Everything a partner asks before the first contract
We sell only through partners, so the questions that matter are about the commercial boundary, not the tooling. The answers below are the same ones our partner managers give on a call. อ่านหน้านี้ภาษาไทย
How selling through partners actually works
The answers most partners want before they look at a single service. Every one of them is a commitment, not a positioning statement.
Does Cyber Defense sell direct?
Cyber Defense sells only through partners and has never sold direct. Every engagement is contracted through an MSSP, systems integrator, MSP or reseller, who owns the customer relationship, sets the end price and keeps the margin. There is no direct sales team inside the company, so there is no route by which your customer could be approached.
Will my customer know Cyber Defense exists?
In managed delivery, Cyber Defense never appears in front of your customer. Reports are delivered in your template with your logo, tickets carry your name, and your account manager runs the call. Our analysts work inside your tenant, behind you in the queue, and are not named on the contract, the ticket or the report. There is one published exception, and you should know about it: the emergency line at /under-attack is answered for anyone who calls it, including an organisation that is not yet anybody’s customer. Containment advice is given first and the engagement is then contracted through a partner — if the caller is already yours, the call comes back to you.
What does managed delivery cost?
Cyber Defense publishes a rate for every managed service at cyberdefense.co.th/pricing, in two columns: the list price your customer pays and the partner price you pay. Each line is a committed unit — per endpoint, per domain, per learner, per site, per engineer day, per repository, per deployment or per year, depending on the service — so you know your cost before you quote, and the gap between the two columns is your margin.
What kind of company becomes a partner?
Cyber Defense works with four kinds of partner: MSSPs, systems integrators, MSPs and resellers. MSPs and MSSPs usually already have people and are missing a platform whose unit cost falls as they grow. Systems integrators and resellers usually have neither, and take the platform and the operations team together so they can sell a recurring service without hiring a security team first.
Do I have to buy the zcr platform to use Cyber Defense delivery?
No. The platform and the delivery are priced separately and can be bought separately, from the same company: zcr.ai is our platform brand, Cyber Defense is the team that operates it. Most managed services run on zcr, while Managed Detection Engineering is delivered as reviewed code for the platform a partner already runs.
What is the relationship between Cyber Defense and zcr.ai?
They are one company. zcr.ai is the platform brand of Cyber Defense Co., Ltd., not a separate legal entity, so a partner contracts with one counterparty however much of it they buy. Two brands on purpose: zcr builds eight products in-house — zcrLog, zcrSIEM, zcrSOAR, zcrCTEM, zcrWAF, zcrOT, zcrADC and zcrX — and Cyber Defense uses them to deliver managed security for partners. Owning the platform is why one detection rule can run a single query across every tenant, and why onboarding the twentieth customer costs almost nothing extra.
Does my customer have to install an agent or give Cyber Defense access?
Access requirements depend on the service, and two services need none at all. Managed Exposure and Managed Leak Detection work entirely from outside — no agent, no credentials, nothing installed — so a customer can be live in the same week you sell it. Services that work inside the environment run in the tenant you or your customer already control, and that access can be withdrawn by you at any time.
Can Cyber Defense deliver for customers outside Thailand?
Cyber Defense delivers for partners outside Thailand. Because the platform is built in-house rather than licensed from a vendor, there is no vendor territory restriction that would stop us serving your customer in another country. The operations team works from Bangkok on UTC+7.
Do I have to manage your analysts?
Cyber Defense is not a staffing agency, and you do not line-manage anyone here. We do not send CVs and we do not bill hours: you buy a defined quantity of delivered work per month, against a documented methodology, reviewed before anything leaves the building.
Will Cyber Defense sell strategy or advisory to my customer?
Cyber Defense does not sell consulting or advisory to anyone, including your customer. Strategy, roadmap and the relationship are the partner’s margin, and there is no advisory practice inside this company that could take them.
How does a partner get started?
A partner starts with a single customer. Apply as a partner, pick a customer you already serve, and Cyber Defense delivers Managed Exposure on their domain for 60 days, in your template, at no cost — so you can see exactly what your customer would receive before you sign anything.
What proof is there that Cyber Defense can operate at this level?
