Powered by happy clients

Service · 09 · Managed Security Services (MSS)
ModernOps · Security

Strengthen security
on top of your
existing network.

Managed firewalls, MFA, ZTNA, and network access control across Cisco, Fortinet, Meraki, Zscaler, DUO, ISE, and ClearPass, with enforced policies, IDPS tuning, compliance reviews, and coordinated incident response.

How MSS works
Firewall Platforms
4ASA · FTD · MX · FortiGate
Identity & ZTNA Stack
DUOZscaler · ISE · ClearPass
Onboarding Cycle
~30days to optimize
Change Model
Ticket-driven only
TL;DR
ModernOps Managed Security Services (MSS) operationalize firewalls, identity platforms, ZTNA, MFA, network access control, and incident response into a recurring service, with baseline documentation, ticket-based change control, and LogicMonitor monitoring across Cisco, Fortinet, Meraki, Zscaler, DUO, ISE, and ClearPass.
01What is MSS

Security operated
on top of the
network you have.

Security Management builds on Network Management with enforced policies, regular compliance reviews, IDPS configuration and tuning, and coordinated incident response, so vulnerabilities and attacks are addressed quickly, not improvised.

Managed Security Services (MSS) is a recurring operating model for firewalls, identity platforms, ZTNA, MFA, network access control, and incident response. ModernOps positions Security Management as building on Network Management, adding enforced security policies, regular compliance reviews, IDPS configuration and tuning, and coordinated incident response.

The motion is operated through Jira Service Management, LogicMonitor, 1Password, documented incident management procedures, ticket-based change control with approval workflows and change windows, and client-facing baseline documents per platform.

Firewalls are onboarded with inventory, make/model/firmware, HA configuration, management platform, exported and archived rulebases, documented NAT/VPN/object groups, validated HA pairs and failover behavior, and LogicMonitor onboarding for interface, CPU, HA, and VPN tunnel alerting.

For cloud security and identity, ModernOps manages Zscaler policy, tenant configuration, and user onboarding alongside Cisco DUO Essentials/Advantage/Premier tenant configuration, IdP integration, DUO Authentication Proxy deployment, app integrations (VPN, RDP, web apps, SSH), MFA validation, and offboarding workflows.

02Who this is for

Built for the
teams that own
the policy.

Security shows up in four conversations across the org, enforcement, integration, change, and incident. We answer each one with a defined operating motion instead of a one-off project.

01 / Security
CISO &
Security Leader
Security policies enforced, compliance reviews performed, IDPS tuned, vulnerabilities and attacks addressed quickly, and security tooling operated through defined processes.
02 / Executive
CIO &
VP of IT
A managed services partner combining hardware/software solutions with ongoing IT services, smooth handoffs, monitoring, management, and security of critical infrastructure.
03 / Infrastructure
Network & Infra
Lead
Firewall, VPN, HA, firmware, and management-platform coverage across Cisco, Fortinet, Meraki, FMC, FDM, ASDM, FortiManager, and Meraki Dashboard.
04 / Operations
IT Ops &
Service Desk
Security changes, incidents, escalations, monitoring alerts, and documentation flowing through ticketing, defined workflows, and client-facing baseline documents.
03What we hear

Common
concerns,
addressed.

Security conversations almost always start with the same set of frustrations. We turn each one into an operating commitment, written into the SOW.

Our firewall rules have grown over time, and nobody has a clean baseline.
ModernOps exports and archives the baseline rulebase, documents NAT policies, VPN tunnels, and object groups, and delivers a Firewall Baseline Document.
Firewall changes are too informal and risky.
Rule changes flow through ticketing with defined ticket types, approval workflows, and change windows.
We need someone watching HA status, VPN tunnels, and firewall health.
Firewalls are onboarded into LogicMonitor for interface, CPU, HA, and VPN tunnel alerting; HA status and failover events are monitored.
We have multiple firewall vendors and management tools.
Coverage spans Cisco ASA, Cisco Firepower/FTD, Meraki MX, and Fortinet FortiGate, with management via FMC, FDM, ASDM, FortiManager, or Meraki Dashboard.
We're rolling out ZTNA or secure web gateway, but policy ownership is unclear.
ModernOps manages Zscaler policy, tenant configuration, user onboarding, identity provider integration, PAC file or Client Connector validation, and policy change workflows.
MFA needs to be operated, not just licensed.
Cisco DUO Essentials, Advantage, and Premier, tenant configuration, app integrations, IdP integration, Authentication Proxy deployment, enrollment, offboarding, and policy change workflow.
Network access control policies are hard to document and maintain.
Cisco ISE and Aruba ClearPass with documented authentication, authorization, posture policies, AD/LDAP/MDM integrations, network device lists, HA/standby status, and replication health.
Security incidents need coordinated response.
Coordinated incident response with QMS-aligned procedures for logging, tracking, responding to, and resolving incidents.
04How we deliver

A documented
operating
model.

