on a laptop. Five separate tools see five unconnected events. One platform, watched by one team, sees the chain. That is the practical reason the detection and response component of AgileSECURE is a unified platform rather than a collection of point products.
What the report means for an Australian business
Three findings stood out for the businesses we look after.
The Christmas break is a target. Ransomware rose to 8.2 per cent of all endpoint threats in December 2025, close to double the six-month average, which Guardz links to holiday staffing gaps. In Australia, the Christmas shutdown lands in our summer holidays, when offices can be closed for two or three weeks. Detection that keeps running when the office is shut is the part that matters most in that window.
Old sign-in methods are still an open door. Guardz recorded 114,827 successful sign-ins through a legacy authentication method that bypassed MFA entirely. This one is a Microsoft 365 configuration fix, not something a security product can do for you, which is why blocking legacy authentication is part of our baseline. Phishing-resistant sign-in is the next step, covered in passkeys explained.
Oversharing becomes an AI problem. Anonymous sharing links in OneDrive and SharePoint topped the report's list of Microsoft 365 risks, and the report notes that Copilot can surface anything a user already has access to. Cleaning up sharing is now a prerequisite for AI, as we set out in preparing Microsoft 365 permissions for Copilot.
Backup and email archiving: Dropsuite, from NinjaOne
The second named component is Dropsuite, now part of NinjaOne, which provides the Microsoft 365 backup and email archiving in AgileSECURE. Dropsuite started in 2011 and grew into a Melbourne-headquartered, ASX-listed company before NinjaOne, the IT management platform, completed its acquisition in June 2025 for about US$270 million. It now sits inside NinjaOne as its SaaS backup product.
Guardz can roll a device back after ransomware, but that is not a backup. Microsoft 365 also keeps deleted items for a limited time, which is not a backup either. Dropsuite keeps a separate copy of your data outside your tenant, so a compromised account, a malicious deletion or a mistake does not take the only copy with it.
- Microsoft 365 backup. Automated, immutable backups of Exchange mailboxes (email, calendars and contacts), OneDrive, SharePoint sites and libraries, and Teams channels and files.
- Granular restores. Recovery to a point in time, down to a single email, file or folder, rather than all or nothing.
- Email archiving. A journal rule captures every email sent and received as it happens, into a tamper-proof archive with search, retention policies and legal hold. That is the record you need when a client dispute, an insurer or a regulator asks what was sent, and it survives even if someone deletes the original.
- Held in Australia. Our clients' backup and archive data is stored in Australia, which keeps it under Australian jurisdiction and makes the question easier to answer when a client, an insurer or your own privacy policy asks where your data lives.
This matters more after the threat report than before it. One of Guardz's predictions for the second half of 2026 is ransomware that encrypts files in SharePoint and OneDrive directly rather than on a laptop, alongside extortion that steals data without encrypting anything. Endpoint protection does little against the first. A clean, immutable copy outside the tenant is what gets the business back. A backup only counts once a restore has been tested, so we test restores as part of the service rather than assuming they will work.
The other core components
Guardz and Dropsuite are the named platforms inside AgileSECURE, but platforms are one part of a security posture. Three more things sit alongside them:
- Microsoft 365 configuration. Conditional access, MFA policy, blocking legacy sign-in and device compliance are set in Microsoft 365 itself. We manage them as part of the baseline. Guardz watches for when they are bypassed.
- Business decisions. Payment verification, leaver processes, access approvals and your incident response plan belong to the business. The report's own $1.5 million case passed a voice verification check, which is a process failure no tool fixes alone.
- Proof for outside parties. Ultimate detects and responds. Businesses that must evidence their controls to a regulator, insurer or client may need outbound email data loss prevention, encryption and forensic investigation, which sit in the Elite tier. We explain who needs that in Guardz Elite: a step up for compliance.
That is also why AgileSECURE is measured against SMB1001 and not against a vendor's feature list. The framework covers the technology and the governance around it, and Guardz is one of the components we use to deliver the technical half.
A note on reading vendor reports
The threat report is Guardz's data about attacks seen on Guardz's platform, and it also promotes Guardz. Its figures are global, skew towards the United States (three quarters of the adversary-in-the-middle phishing incidents it recorded were in the US), and have not been independently audited. Its headline claim that its AI triage reaches 92.4 per cent accuracy, against 67 per cent for human analysts, is Guardz's own benchmark. We read reports like this for direction, not as Australian statistics, and we would suggest you do the same with any vendor's numbers, ours included.
Questions worth asking whoever runs your security
- What platform is it, and which plan? If they cannot name both, that is your answer.
- Is anyone watching alerts at 2am on a Sunday, or during the Christmas shutdown? Who, and what are they allowed to do without calling you first?
- Does it cover identity and email, or only the devices?
- When a Microsoft 365 account is compromised, how quickly are its sessions revoked, and who does it?
- What sits outside the platform, and who owns those pieces?
If you would like a baseline before that conversation, our free Cyber Health Check is a quick place to start. We run AgileSECURE for clients across Melbourne and the Mornington Peninsula.
Common questions
Does Guardz replace Microsoft Defender?
Is AgileSECURE just a Guardz licence?
What does AgileSECURE cost?
Where is our backup data stored?
Do we need the Elite tier?
The takeaway: Guardz Ultimate is one of the core components of AgileSECURE, with every module in use and 24/7 human analysts behind it. It does the watching. Dropsuite from NinjaOne keeps a separate, immutable copy of your Microsoft 365 data and a tamper-proof email archive. Microsoft 365 configuration, governance and Agile IT's accountability turn those tools into a security posture.