Cyber Defense has been running security operations since 2015 and holds three independent credentials. zcrLog, the platform product behind our log and compliance delivery, won the Best Cybersecurity Innovation Award 2025 from NCSA Thailand, VNU Asia Pacific, SCBX NextTech and Cybersec Asia. Cyber Defense was named KnowBe4 Partner to Watch — Asia 2025 in the APJ Partner Programme Awards. And our log retention is certified to Thai standard มศอ. 4003.1-2560, the NECTEC standard for computer traffic data retention under the Computer Crime Act.
Do you hold ISO 27001 or SOC 2?
No — Cyber Defense holds neither ISO 27001 nor SOC 2 today, and there is no announced date for either. The certification it does hold is Thai standard มศอ. 4003.1-2560 from NECTEC, for computer traffic data retention under the Computer Crime Act, and that is a product certification rather than a management-system one. If your procurement process requires an ISMS certificate from every subcontractor, say so in the first conversation — it is a real blocker and it will not get smaller later. What we can do is answer your security questionnaire against the controls actually in place, name the access each service needs, and work inside the tenant you own, under accounts you issue and can revoke without asking us.
Where is Cyber Defense registered?
Cyber Defense Co., Ltd. is a Thai company registered in 2015, tax ID 0105558158009. The office is at 139 Setthiwan Building, Room B6-7D15, 11th Floor, Pan Road, Silom, Bang Rak, Bangkok 10500, Thailand.
Managed SOC Operations
Our analysts monitor, triage and escalate on your tenant. Your customers call you; we sit behind you in the queue and never appear on the ticket.
Can my customer tell you are involved?
No — every ticket, report and escalation carries your brand, and we never contact your customer directly. Cyber Defense has no direct sales team, so there is no route by which we could approach them even by accident.
Which SIEM do you support?
SOC monitoring is delivered on zcrSIEM, the platform we build ourselves under the zcr.ai brand. That is deliberate: because we operate on a platform we own, one detection runs a single query across every tenant and your twentieth customer costs us almost nothing extra, which is what keeps the monthly unit where it is.
Do we have to buy the platform from zcr.ai as well?
Yes — the tenant runs on zcrSIEM, licensed from zcr.ai. You can buy the platform there and the operators here, or take both together. We do not run on tooling rented per customer, because that would put somebody else's licence cost inside your price.
Who talks to the customer when something is confirmed?
You do — we escalate to your named contacts with the case written up and a recommended action, and the conversation with the end customer is yours and stays yours. If your team wants us to keep working the case in the background while you talk, that is the normal pattern.
Can we run our own analysts alongside yours?
Yes, and the split is usually by shift or by tier. Either your team covers local business hours and we cover nights and weekends, or your team owns the customer relationship and escalation while we own triage.
What happens when we add customers?
Each end customer is a separate tenant, billed per endpoint per month with a monthly minimum per end customer — both numbers are on the price list — and there is no re-scoping exercise. Onboarding the twentieth customer is the same process as the first, which is the whole point of us running on our own platform.
Managed Exposure
Continuous external attack surface monitoring on zcrCTEM. Nothing installed, no credentials issued, so a customer can be live the same week you sell it.
Do we need the customer's permission before we start?
No account, agent or change on the customer side is required, because discovery stays passive and works from information the customer already publishes to the internet. There is no test authorisation to chase before you can show a first report.
Can we run it on a prospect who is not a customer yet?
Yes — discovery is passive and reads only what that organisation already publishes, so a prospect domain is no different from a customer domain. It is a common way to open a conversation, and the output is yours to hand over however you want to position it.
How is this different from a vulnerability scan?
A vulnerability scan checks hosts you already know about, usually from inside. This starts from what the internet knows about your customer — domains, certificates, exposed services, forgotten hosts nobody has an inventory entry for — and keeps watching them as they change.
Does it replace a penetration test?
No — exposure monitoring tells you what is reachable and what looks weak, while a penetration test proves what an attacker could actually do with it. The natural pairing is exposure every month and a pentest once a year.
What if the customer has hundreds of subdomains?
They are all included, because you are billed per registered domain per month rather than per asset discovered. An estate that grows during the year does not change the invoice.
Can we white-label the report?
Yes — reports are produced in your template with your logo and your contact details, and our name does not appear anywhere in them.
Managed Leak Detection
Credential dumps and brand abuse monitored across dark web sources, verified by an analyst before anything reaches your inbox.
