Protection
Layers that start on day one.
Endpoint, cloud, identity, email, web, backup, and people controls run together in the managed plan. They are not optional add-ons or a later phase.
How do you approach security and compliance?
We assess risk by business impact, not scanner noise; implement the controls, collect evidence, and re-assess. Compliance becomes a state you maintain, not a project you repeat.
Protection
Endpoint, cloud, identity, email, web, backup, and people controls run together in the managed plan. They are not optional add-ons or a later phase.
Governance
We inspect software, cloud, and hardware in detail, prioritize findings by business impact, then review controls with named owners and scheduled evidence.
Two lenses
Most breaches use one direction to arrive and the other to move. Both need their own controls.
North–South · the perimeter
Traffic moving across your boundary must pass a control before it reaches data.
Hop 01
Internet
DNS + web filtering
Hop 02
Edge
MFA + current firmware
Hop 03
Gateway + DMARC
Hop 04
Device
AV + EDR isolation
Hop 05
Cloud
CDR + conditional access
Hop 06
Data
Backup + least privilege
East–West · containment
Segmentation and identity controls limit how far a compromised device can travel.
Zone · Staff
Zone · Servers
Zone · Recovery
Security bundle
The layers work as a bundle. A control you decline is a path an attacker keeps open.
AV
Stops: Known ransomware.
EDR
Stops: Novel malware.
MDR
Stops: Abused tools overnight.
CDR
Stops: Suspicious sign-ins and sharing.
Dark web
Stops: Credential stuffing.
Awareness
Stops: Human-delivered attacks.
Granular assessments
Findings are written specifically enough to act on this week, with a fix and owner attached.
01
Patching, hardening, admin access, endpoint health, and configuration drift.
A prioritized fix and owner for each device.
02
Microsoft 365 and Entra access, sharing, mail rules, roles, and sessions.
The exact exposure and change needed.
03
Edge, wireless, server firmware, backup immutability, and operational devices.
Lifecycle position and replacement horizon.
Assessment rhythm
Continuous
EDR, MDR, CDR, dark-web monitoring, and awareness telemetry.
Alerts with triage notes + monthly posture roll-up.
Quarterly
Configuration, phishing, patch posture, roles, and access re-review.
Posture report + prioritized fix list.
Annual or material change
Attack-surface review, vulnerability scan, and framework assessment.
Assessment report + updated risk register.
Governance loop
The loop converts a requirement into a configured control, evidence, a decision, and then a new review.
Set scope, ownership, and risk appetite.
Configure and document the control.
Collect proof as the environment runs.
Prove the control works and is acted on.
Put the state in front of accountable people.
Close gaps, re-test, and begin again.
What you receive
Every artefact has an audience and cadence, so there is a clear record of what happened and what needs a decision.
| Artefact | Cadence | Audience |
|---|---|---|
| Executive risk score | Monthly | Leadership |
| Prioritized fix list | On issue / quarterly | Work owners |
| Security posture summary | Monthly | IT contact |
| Phishing results | Monthly | People managers |
| Compliance evidence pack | Quarterly / on request | Auditor or regulator |
| Incident summary | Per incident + monthly | Leadership |
One ranking philosophy: business impact over scanner noise. We prioritize what is exposed, what it could cost, and how likely it is.
Let’s talk
We can start with your environment, the controls that matter most, and the evidence you need to maintain.