← All services
Security Services

Security Services

Managed Firewall, EDR, XDR and round-the-clock threat management, layered together instead of bought as disconnected tools.

Overview

Resilient and compliant by design

In short: Layered security managed as one thing rather than bought as disconnected tools. Start by finding out what your Microsoft licence already covers and whether it is switched on: in most estates we assess, the largest gain available is configuration rather than purchase.

Most breaches don't start with a sophisticated attack. They start with an unused MFA setting, a forgotten guest account, or a Conditional Access policy nobody finished configuring.

Who this is for
You've bought security tools over time but nobody's watching them as a whole
You run Microsoft 365 but have never had a formal review of the tenant's security posture
You need Cyber Essentials or Cyber Essentials Plus for a contract, insurer or supply chain

The problem

Microsoft 365 ships secure defaults, but almost nobody runs them by default: MFA gaps, stale guest access, unmonitored admin roles and unlabelled sensitive data build up quietly until an incident forces the audit. Point tools bought in isolation leave exactly the seams attackers look for.

What we would do

Start by finding out what your existing Microsoft licence already covers and whether it is switched on. In most estates we assess, the largest security gain available is configuring what is already paid for, not buying anything new.

  • If you are working toward Cyber Essentials or answering a customer security questionnaire, do the certification-shaped work first: it forces the same controls and produces evidence you can show.
  • If you have a regulatory obligation or a genuine threat profile, managed detection and response is worth buying on top, and we will say so specifically rather than as an upsell.

When we are not the answer: If you want a security product bought and installed without anyone changing how the business works, we are the wrong provider. Most of the risk we find is in configuration, process and joiners-and-leavers, and no product closes that on its own.

How we help

Security isn't a product you buy once, it's a posture you maintain. We bring Managed Firewall, endpoint detection and response (EDR), extended detection and response (XDR) and 24/7 threat management together with Microsoft 365 security and proven frameworks, so nothing sits as a gap between tools nobody's watching as a whole.

More on how we deliver our security services

Whether you're chasing Cyber Essentials certification or hardening your Microsoft tenant, we bring the expertise and the ongoing vigilance to keep your business protected, correlating signals across your perimeter, endpoints and cloud rather than reviewing them in isolation.

Independent penetration testing is delivered with our CREST-approved partner Punk Security, because we don't mark our own homework.

Named assessment

Microsoft 365 Security Assessment

You run Microsoft 365 but have never had a formal review of the tenant's security posture. That is the most common starting point we see, so we run the Microsoft 365 security assessment as a scored check across identity, data protection, device management and threat protection, rather than a generic best-practice list you then have to interpret.

The output is a low, medium or high read on where you actually stand today, and a priority order for what to fix first based on real risk. The gaps it keeps surfacing are the same ones set out further down this page: legacy authentication still enabled, standing Global Administrator access, guest accounts nobody can account for, user-granted application consents, incomplete mailbox auditing and anonymous sharing links with no expiry.

Run the free Microsoft 365 Security Posture Assessment
Retro pixel-art illustration of a glowing shield with a padlock deflecting descending pixelated bug and virus sprites
What's included

Everything you need, managed for you

Managed Firewall as part of one joined-up perimeter, not a standalone box
Endpoint Detection and Response (EDR) across every device
Extended Detection and Response (XDR) correlating signals across endpoint, identity, email and cloud
24/7 threat management, detection and incident response
Independent penetration testing through our CREST-approved partner Punk Security
Cyber Essentials and Cyber Essentials Plus
Microsoft 365 security: Defender, Purview and conditional access

Antivirus, EDR, XDR and MDR: what's the difference in plain terms?

Traditional antivirus asks whether a file matches something known to be bad, and blocks it if so. That works against commodity malware and fails against anything novel or anything that does not involve a file at all, which describes most modern intrusions: attackers increasingly use legitimate administrative tools already present on the machine, so there is no malicious file to match.

EDR, endpoint detection and response, changes the question from what a file is to what a process is doing: it records behaviour on the endpoint, flags sequences that look like an attack even when every individual component is legitimate, and gives a responder the ability to isolate the machine.