Security operations become a controlled service motion: baseline, enforce, respond, on a recurring rhythm, not a quarterly fire drill.

01
Baseline
Document every policy
Firewall inventory, make/model/firmware, HA configuration, and management platform are collected; rulebases are exported and archived; NAT, VPN tunnels, and object groups are documented; HA pairs and failover are validated; baseline documents are delivered.
02
Enforce
Run change through tickets
Rule and policy changes flow through Jira Service Management with defined ticket types, approval workflows, and change windows. Zscaler, DUO, and Network Identity each define their own policy change workflow.
03
Respond
Coordinate incident response
Firewalls and Network Identity platforms are onboarded into LogicMonitor. IDPS is configured and tuned. Vulnerabilities and attacks are addressed quickly through QMS-aligned incident management procedures.
05What changes

Before
& after.

Two snapshots of the same network. One in the world without ModernOps, one with.

Before
Inherited rules.
Ad hoc changes.
Fragmented
ownership.

Security tools are deployed but not fully operationalized, inherited firewall rules, inconsistent documentation, ad hoc policy changes, unclear HA and VPN monitoring, loosely managed MFA rollout, and fragmented ownership across firewall, identity, cloud security, and incident response workflows.

After · with ModernOps
Managed service.
Enforced policy.
Tuned IDPS.
Coordinated IR.

Security infrastructure becomes a managed service motion. Policy enforcement, compliance reviews, IDPS configuration and tuning, incident response coordination, ticket-based change support, monitoring, firmware maintenance planning, identity integration, offboarding workflows, and baseline documentation become part of the recurring managed services model.

06Side by side

Legacy security ops
vs. ModernOps MSS.

Same security stack. Different operating model. Seven dimensions where the work shifts off your team.

Dimension Legacy approach ModernOps with MSS
Firewall documentation Tribal knowledge or partial documentation. Baseline rulebase exported and archived; NAT, VPN tunnels, object groups documented.
Change control Informal requests or tool-side edits. Rule and policy changes via ticketing with defined ticket types, approval workflows, and change windows.
Monitoring Reactive checks. LogicMonitor for interface, CPU, HA, VPN tunnel alerting; HA/failover monitored.
Vendor fit One operating approach forced across platforms. ASA, FTD, Meraki MX, FortiGate via FMC, FDM, ASDM, FortiManager, Dashboard, plus Zscaler, DUO, ISE, ClearPass.
Identity security MFA, ZTNA, NAC are separate projects with unclear ownership. DUO, Zscaler, and Network Identity onboarding, configuration baselines, identity integrations, and policy workflows.
Incident response Scattered coordination. Coordinated incident response to address vulnerabilities and attacks quickly.
Baseline handoff No clear starting point. Firewall, Zscaler, DUO, and Network Identity Baseline documents.
07What you get

Six measurable
service
outcomes.

Each outcome maps to a specific operational deliverable, not a marketing promise.

Govern the
firewall estate
Baseline and archive rulebases, document NAT/VPN/object groups, and manage rule changes through ticketing.
Monitor security
infrastructure health
LogicMonitor for interface, CPU, HA, and VPN tunnel alerting; HA and failover events monitored.
Support the
real vendor mix
Cisco ASA, Firepower/FTD, Meraki MX, FortiGate, with FMC, FDM, ASDM, FortiManager, and Meraki Dashboard.
Operationalize
zero-trust access
Zscaler policy & tenant configuration; Cisco DUO tenant, app integrations, MFA enrollment, and offboarding.
Control network
identity
Cisco ISE and Aruba ClearPass with documented policy sets, integrations, HA status, and replication health.
Respond with
coordination
Coordinated incident response to address vulnerabilities and attacks quickly under QMS-aligned procedures.
08Change pattern

Every rule change
runs the
same way.

From the moment a firewall, Zscaler, DUO, or Network Identity policy change is requested, every change follows the same five-step ticket-driven motion.

Runbook · MSS-CHG-01

Policy
change
workflow.

Defined ticket types, approval workflows, and change windows govern firewall, Zscaler, DUO, and Network Identity policy changes. Coordinated incident response covers vulnerabilities and attacks under QMS-aligned procedures for logging, tracking, responding, and resolving.