Is this just a feed we could buy ourselves?
No — what you are buying is the verification step. A raw leak feed hands you thousands of unfiltered records; here an analyst confirms the record is real, current and actually belongs to your customer before it becomes an alert you have to act on.
How quickly do we hear about a confirmed leak?
Verified credential leaks are escalated immediately rather than held for the monthly report, against the response targets written into your partner agreement. Lower-risk findings are collected into the monthly summary.
Do you need access to the customer's mail server or directory?
No — the service reads external sources only, with no agent, no mailbox connector, no directory sync and nothing to approve on the customer side.
Can you take a fake domain down?
We prepare the takedown evidence — registrar, host, screenshots, timestamps and the abuse contact — in a form you can file. The complaint itself has to come from the brand owner, so filing stays with you or your customer.
What counts as one unit?
One registered domain, plus the brand terms and executive names attached to it. Lookalike variants of that domain are covered inside the same unit rather than billed separately.
Will our customer know we did not build this ourselves?
No — alerts and reports carry your brand and your contact details, we are not named in the output, and we never contact your customer.
Managed Penetration Testing
Web, API and infrastructure testing against a documented methodology, senior-reviewed, written in your report template with your logo.
What happens if we outgrow the quota?
You raise the quota from the following month, or buy an extra engagement at list rate. The quota is a planning floor so we can reserve tester capacity for you, not a ceiling on what you are allowed to sell.
Can our customer meet the tester?
No — we work behind you and are not introduced to your customer. When a technical walkthrough is required, we brief your engineer beforehand with the findings, the reproduction steps and the questions we expect to be asked, and your engineer runs the meeting.
Do you test production systems?
Yes, with an agreed test window, a rules-of-engagement sheet signed through you, and a named contact on the customer side who can stop the test. Destructive testing is excluded unless it is explicitly authorised in that sheet.
How far in advance do we need to book?
An engagement drawn from your monthly quota is already reserved capacity, so it is scheduled rather than queued. Ad-hoc engagements outside the quota depend on the schedule at the time you ask.
Will an auditor accept the report?
The report documents scope, methodology, findings, evidence and the retest outcome, which is what an audit asks to see. It is issued under your name, so you are the testing provider of record.
Which test types are inside the quota?
Web application, API, external infrastructure and internal network testing. Anything outside those is quoted separately rather than silently drawn against your quota.
Managed Detection Engineering
Rules, parsers and tuning for the platform you run, delivered as reviewed code. Keeps your detection current without a dedicated engineer on your payroll.
Which platform do you write for?
zcrSIEM and Elastic are the backends we work in every day, and Sigma is the source format, so a rule can be compiled for any backend that accepts it. If you run something else, ask before you commit days and we will tell you honestly whether it is a good use of them.
Who owns the rules you write?
You do — the rules are delivered as code into your repository and stay yours if the engagement stops. There is no rule library you lose access to when you leave.
What is an engineer day?
A day of a detection engineer working on scope you set. A typical unit of work is one new log source parsed with its first detections written, or a tuning pass across a rule set that has become noisy.
Can we send you a specific threat and get a rule back?
Yes — a technique, an IOC set, a customer question or somebody else's incident write-up all work as input, and the output is a tested rule with its false-positive profile documented.
What happens to unused days?
Days are booked by month and do not roll forward, because the engineer's time was reserved for you. Tell us early in the month if your queue is empty and we will schedule tuning or coverage work against your existing rule set instead.
Do you need access to our customers' data?
We work at the rule layer of your platform, and where a detection has to be tested we use replayed or sanitised samples that you provide. There is no direct contact with your end customer at any point.
Managed Onboarding
We stand the platform up for your customer and hand you a working tenant. For reseller partners who sell but would rather not operate.
Do you stay involved after handover?
Only if you ask us to: the deployment ends with a working tenant and a handover pack, and running it afterwards is either your own team's job or a separate Managed SOC Operations subscription.
Who talks to the customer's IT team during the build?
You do — we take the requirements from you, send configuration questions back through you, and do not join calls with your customer. If a joint session is unavoidable, your engineer runs it with us briefed behind them.
What if the customer's environment turns out to be a mess?
The fixed price covers the deployment as scoped. Where a source cannot be connected because of something on the customer side, we document precisely what is blocking it and hand that back to you, rather than absorbing it silently and slipping the date.
