PROMETHEUS WATCHTOWER
Keep critical controls working as your organization changes.
Watchtower combines proactive assessment with ongoing managed IT and cybersecurity. Beacon shows what needs attention. Citadel resolves agreed gaps and keeps the technology and protections in scope working as the organization changes.
Four operating pillars
Security controls that stay maintained.
Access stays controlled.
MFA, access policies, single sign-on, onboarding/offboarding, account lifecycle, privileged access, and mobile/BYOD controls.
Systems stay protected.
EDR/MDR, patching, network isolation where appropriate, phishing and domain protection, and security monitoring.
Recovery stays possible.
Backups, restore testing, recovery readiness, email/data protection, and configuration continuity.
Evidence stays current.
Policies, evidence maintenance, vendor coordination, recurring review, documentation, and exceptions tracking.
Beacon
See what needs attention.
Beacon can stand alone as the starting assessment. It verifies the environment, identifies meaningful gaps, prioritizes what should happen next, and organizes the available evidence.
Citadel
Resolve it and keep it working.
Citadel is the protective and managed component of Watchtower. It addresses agreed findings and maintains the technology, security, recovery, and governance responsibilities in scope.
Watchtower FAQ
How Beacon and Citadel work together.
How do Beacon and Citadel work within Watchtower?
Watchtower is the overall managed IT and cybersecurity offering. Beacon assesses the environment, identifies priorities, and organizes evidence. Citadel resolves agreed gaps and maintains the technology and protections in scope.
What does Watchtower include?
Watchtower brings Beacon and Citadel together around four operating pillars: identity, defense, resilience, and governance. The specific identity, cloud productivity, endpoint, backup, email, monitoring, and documentation responsibilities are defined up front across supported cloud and mixed environments.
Can our existing IT provider use the findings?
Yes. The assessment stands on its own, and your existing provider can use it as the remediation plan. Hiring Prometheus for implementation or ongoing service is not required.
What is recurring service versus separately scoped work?
Recurring service covers the agreed security, cloud productivity, identity, endpoint, backup, and governance administration across supported cloud and mixed environments. Major migrations, new office deployments, forensic investigations, incident response, and other project work are scoped separately.
Start with a short conversation
Discuss Watchtower.
Already have assessment findings? Bring them. We can discuss what should be closed first and whether ongoing control maintenance fits your organization.
Call (561) 287-9185 or email info@prometheusconsultinglabs.com.
