Mid‑market gets 24/7 Zero Trust detection
Virtual IT Group unveiled a 24/7 Zero Trust Detection & Response (ZDR) service aimed at mid-market orgs, packaging identity-aware detection and continuous monitoring into a managed offering. The move signals identity-first Zero Trust is being productized for smaller customers that lack in-house SOC maturity. (manilatimes.net)
Virtual IT Group and The Instillery launched the Zero Trust Detection & Response (ZDR) service for Australia and New Zealand on March 18, 2026, after The Instillery joined VITG via an acquisition completed in 2025. (manilatimes.net) The ZDR bundle explicitly includes deep packet inspection across all traffic, continuous 24/7 monitoring, local ANZ threat intelligence, and a per‑user, per‑month pricing model that can be appended to a customer’s environment without forcing an MSP switch. (vitg.com.au) The launch is the first service introduced since Maurice McCarthy became CEO in February 2026, and VITG now maintains a dedicated Zero Trust practice with four engineers certified through Zscaler Aces, including Masaki Takeda and Ronnie Meekers. (vitg.com.au) Because VITG advertises unified endpoint, identity and network protection, the service can surface the three telemetry domains that Splunk Enterprise Security correlation searches use—access/identity, endpoint, and network—enabling multi‑domain detections and threat‑intel enrichment. (vitg.com.au) The NSA/DoD Zero Trust Implementation Guidelines require continuous authentication of User/Person Entities and recommend integrating privileged access management telemetry with security analytics for real‑time detection of anomalous privilege use, a capability that identity‑aware ZDR telemetry is positioned to feed. (media.defense.gov) Splunk guidance for MSSPs advocates architecting Splunk for multi‑client operations and treating detection logic as code with version control and CI/CD for faster, low‑risk onboarding; VITG’s “add immediately” and per‑user pricing model aligns with those rapid, repeatable MSSP onboarding patterns. (splunk.com) VITG’s emphasis on full‑traffic DPI plus local ANZ threat intelligence targets the exact mid‑market blind spot the PR highlights—partial network sampling—and supplies the region‑specific telemetry needed to detect identity‑centric lateral movement and credential misuse campaigns. (vitg.com.au)