XDR extends the same idea beyond the endpoint by correlating signals across identity, email, cloud applications and infrastructure. This matters because a real intrusion is a sequence, not an event: a phishing email, then a sign-in from an unusual location, then a mailbox rule that hides the attacker's replies, then access to a file share.

Reviewed separately, each is a low-priority alert somebody closes. Correlated, they are one obvious incident. MDR is the separate question of who is watching: a managed service where humans triage and respond, rather than a product that generates alerts into a queue. EDR and XDR are capabilities; MDR is staffing.

What do the five Cyber Essentials controls actually require?

Cyber Essentials covers five control themes, each with specific technical requirements rather than general aspirations. Firewalls: every device protected by a correctly configured boundary or software firewall, with default administrative passwords changed and no unnecessary services exposed. Secure configuration: remove or disable unused accounts and software, change default passwords, disable auto-run.

Three of the five control themes, in the detail an assessor actually checks:

  • User access control: accounts created through an approval process, administrative accounts separate from everyday accounts, access removed when no longer needed, and multi-factor authentication on cloud services
  • Malware protection: anti-malware or application allow-listing on all in-scope devices
  • Security update management: everything within vendor support, with critical and high-severity updates applied within fourteen days

The requirement that catches most applicants out is the last one, because it applies to all software, not just operating systems, and because unsupported software is an automatic fail whether or not it is patched. Scope is the other stumbling block: home workers' devices, mobile phones used for work email and cloud services all fall in scope in ways organisations do not expect.

Certification is a self-assessment verified annually, and the question set is revised periodically, so answers that passed two years ago may not pass now. Cyber Essentials Plus adds independent technical verification: an assessor testing your actual devices rather than reading your description of them.

Why isn't MFA on its own enough any more?

Because attackers adapted. Multi-factor authentication remains the single highest-value control you can deploy and stops the overwhelming majority of password-based attacks, but three techniques now routinely defeat basic implementations. Adversary-in-the-middle phishing proxies the real login page, captures the session token after you have completed MFA, and replays it: the attacker never needs your password or your code.

MFA fatigue pushes repeated approval prompts until a tired user taps accept. And SIM swapping undermines SMS as a factor, which is why SMS is the weakest option still in common use.

Conditional Access is what turns authentication from a single gate into a policy decision. Rather than asking only whether the credentials are correct, it evaluates the whole context of the sign-in and applies the appropriate requirement or blocks it.

The highest-value policies are requiring a compliant or managed device for access to company data, blocking legacy authentication protocols that cannot enforce MFA at all, and requiring phishing-resistant methods such as passkeys or FIDO2 security keys for administrators. Every organisation should also keep excluded break-glass accounts with long unique credentials stored offline, because a policy that locks out every administrator is a self-inflicted outage that happens more often than anyone admits.

Why is email still the main way attackers get in?

Because it is the one system that must accept unsolicited content from strangers by design. Every other route can be closed; email cannot be. The attacks that succeed are rarely the crude ones. Business email compromise involves no malware at all: the attacker gains access to a mailbox, watches genuine conversations for weeks, then intervenes in a real invoice thread with amended bank details.

Because the message comes from a legitimate account, in an existing thread, with correct context, no technical control reliably distinguishes it from the real thing. Supplier compromise works the same way from the other end, which is why 'the email came from our supplier's real address' describes the attack rather than a defence.

The controls that actually help are layered. On the technical side:

  • SPF, DKIM and DMARC correctly configured, so your domain cannot be trivially spoofed
  • Link and attachment detonation
  • Impersonation protection for your executives and key suppliers
  • Alerting on the tell-tale signs of a compromised mailbox, particularly newly created inbox rules that forward or delete

On the process side, and this is the one that stops the loss: a bank detail change must be verified by telephone on a number already held on file, never a number from the email. Most successful invoice frauds would have been prevented by a single phone call.

Why is backup a security control rather than just an IT one?

Because backup is what determines whether a ransomware incident is a bad week or an existential event. Modern ransomware operators understand this perfectly, which is why they hunt backups first:

  • They dwell in the network for days or weeks
  • They locate the backup infrastructure
  • They delete or encrypt what they find
  • Only then do they trigger the encryption

Backups that are online, reachable from the same network and accessible with the same domain credentials as everything else are not a recovery position; they are simply more data waiting to be encrypted. The controls that matter are immutability, separated credentials that are not domain accounts, and at least one copy that is offline or logically isolated.