How long does a deployment take?
It is driven by how quickly log sources are made available, not by our queue. You get a schedule with every customer-side dependency named up front, so the timeline you quote is one you can defend.
Does this include the platform licence?
No — the zcr licence comes from zcr.ai, and this is the delivery work of standing it up. They can be bought together but they are priced as two separate lines, so you can mark them up differently.
Can we do the deployments ourselves later?
Yes — the handover pack is deliberately written so your engineers can repeat the build without us. Buying the first few deployments and taking the rest in-house is a normal path for a reseller partner.
Incident Response Retainer
A pre-agreed retainer so that when your customer is breached at 2am, you already have a forensics team and a signed scope instead of a procurement problem.
Why sell a retainer instead of quoting the emergency?
Because an emergency cannot be quoted. Hourly incident work has no price until the day your customer needs it, which is the day they are least able to argue about it. The retainer turns the same capability into a line you sell once and collect every year, at a cost you knew before the incident and can mark up like any other subscription. You only pick up the phone to us when something actually happens.
Can we hold one retainer across several customers?
Yes — the retainer is held with you rather than with an end customer, so you can direct it, and the incident it includes, at whichever of your customers has the problem. That is the main reason it is worth buying as a partner rather than passing the problem to your customer to solve alone.
What are we paying for in a year when nothing happens?
The settled scope, the signed rules of engagement, the named contacts and the response commitment — all the work that otherwise gets done badly, at speed, on the worst day of the year. Readiness work such as a playbook review or a tabletop with your engineers is commonly attached to the retainer, and whether an unused incident carries into the following year is a term of the agreement, so settle both when you sign.
Who is the incident commander, you or us?
You are, by default, with our responders supplying the forensics and containment capability behind your commander. If you would rather we drive the technical response, that is agreed in the retainer in advance — still under your name and your customer relationship.
Does the retainer cover legal notification or PR?
No — we cover technical investigation, containment support and the written findings only. Regulatory notification, legal advice and communications belong to your customer and their counsel, and we give you the factual timeline they will need.
Do you negotiate with ransomware operators?
No — we do not negotiate with or pay threat actors under any circumstances. We handle investigation, containment and recovery support, and will work alongside whichever specialist your customer or their insurer appoints for that part.
What do you need from us when an incident starts?
The affected environment, a contact who can authorise containment actions, and access arranged through you. Scope, rate and authority were all settled when the retainer was signed and the incident itself is already paid for, so the first hour goes into the investigation rather than into procurement.
Managed OT Monitoring
Asset discovery and monitoring for industrial, solar and EV charging environments — where an IT-shaped SOC playbook does not apply.
Will this touch the control network?
No — monitoring is entirely passive, a mirror of the traffic with no agent, no active scanning and no writes. The OT network sees a listener, never a participant.
Our customer's OEM says monitoring voids the warranty.
A passive tap does not connect to or modify the controllers, which is what a warranty clause is normally written against. We give you the technical description in writing so you can put it in front of the OEM before you commit to anything.
Do you need to send someone to the site?
The sensor has to be placed once, and your engineer or the plant's integrator can do it with our placement instructions; we then validate the traffic we start receiving. Everything after that is remote.
How is this different from Managed SOC Operations?
The data, the analysis and the escalation path are all different. OT alerts are judged against the physical process and go to plant engineering, so partners who sell both buy them as two separate units rather than one bundled service.
What counts as a site?
One physical location with its own control network — a plant, a substation, a solar farm or a charging depot. Each is billed separately because each needs its own traffic baseline before the monitoring means anything.
Do your analysts actually know OT, or is this an IT SOC with a new dashboard?
OT cases are handled against OT playbooks, with protocol-level analysis and consequence-based severity. The zcrOT product exists because IT-shaped detection does not survive contact with a control network.
Managed Security Awareness
Phishing simulation and training run as a programme rather than a one-off campaign. We own the calendar, chase the people who ignore it, and produce the report you present.
Do you have to talk to our customer's HR or IT team?
No — user lists, mail-flow allowlisting and scheduling all come through your engineer, and we never appear in front of your customer. Reminders and reports go out under your brand.
Whose platform does it run on?
