Skip to main content

Back to Secure IT

Hardening that does not slow the business down

We harden endpoints, network and Microsoft 365 services along recognised baselines, and set up monitoring so your team follows real incidents rather than false alarms.

30 minutes · no sales pitch · an honest read on whether we fit

A fit when

  • You had an incident or a near miss and want to close the gaps
  • Your security controls get worked around in daily use
  • A customer or insurer asks for an evidenced security posture
  • You need a baseline that new devices can be measured against

The situation

  • Security controls get worked around because they block the daily job.
  • Monitoring produces so many alerts that nobody looks any more.
  • There is no baseline. Every device is an individual case with its own history.
  • In a real incident it is unclear who does what, and whom you must inform in which order.

What we do

We set up a baseline along CIS or BSI Grundschutz that fits your environment and roll it out in stages rather than in one go. Microsoft Defender is configured so detections are justified and alerts end up with someone who can act on them. On top of that comes an incident plan that has been rehearsed once before it is needed.

What is included

  • 01Survey and baselineThe current state measured against CIS baselines and your own obligations, with a prioritised gap list.
  • 02Endpoint hardeningDefender for Endpoint, attack surface reduction, encryption and device compliance that is actually enforced.
  • 03Monitoring worth readingRules and alert routing set so an alert means an action rather than another email.
  • 04Incident plan with a rehearsalWho decides, who communicates, who isolates systems, and how reporting deadlines are met.

What you end up with

Documented security baselineEnforced device complianceAlert routing with named ownersRehearsed incident plan
Request a briefingA reply within 1 business day, from a person.