01
Request &
classify
A change request is opened in Jira Service Management with the appropriate ticket type, firewall rule, Zscaler policy, DUO app integration, or Network Identity policy.
02
Review &
approve
The defined approval workflow runs. Risk, blast radius, rollback path, and dependencies are reviewed before the change is approved for a window.
03
Implement in
change window
Engineers apply the change inside the approved window via FMC/FDM/ASDM, FortiManager, Meraki Dashboard, Zscaler Admin Portal, DUO Admin Portal, ISE, or ClearPass.
04
Validate &
monitor
HA status, VPN tunnels, MFA flow, identity policy, and posture are validated. LogicMonitor confirms interface, CPU, HA, and tunnel health.
05
Document &
close
Baseline documents are updated, the ticket is closed, and any incident-driven changes feed into IDPS tuning, compliance review, and incident response follow-up.
09Operating flow

Telemetry.
Threat.
Triage. Enforced.

Every edge streams telemetry to the SIEM. When a threat is detected, the SOC triages on a documented runbook, a rule change is approved under change control, and enforcement is verified before the ticket closes.

10Supported platforms

One service,
the full
security stack.

Coverage spans firewalls, firewall management, ZTNA / secure web gateway, MFA, network identity / NAC, monitoring, and credential management, across the platforms customers actually run.

Firewall · 01
Cisco ASA
ASDMHAVPN
Firewall · 02
Cisco FTD
FirepowerFMCFDM
Firewall · 03
Meraki MX
DashboardAPI
Firewall · 04
FortiGate
FortiManagerUTMIDPS
ZTNA / SWG · 05
Zscaler
Internet AccessPrivate AccessApp Connector
MFA · 06
Cisco DUO
EssentialsAdvantagePremier
NAC · 07
Cisco ISE
AuthNAuthZPosture
NAC · 08
Aruba ClearPass
Policy MgrHA
Identity · 09
Azure AD /
Okta
SAMLSSOSCIM
Auth Proxy · 10
DUO Auth Proxy
VPNRDPSSH
Monitoring · 11
LogicMonitor
InterfaceCPUHAVPN tunnel
Credentials · 12
1Password
Vaulted accessAudit
11Posture ledger

Posture ledger
across policy &
identity.

Each managed platform sits in a posture ledger with last change, last review, integration health, and an explicit state, surfaced through monthly reviews, never as a surprise.

12Proof points

Service metrics
& coverage.

Numbers that frame the program: SKU breadth, framework alignment, monitoring integration, and the change model that governs every policy edit.

Productized SKUs
across the firewall estate
7Basic / Advanced / Controller / Standby
Identity & ZTNA SKUs
per-user / per-node
4Zscaler · DUO · NID Basic · NID Standby
Operating framework
QMSSOC 2 Type 1 controls
Monitoring integration
firewall & identity
LMinterface · CPU · HA · VPN tunnel
Change model
Ticketdefined types · approval · windows
Baseline documents
delivered at onboarding
4Firewall · Zscaler · DUO · NID
13Onboarding

30 days
from assess to
optimize.

Three repeatable phases. Predictable handoffs. Monitoring active, alerting tuned, and KPI scorecard in place by day 30.

Phase 01 / Days 0 – 10
Assess
scope & intake
  • Confirm security scope from SOW
  • Collect firewall inventory, make/model/firmware, HA configuration
  • Confirm management platforms (FMC, FDM, ASDM, FortiManager, Dashboard)
  • Confirm Zscaler, DUO, ISE/ClearPass access requirements
  • Identify identity providers and integration paths
Phase 02 / Days 10 – 20
Implement
baseline & integrate
  • Establish management access; store credentials in 1Password
  • Export and archive firewall rulebases; document NAT/VPN/object groups
  • Validate HA status; configure LogicMonitor alerting
  • Document Zscaler & DUO tenant configuration; configure IdP integration
  • Document Network Identity policy sets, AD/LDAP/MDM integrations
Phase 03 / Days 20 – 30
Optimize
enforce & document
  • Define change management processes and approved windows
  • Confirm firmware cadence; validate MFA end-to-end
  • Define user offboarding workflow
  • Monitor HA, VPN tunnels, firewall & NID health
  • Deliver Firewall, Zscaler, DUO, and NID Baseline documents
14Why ModernOps

Why customers
choose ModernOps.

The operating choices that separate a managed security program from a stack of licenses on a shelf.

