For businesses
Cybersecurity that produces evidence, not just alerts
Security has become a commercial requirement. Insurers audit it at renewal, enterprise customers audit it before signing, and regulators audit it afterwards. We assess what you actually have, fix the gaps in priority order, and produce the documentation the person asking will accept.
- Microsoft 365 and Entra ID posture assessment
- Cyber insurance questionnaires mapped to real findings
- MFA and conditional access staged from report-only
- Defender, Sentinel, Splunk, and Elastic deployment
- Authorized external, internal, and web application testing
- Retest and closure evidence for auditors and insurers
What we deliver
Know where you actually stand
An assessment against what is configured, not what was intended when the system was installed.
- Microsoft 365 and Entra ID security posture assessment
- Multi-factor authentication coverage and privileged access gap analysis
- External attack surface review — what the internet can see of you
- Cyber insurance questionnaire mapped to concrete configuration findings
- Prioritized remediation roadmap costed into phases you can budget
Close the gaps
The remediation work itself, delivered by the same engineers who found the problem.
- Multi-factor authentication and conditional access rollout, staged by ring
- Privileged access separation and administrative account tiering
- Microsoft Defender deployment and policy tuning across endpoint and identity
- Network segmentation, including isolation of operational technology
- Email security, phishing protection, and DNS filtering configuration
Detect and respond
Prevention fails eventually. The question is whether anyone notices in hours or in months.
- SIEM deployment and log source onboarding in Sentinel, Splunk, or Elastic
- Detection rule development and alert tuning to cut false positives
- EDR and XDR configuration with response actions defined in advance
- Incident response planning with roles, contacts, and decision authority named
- Post-incident review and remediation of the path that was used
Test it independently
An authorized attempt to break in tells you more than any dashboard.
- External and internal network penetration testing
- Web application and API testing aligned to the OWASP methodology
- Cloud configuration testing across Azure and AWS
- Recurring vulnerability scanning with CVE prioritization by exploitability
- Retest and closure evidence after remediation, for auditors and insurers
Platforms we work in
Named platforms, not categories — so you can tell at a glance whether we already know your environment.
- Microsoft security
-
- Defender for Endpoint
- Defender for Identity
- Defender for Office 365
- Microsoft Sentinel
- Intune
- Identity
-
- Entra ID
- Conditional Access
- MFA
- Duo
- Privileged access tiering
- SIEM & detection
-
- Microsoft Sentinel
- Splunk
- Elastic
- EDR
- XDR
- Assessment
-
- Nessus
- Burp Suite
- Nmap
- CIS Benchmarks
- OWASP
- Network
-
- Fortinet
- Palo Alto
- Segmentation
- DNS filtering
How it runs
From first call to sign-off
Every engagement is governed by a written statement of work naming deliverables, assumptions, and who is responsible for what.
-
Assessment first
We establish current state before recommending spend. Most organizations already own security capability they have not configured — finding that is cheaper than buying more.
-
Prioritized roadmap
Findings ranked by real risk and effort, split into what to fix this month, this quarter, and this budget year. Costed, so it can be approved.
-
Remediation in stages
Changes rolled out by ring with a rollback position. Identity policies go to report-only and are reviewed against real sign-in data before enforcement.
-
Verify and document
Retesting to confirm closure, and documentation in the form insurers, auditors, and enterprise customers actually ask for.
Questions
What people ask
Cybersecurity that produces evidence, not just alerts — questions
Our cyber insurance renewal is asking questions we cannot answer. Where do we start?
Send us the questionnaire. We map each item to a concrete finding in your environment — MFA coverage, privileged account separation, backup immutability, endpoint detection, incident response planning — and give you a prioritized list of what has to change to answer honestly. That mapping is usually a short engagement and it determines everything that follows.
Is a vulnerability scan enough, or do we need a penetration test?
They answer different questions and many questionnaires specifically require the second. A scan enumerates known vulnerabilities from a signature database. A penetration test involves a person attempting to chain findings into real access. If an insurer or a customer has asked for a test, a scan report will usually not satisfy them.
We already have Microsoft 365 Business Premium. Do we need more products?
Often not. Business Premium and the Defender suite include substantial capability that is commonly unlicensed in practice, unconfigured, or left at defaults. A posture assessment frequently finds that the biggest available improvement is switching on and tuning what you already pay for.
What happens if we are breached?
For clients under a managed agreement we work the incident with you: containment, scope determination, recovery from known-good and preferably immutable backups, and a post-incident review of the path that was used. Incident response planning — naming roles, contacts, and decision authority before anything happens — is part of the standard engagement, because the middle of an incident is a bad time to discover nobody knows who can authorize taking systems offline.
Do you do security awareness training?
Yes, including simulated phishing with reporting by department. It is worth being realistic about it: training reduces click rates, it does not eliminate them. It belongs alongside technical controls such as MFA and conditional access rather than instead of them.
Send us the questionnaire you cannot answer
Insurance renewal, customer security review, or audit finding — the document itself tells us what actually needs to change.