The programme runs on KnowBe4, where Cyber Defense was named Partner to Watch — Asia in the 2025 APJ Partner Programme Awards. The licence and our delivery fee are quoted separately, so you can price them however suits the deal.
Can the training and the phishing templates be in Thai?
Yes, and they can be mixed inside one organisation where staff differ — Thai for operations, English for a head office team, in the same programme and the same report.
What counts as one unit?
One enrolled learner per month, at the rate on the price list. Headcount therefore drives both the KnowBe4 licence and our delivery fee, so a customer whose headcount grows during the year changes both lines — count the learners before you quote a fixed annual price.
What if the click rate does not improve?
We report the number whether it moved or not, and then change the programme: different template difficulty, department-level targeting, or a manager-level report where a specific team is not engaging. A flat number that is reported honestly is the reason the programme gets fixed.
Who chases the people who never complete the training?
We do, on a reminder schedule agreed with you, and we escalate the remainder to you by name. Chasing is the part every partner underestimates, and it is the part that decides whether the programme works.
Managed Code Review
Static analysis run properly — pipeline wired, rule set tuned, findings triaged by an engineer — so developers receive exploitable issues instead of ten thousand warnings.
Do we have to give you the customer's source code?
Usually not, because the preferred setup runs the scan inside the customer's own pipeline and we work from the findings and the affected snippets. Where a deeper review genuinely needs repository access, it is granted by you, scoped to specific repositories and time-limited.
Which languages do you cover?
The stacks we work in day to day: Java, C#, JavaScript and TypeScript, Python, PHP, Go, and mobile in Kotlin and Swift. If a customer's stack is outside that, we tell you before you sell it rather than after.
Is this the same as a penetration test?
No — code review finds the flaw in the source before it ships, while a penetration test proves what is exploitable in what already shipped. For a software customer they sit at different points of the release cycle and are usually sold as two lines.
What if the customer has no CI pipeline at all?
The first of the work goes into building enough of a pipeline to run a scan on every merge, scoped openly rather than pretending the tool will slot into nothing. It is the part that decides whether the rest of the engagement is worth anything.
Who owns the SonarQube licence?
Your customer or you — we do not need to own it and we do not resell it as part of this. We work inside whichever instance you point us at, and the finding history stays there.
How is it billed?
Per repository, at the rate on the price list. Wiring the pipeline and tuning the rule set are inside that rate; a customer with several repositories is several units, so count them before you quote.
Managed EDR Operations (MDR)
MDR on the agent you already sell. You keep the EDR licence and the tenant; we run the console — triage, containment and escalation.
Why is the service not named after an EDR vendor?
Because the name would promise something we cannot always deliver. Our reseller rights for the products we know best are Thailand-only, so a service named after one of them would read as an offer to sell you that licence wherever you are. This is the operator layer only. You buy the licence from whoever you buy it from, in your own market, and we run it.
Which EDR products can you operate?
CrowdStrike, SentinelOne, Microsoft Defender and Sangfor are the consoles the team is in every day. If you run something else, ask before you sign and we will tell you honestly whether we can operate it well or whether you would be paying us to learn it.
We already pay the vendor for their managed service. Why this?
Their managed service covers their agent, which is the right answer while you only ever sell one agent. The moment an estate has two, you have two escalation paths, two report formats and nobody who owns the whole picture. Mixed estates are the normal case after a few acquisitions, and this is the operator that sits across them.
Whose tenant do the analysts work in?
The analysts work inside your tenant, under accounts you issue. The licence, the data, the audit trail and the contract with the EDR vendor all stay with you, and you can revoke our access without asking anyone. Our name does not appear in the console, the tickets or the reports.
Can we buy this and Managed SOC Operations together?
Yes, and it is the common pattern: endpoint telemetry is worked in the EDR console while everything else is worked in zcrSIEM. The escalation path and the write-up are the same either way, so your customer sees one service rather than two suppliers.
What counts as an endpoint?
Every device with the agent installed, server and workstation alike, counted once a month. Billing is per endpoint per month with a monthly minimum per end customer, both published on the price list, so you can quote a site before you have the exact device count.
Pick one customer. We will run it for 60 days.
Choose a customer you already serve. We deliver Managed Exposure on their domain for two months, in your template, at no cost — so you can see exactly what your customer would receive before you sign anything.
Apply as a partner