01
Security built on network operations
Strengthening security on top of the existing network with enforced policies, compliance reviews, IDPS tuning, and IR.
02
Broad infrastructure coverage
Ongoing management, monitoring, and change support for firewalls, identity platforms, and cloud security.
03
Multi-vendor firewall ops
Cisco ASA, Firepower/FTD, Meraki MX, FortiGate via FMC, FDM, ASDM, FortiManager, Meraki Dashboard.
04
Baseline-first onboarding
Exported and archived rulebases; documented NAT, VPN tunnels, object groups, HA status; baseline documents delivered.
05
Identity & zero-trust depth
Zscaler policy/tenant management, DUO tenant configuration and app integrations, ISE / ClearPass.
06
Ticket-driven change model
Firewall, Zscaler, DUO, and NID onboarding define policy/configuration change request processes.
07
Monitoring integration
Firewalls and Network Identity platforms onboarded into LogicMonitor where applicable.
08
QMS-aligned posture
Security Management procedures provide evidence that logical/physical security and account administration meet policy.
15FAQ

Frequently
asked
questions.

Service definition, firewall coverage, identity, ZTNA, MFA, change control, and the operating boundaries between ModernOps and its customers, answered in plain language.

Q.01What does Security Management include?+
Ongoing management, monitoring, and change support for client security infrastructure, firewalls, identity platforms, and cloud security services, with enforced policies, compliance reviews, IDPS tuning, and coordinated incident response.
Q.02How is the service positioned for customers?+
“Strengthen security on top of your existing network”, with enforced security policies, regular compliance reviews, IDPS configuration and tuning, and coordinated incident response.
Q.03Which firewall platforms are supported?+
Cisco ASA, Cisco Firepower/FTD, Meraki MX, and Fortinet FortiGate.
Q.04Which firewall management consoles are supported?+
FMC, FDM, ASDM, FortiManager, and Meraki Dashboard.
Q.05What's the difference between Basic and Advanced firewall coverage?+
Basic is a single unmanaged unit; Advanced is managed with full rulebase support.
Q.06Does ModernOps support firewall controllers and standby devices?+
Yes. SKUs include Firewall Controller (FMC or FortiManager), Firewall Standby (HA secondary), and Firewall Controller Standby.
Q.07What happens during firewall onboarding?+
Inventory collection, management platform confirmation, access establishment, baseline rulebase export, NAT/VPN/object group documentation, HA/failover validation, LogicMonitor onboarding, change workflow definition, firmware cadence confirmation, and Firewall Baseline Document delivery.
Q.08Are firewall rule changes included?+
Yes. Rule change requests are handled through ticketing with defined ticket types, approval workflow, and change windows.
Q.09Does ModernOps monitor firewall health?+
Yes. Firewalls are onboarded into LogicMonitor for interface, CPU, HA, and VPN tunnel alerting.
Q.10Does ModernOps manage Zscaler?+
Yes. Zscaler is a per-user Security SKU; ModernOps manages policy, tenant configuration, and user onboarding for the cloud-delivered secure web gateway and ZTNA platform.
Q.11What does Zscaler onboarding include?+
User count and license tier confirmation, Admin Portal access, Internet Access policies, App Connector configuration when ZPA is in scope, identity provider integration, PAC file or Client Connector validation, policy change workflow, and Zscaler Configuration Baseline delivery.
Q.12Does ModernOps manage Cisco DUO?+
Yes. ModernOps resells Cisco DUO Essentials, Advantage, and Premier and manages tenant configuration, application integrations, and user onboarding.
Q.13What does DUO onboarding include?+
User count/license confirmation, DUO Admin Portal access, Azure AD/Okta/on-prem AD integration, DUO Authentication Proxy deployment if needed, application integrations (VPN, RDP, web apps, SSH), MFA validation, user offboarding, policy change workflow, and DUO Configuration Baseline delivery.
Q.14Does ModernOps support NAC / Network Identity?+
Yes. ModernOps supports Cisco ISE and Aruba ClearPass, with Basic for a primary node and Standby for an HA secondary.
Q.15What does Network Identity onboarding include?+
Platform/node count confirmation, remote access establishment, authentication/authorization/posture policy documentation, AD/LDAP/MDM/network device integration documentation, HA/standby and replication health confirmation, LogicMonitor onboarding, change workflow definition, and Network Identity Baseline Document delivery.
Q.16How does Security Management relate to Network Management?+
Security Management builds on Network Management by adding security measures, policy enforcement, compliance reviews, IDPS configuration, and incident response coordination.
Q.17Does ModernOps handle security incidents?+
Yes. ModernOps provides coordinated incident response, and the QMS requires incident management procedures for logging, tracking, responding to, and resolving incidents.
Q.18Where are credentials stored during onboarding?+
Remote management access credentials are stored in 1Password.
16Get started

Start with a
security
assessment.

ModernOps will review your firewall estate, rulebase documentation, NAT and VPN policies, HA posture, firmware cadence, Zscaler configuration, DUO/MFA coverage, Network Identity platform, monitoring gaps, policy change workflow, and incident response path, then map a practical route to managed security operations.