Security
Security that is verified and reported, not just purchased.
Deployment is only the beginning. Verification and monthly reporting turn a security purchase into a control you can understand and document.
The premise
Partial coverage is the most common security failure we find.
Businesses rarely have nothing in place. They have something in place for most people, most devices and most mailboxes — and no reliable way to tell which ones are in the remainder.
We have worked with clients whose endpoint protection covered only part of the device fleet and whose backup counts no longer matched the mailboxes people actually used. Nobody intended to leave gaps. The environment changed, the counts did not, and no one was responsible for reconciling them.
Our answer is not a more expensive product. It is a single baseline, applied to everyone, verified after deployment, and reported on every month so that "are we covered?" has a documented answer.
The baseline
What every managed user and device gets.
Within our comprehensive managed-services program, this is the floor—not a premium tier or a collection of add-ons.
- Endpoint detection and responseAcross the managed device fleet, reconciled against the asset register rather than an old invoice
- Multi-factor authenticationEnforced across managed accounts, including shared and service accounts where supported
- Managed patchingWindows and third-party applications, on a defined cadence, with monthly coverage reporting
- Email securityFiltering and impersonation protection, plus DMARC, SPF and DKIM configuration
- Cloud backupMicrosoft 365 and Google Workspace mailboxes in scope, with restore testing supported at least annually
- Password administration & policyPolicy implementation and improvement included; an organizational password-management platform is optional and requires additional licensing
- Security awareness trainingOngoing and measured—for the attack that targets your people rather than your firewall
- Written information security planMaintained as the environment changes to support your internal and external reviews
- Asset registerAge, specification and warranty for managed devices, so coverage can be understood and forecast
- Secure remote supportUnattended access with an audit trail—fast for us and accountable to you
How it is run
Deployed, verified, reported — in that order.
Deployment is the easy part and the part everyone does. Verification and reporting are what turn a purchase into a control.
Deploy against the register, not the invoice
Coverage is reconciled against the asset register and your actual staff list — every device, every account — rather than against whatever count a previous renewal happened to carry forward.
Verify, and close what slipped through
After rollout we audit for the gaps that always exist: the shared mailbox with no second factor, the laptop that never checked in, the service account nobody claims. Each one is closed and recorded.
Report monthly, in a form a business leader can read
Patch status, coverage percentages, training completion and any exceptions—with the exceptions explained rather than buried in an appendix.
Support restore testing at least annually
We support a documented restore test from protected data at least once per year. More frequent testing can be planned when the backup service, recovery objectives, or business needs call for it.
Maintain the written plan
The information security plan is a living document — updated when the environment changes, not rewritten in a panic when a client's due-diligence questionnaire arrives.
Paperwork
Cyber insurance and client due diligence.
The questionnaires are getting longer and the attestations are getting sharper. Answering them incorrectly is worse than answering them slowly.
Cyber policies increasingly ask you to attest to specific controls — enforced multi-factor authentication, tested backups, endpoint detection, patch cadence, awareness training. An attestation that turns out not to hold is a coverage argument at exactly the wrong moment.
We maintain the technical records that support those answers, so completing an application or a client's security questionnaire begins with current evidence rather than a research project. You remain responsible for your representations and compliance obligations; where the technical answer would be "no," you hear that from us before you sign it.
Reports reflect the data available from the tools and analytics in scope. That evidence significantly improves your ability to provide accurate information on insurance applications and client questionnaires, while leaving final review and representation with your organization.
Start here
Not certain what is actually deployed across your business?
Many businesses are not. Discovery reconciles security coverage against your actual people, accounts, and devices, and you receive the findings in writing.