The second half is testing. A backup job reporting success proves that data was written, not that a business can be restored from it. Restore testing is the only evidence that matters, and it should answer specific questions: how long a full restore actually takes against the recovery time the business assumed, whether application-consistent restores of databases work, and whether the documentation needed to run the restore is itself stored somewhere that will survive the incident. Extortion has also shifted toward data theft as well as encryption, so backup solves availability but not confidentiality.

What does 24/7 threat management involve in practice?

It means three distinct things, worth separating when comparing providers. Monitoring is collecting and watching telemetry from endpoints, identity, email, cloud and network continuously. Detection is the analytics that turn that telemetry into a prioritised signal, which is where most of the engineering value sits, because raw alert volume from a modern estate is far beyond what any team can read.

Response is what happens next: triage to establish whether an alert is real, then containment actions such as isolating a device, disabling an account or revoking active sessions. A service that monitors and detects but escalates every decision back to a customer who is asleep has not solved the out-of-hours problem it was bought for.

The questions worth asking are therefore about authority and escalation rather than about tooling. Which containment actions can be taken without waiting for your approval, and which always require it? Who gets contacted at three in the morning, and what happens when they do not answer?

Is the underlying tooling yours or the provider's, and what happens to your historical telemetry if you change supplier? How long is data retained, and is that long enough for investigation given that attackers commonly dwell for weeks before acting?

Managed security services, MSSP, SOC-as-a-service: what do the labels mean?

They overlap enough to be genuinely confusing, so here is the plain version. A managed security service provider, or MSSP, is a company that runs some or all of your security controls for you rather than selling you the tools to run yourself.

SOC-as-a-service is narrower: the monitoring, detection and response function of a security operations centre, bought as a service instead of staffed in-house. Managed detection and response, or MDR, is SOC-as-a-service with the response part explicitly included rather than stopping at the alert.

The distinction that actually matters when you are buying is where the work stops. Some managed security services end at a dashboard and a monthly report, which leaves the hardest part, deciding what to do about an alert at two in the morning, exactly where it was. Ask what happens between detection and resolution, who is authorised to act, and what the response commitment is outside business hours. That answer separates providers far more reliably than any list of tooling.

What we do sits in that space and we would rather describe it than badge it: Microsoft 365 and Entra ID hardening, Defender deployed and tuned rather than left at defaults, 24/7 threat monitoring with response, email security, backup treated as a security control, and Cyber Essentials or Cyber Essentials Plus certification where you need to evidence it to a client or an insurer. If you are comparing us against an MSSP or a SOC-as-a-service provider, those are the same questions to put to us.

Where do most Microsoft 365 tenants have gaps?

The recurring findings are remarkably consistent. Legacy authentication protocols still enabled somewhere, which lets an attacker bypass MFA entirely. Global Administrator assigned permanently to more people than need it, often including a departed supplier. Guest accounts accumulated over years, with nobody able to say who invited them.

Third-party application consents granted by users, giving applications standing access to mail and files that survives a password reset. Mailbox auditing not fully enabled, so there is no record when an investigation is needed. Anonymous sharing links with no expiry, created years ago and still live.

None of these are exotic and all are visible to anyone who looks systematically. The reason they persist is not incompetence but drift: a tenant is configured correctly at a point in time, then absorbs three years of pragmatic exceptions and defaults that changed on Microsoft's side without anyone reviewing the impact.

Microsoft's Secure Score is a reasonable starting map but not a target to be maximised, because some recommendations do not fit every organisation and chasing the number rather than the risk produces controls that get switched off the first time they inconvenience someone senior.

Frequently asked

Questions we hear a lot

What's the difference between EDR and XDR?

EDR (Endpoint Detection and Response) watches and responds to threats on individual devices. XDR (Extended Detection and Response) correlates signals across endpoints, identity, email and cloud so an attack that touches several of them is seen as one story, not four unrelated alerts. We run both, joined up.

