How we work

Three ways to bring us in

Assess, Improve, Support. They are not stages you have to move through in order, and none of them is a prerequisite for the others. Pick the one that matches the problem you have.

Detect

Assess

Scoped and quoted up front

An assessment answers a question you cannot answer from the inside: what is actually configured, and where does that leave you. We read the configuration directly, work out what it means in practice, and hand back something your team can act on.

The subject is up to you. It might be the whole estate, or one product area you have doubts about, or a design you are about to commit to, or the provider you already pay to run your security.

What we can assess

  • Your Microsoft estate. A full review across identity, threat protection, data protection and cloud posture, scored against recognised benchmarks and ranked by real risk.
  • A single product area. Sentinel, Conditional Access, Purview, Intune or Defender on its own, when you know roughly where the problem is and want depth rather than breadth.
  • A design, before you build it. A second opinion on an architecture, a migration plan or a proposed change, while it is still cheap to alter.
  • Your managed provider. An independent read of what your MSSP or MSP has actually configured, against what your contract says they would.
  • Your licence position. What you already pay for and are not using. This one regularly pays for the engagement.

What you get

Findings ranked by real risk rather than by how many controls failed, each carrying the evidence behind it, the reasoning, and the fix that closes it. A report you can put in front of a board or an insurer, and a working session with your team to go through it properly rather than emailing a PDF and disappearing.

Found: Legacy authentication still permitted, bypassing MFA entirely for a third of accounts.

Fixed: Conditional Access policy blocking legacy auth, phased in over two weeks, with a short exception list for the service accounts that genuinely needed it.

This is the kind of gap a questionnaire never surfaces. Nobody remembers a protocol setting from three IT managers ago, so we read the sign-in logs instead of asking.

What an assessment produces: a posture score by domain across identity and access, threat protection, data and endpoint, and cloud posture, and a prioritised action list where each finding shows its severity, the evidence behind it and the fix that closes it.
Illustrative extract: figures shown are not a real client.
Defend

Improve

Fixed scope, fixed fee, clear end date

At some point somebody has to do the work. An Improve engagement is a defined piece of engineering with a scope we agree in advance, a fee we quote before we start, and a date it finishes. No open-ended time and materials, and no retainer required.

It does not have to follow an assessment. Plenty of clients already know what needs doing and simply do not have the hours or the specific expertise on staff.

The kind of work this covers

  • Hardening and remediation. Closing the findings from an assessment, ours or somebody else's, in priority order.
  • Deployment and rollout. Standing up Sentinel, Defender, Purview or Intune properly, including the tuning that usually gets skipped.
  • Design and build. Conditional Access architecture, privileged access models, label taxonomies, landing zone security.
  • Migrations and consolidation. Tenant to tenant moves, retiring third-party tools you are paying twice for, moving off legacy platforms.
  • Getting a project unstuck. The piece of work that has been half finished for eight months because the person who understood it left.

Found: Sensitivity labels had existed for three years and had never been applied to a single document.

Fixed: Label taxonomy rebuilt around how the business actually classifies work, auto-labelling piloted in Finance, then rolled out tenant-wide over four weeks.

A defined project with a real finish line was the right shape here. There was no need for an ongoing relationship to close it.

Repeat

Support

Ongoing, by arrangement

Estates do not hold still. New starters, new licences, new integrations, and new Microsoft features arriving every month whether you asked for them or not. Support keeps senior Microsoft security expertise available to your team without you having to hire it.

This is deliberately not a managed service. We are not taking your monitoring contract or putting an agent on everything. Your team stays in charge; we are the people they call when something is outside what they have done before.

What it usually includes

  • Scheduled re-assessment. So configuration drift gets caught in weeks rather than at the next audit.
  • Engineering time. An agreed amount of senior capacity each month, used on whatever matters most that month.
  • Someone to ask. Direct access to the engineers who know your estate, for the questions that are too small to raise a project for.
  • Change review. A second pair of eyes on the changes your team is planning, before they go in.

Found: A re-assessment six weeks after an initial fix caught a newly onboarded app registration holding tenant-wide mail read access, granted without review.

Fixed: Consent revoked the same day, and an app governance process put in place so the next one cannot be granted silently.

This is the argument for staying involved. A point-in-time assessment catches what is wrong that week. Security posture is a moving target.

Independent assurance

Is your provider doing what you pay them for?

Most organisations that outsource security have no way to check the work. The reporting comes from the same provider doing the configuring, and a monthly service summary is not evidence. We read your tenant directly and show you the difference between what your provider says is in place and what is actually there.

  • Coverage you are paying for. Whether the licences, connectors and agents in the contract are deployed across the estate, or only across most of it.
  • Detections that would actually fire. Analytics rules enabled, tuned and mapped to real technique coverage, rather than a default rule set switched on at onboarding and untouched since.
  • Drift since onboarding. What was configured on day one, and what has quietly changed, lapsed or been exempted since.

Common questions

Before you get in touch

Do we have to start with an assessment?

No. If you already know what needs doing, we can go straight to doing it. An assessment is useful when the question is genuinely open, and a waste of your money when it is not.

What access do you actually need?

For an assessment, read-only. A dedicated application identity, never a personal login, with the minimum Microsoft Graph, Azure RBAC and, where relevant, Exchange Online permissions the work requires. Nothing is enabled until an administrator in your organisation approves it, and we check every permission before we start so you can see exactly what we can reach. Work that changes things uses separate access, scoped to the job and approved on its own terms.

How long does it take?

An assessment is usually a few working days from access being granted to a report in your hands, depending on the size of the estate. Project timelines depend entirely on the work, and we give you a date before you commit rather than after.

We already have an MSSP. Is this still relevant?

Often more so. Outsourcing security to a provider does not tell you whether the work is being done, and the reporting you receive comes from the same people doing the configuring. We read your tenant independently and show you what is actually in place. We are not pitching to replace your provider, and the review does not arrive with a proposal to take over the contract.

What frameworks do you assess against?

Recognised security benchmarks for what can be scored, and Microsoft's own best-practice guidance for the products themselves. The same evidence is cross-mapped to NIST CSF, ASD Essential 8 and ISO 27001, so you can speak to whichever framework your board, client or insurer cares about without commissioning a second piece of work.

Do you work with our existing IT provider?

Regularly, and it usually goes well. We are specialists rather than a general IT provider, so we are not competing with them for the rest of your IT. Where we are reviewing a provider's work rather than working alongside them, we will tell you that up front.

Not sure which one you need?

Describe the problem and we will tell you which of the three actually fits, including when the answer is that you do not need us yet.