A solid footing that had aged
This was not a business starting from nothing. They already had industry standard measures in place, the kind that were perfectly reasonable five years ago. Identity, access and device management were all there in some form. The issue was not absence, it was age. Role based access had drifted, authentication was not doing enough of the work, and devices were tracked on an asset list without being properly controlled. Good bones, due an uplift.
Uplifting to our Foundation baseline
We started by bringing their existing posture up to our Foundation standard. We audited the environment from the identity layer up, then put compliance and conditional access controls in place so users could only sign in from compliant devices, cutting their exposure to session token theft and credential compromise. We tightened their Defender configuration and lifted their email security, keeping more outside threats out of user inboxes before they could land. This was not a rebuild. It was a deliberate step up from where they already were.
Moving into Governance
The Foundation uplift was the start, not the destination. Inside six months we moved them into our Governance tier, embedding security leadership and intelligence into how they make decisions. The relationship shifted from fixing what existed to shaping what comes next, setting direction on access, applications and risk before exposure turns into incident. We have held and built on that position for over two years, and the posture has kept maturing the whole way.
Governance in action: the SOC question
With growth in mind and a reputation to protect, they wanted a SOC that could actively investigate every login across their environment. The instinct was right. The order of operations mattered more, and that is exactly the kind of call Governance exists to make.
Before a SOC can earn its keep, the environment has to be managed and the apps properly sanctioned. So we ran a structured audit and gap analysis, integrated their apps with their identity provider, Microsoft Entra, and carried out a Defender for Cloud Apps review using App Governance and Cloud App Discovery to map every application in use and retire the ones that did not belong.
This is the step most SOC providers skip. They bolt a SIEM on, collect the logs, and wire up playbooks to clear the routine incidents. It works, but they end up managing far more alerts than they should, because the environment was never sanitised and leadership never set direction on which apps to use for which tasks. With AI usage climbing and most cloud platforms a single sign in with Microsoft away, that gap is exactly how sensitive company data walks out the door.
We had them close that gap first. The result was a saving of up to $85,000 in a year, and a clear, governed path toward active defence when the time is right.
Still moving forward
Two years in, this is a partnership defined by momentum. Each stage has built on the last, from an ageing baseline, to our Foundation standard, into Governance, and onward. They now see technology change differently, putting the right controls in place from the start and treating security as something that keeps progressing rather than something you fix once.