Can you help us get Cyber Essentials certified?

Yes. We assess you against all five Cyber Essentials control themes, close the gaps, and guide you through both Cyber Essentials and the independently audited Cyber Essentials Plus, which is increasingly required for public-sector and supply-chain contracts.

Do you provide 24/7 threat monitoring?

Yes. Our threat management runs around the clock, with detection, triage and incident response, so a security event at 2am on a Sunday is caught and acted on, not discovered on Monday morning.

Does holding Cyber Essentials mean we're secure?

It means you have a verified baseline, which is genuinely worth having, but it is a floor rather than a ceiling. Cyber Essentials addresses the commodity attacks that make up the bulk of incidents. What it does not cover is detection and response, backup and recovery, security monitoring, staff awareness, supplier risk, or incident planning: a certified organisation can still be breached and, without those, may not know for weeks. Treat certification as evidence that the basics are in place and as a procurement requirement you can now satisfy, not as a statement that the risk has been dealt with.

Is cyber insurance a substitute for security controls?

No, and increasingly it is conditional on them. Insurers now ask detailed technical questions at renewal (multi-factor authentication coverage, endpoint detection, offline or immutable backups, patching cadence, whether unsupported software is in use) and price or decline on the answers. Two practical risks follow. First, answering optimistically can leave a claim disputed at exactly the wrong moment, since the declaration forms part of the contract. Second, policies commonly limit losses arising from controls you said were in place and were not. Insurance transfers residual financial risk; it does not transfer the operational disruption or the notification obligations.

Do we need a penetration test or a vulnerability scan?

They answer different questions and are not interchangeable. A vulnerability scan is automated, broad and repeatable: it enumerates known weaknesses and is best run regularly, because its value is in trend and coverage rather than depth. A penetration test is a human exercise where a tester chains findings together to demonstrate what an attacker could actually achieve, which surfaces logic flaws and privilege escalation paths no scanner reports. If you have never scanned, start there. Add penetration testing when you have a specific question worth answering, and keep testing independent of whoever configured the environment.

What should we do first if we think we've been breached?

Contain without destroying evidence, and start the clock on your obligations. Isolate affected devices from the network rather than powering them off, since shutting down discards memory that may be the only record of what ran. Do not wipe and rebuild before anyone has looked. Reset credentials for affected accounts and, critically, revoke active sessions and tokens as well, because a password change alone does not evict an attacker holding a valid session. Preserve logs immediately. Then start the reporting assessment: if personal data is involved, UK GDPR requires notification to the ICO within 72 hours of becoming aware where the breach poses a risk to individuals.

Are Macs and mobile devices covered by endpoint security?

They can be and they should be, though coverage differs by platform. macOS is fully supported by mainstream endpoint detection and response tooling and needs it: the belief that Macs are not targeted has not been true for years. Mobile devices work differently: iOS and Android are more constrained by design, so protection focuses on mobile threat defence, separation of work and personal data, and enrolment into management so a lost phone can have company data removed without wiping personal photos. The gap worth checking is whether unmanaged personal phones can currently reach company mail and files, because in most tenants they can unless a Conditional Access policy says otherwise.

Does moving to Microsoft 365 make us more or less secure?

More secure than a neglected on-premises environment, and less secure than people assume, because the risk changes shape rather than disappearing. You gain a platform patched by Microsoft, resilient infrastructure, and access to detection capability no mid-sized organisation could build alone. What you take on is that your data is now reachable from anywhere with valid credentials, which makes identity the perimeter: a single compromised account with no Conditional Access is an intrusion with no network to breach. Cloud makes strong security achievable at a price point that was previously out of reach; it does not make it automatic.

Our security services is delivered UK-wide from our office in Brough, East Yorkshire, with on-site support across the county where it helps. We work with businesses in Barnsley, Halifax, Doncaster, Wakefield, Harrogate and Huddersfield and 6 more Yorkshire towns and cities, and remotely with clients right across the UK.

Know your Microsoft 365 security posture

Book a free security posture review and we'll show you where your Microsoft 365 and identity setup is exposed, and the fastest way to close the gaps.

Technology partners

Best-of-breed technology we use to deliver our security services.

See all technology partners →