Designed by the people
who run it.
Security architecture, Microsoft deployments, SIEM migration and incident response. Bought by the project rather than by the month, and delivered by the same team that then operates it around the clock.
Expertise by the project,
not by the month.
Four of our five practices are a standing service you buy for a year. This one is not. It is the engagement with a defined start, a defined end and something working at the finish.
Most of it is Microsoft work: designing a security architecture, deploying Defender and Sentinel properly, migrating off a legacy SIEM, or coming in after an incident to work out what happened. Some of it is advisory rather than hands-on, and some of it is a person sitting in your leadership meetings.
The thing that makes it worth buying from us rather than from a pure consultancy is what happens after the invoice. A consultancy designs it and leaves. We design it, deploy it and then operate it, which changes the decisions taken on the way through - nobody here is going to specify something clever that becomes somebody else’s problem to run at three in the morning.
- A Microsoft FastTrack Partner, delivering Microsoft’s own funded security engagement.
- Security architecture designed against how you actually operate, not a reference diagram.
- Microsoft deployments done properly: Sentinel, Defender, Entra and Purview.
- Legacy SIEM migration, including the detection content nobody wants to rewrite.
- Incident response led by people who have led one before.
- A vCISO in your leadership meetings, with a platform doing the paperwork.
- Day rate, fixed scope or retained, and we will tell you which fits before you ask.
Microsoft will often
pay for the first engagement.
Microsoft funds a structured security engagement delivered by partners, and we deliver it. It is scoped around eight security domains, and you pick the ones that match what is actually worrying you. For an eligible organisation Microsoft funds it rather than you.
It is proved on your own tenant rather than in a slide deck: we configure, demonstrate and measure against your real estate, and you keep the findings and the roadmap whatever you decide to do next. Most engagements start with a Zero Trust assessment to work out where the gaps are before anybody changes a setting.
Secure your infrastructure
Cloud and on-premises workloads: servers, databases, containers, storage, APIs and network infrastructure, assessed with Microsoft Defender for Cloud.
Protect identities and access
User identities, privileged accounts and access policy across cloud and hybrid, using Entra ID Protection and Defender for Identity. Where most compromises start.
Defend against email threats
Phishing, business email compromise and malicious attachments, through Microsoft Defender for Office 365 and collaboration threat detection.
Detect and respond to attacks
A unified security operation across Defender XDR, Microsoft Sentinel and Security Copilot. The domain closest to what we run for customers every day.
Secure devices and endpoints
Employee devices and access to cloud applications, using Defender for Endpoint and Defender for Cloud Apps.
Manage your security posture
One view of security posture and attack surface across the estate, so exposure is measured rather than estimated.
Protect your data
Data security posture and AI data exposure assessed with Microsoft Purview: what sensitive data you hold, who can reach it, and where it is leaking.
Secure AI
Assessing and protecting AI workloads, including the agents now acting inside your estate. The newest domain, and the one fewest organisations have looked at.
Eligibility and funding are Microsoft’s decision rather than ours, and they vary by programme, region and the size of your estate. We will tell you honestly whether you are likely to qualify before anybody fills in a form.
A design nobody has to operate
is a design nobody stress-tested.
The gap between a consultancy engagement and an operational reality is where most security programmes quietly fail.
A consultancy is measured on the document. It specifies the architecture, hands over a deck and a diagram, and the engagement closes. Whether the thing is maintainable at 3am is somebody else’s question, and by the time anybody finds out, the people who designed it have moved on.
We end up running what we build, on the same platform, with the same analysts. That is a constraint on us and it is the point: it rules out the clever design that nobody can operate, and it means the detection content, the data connectors and the escalation paths are built by people who will be woken up by them.
If you want the design and nothing else, we will still do it, and we will still tell you what it costs to run.
What you can
buy by the project.
Some of these are a fixed engagement, some are retained, and one of them is a person. All of them land with the same team.
- Professional Services
- Virtual CISO
- Microsoft Security Consultancy
- Sentinel Implementation & Migration
- AI Governance
- Incident Response
- Compromise Assessment
- Security Architecture
Consultancy, answered.
What is cyber security consulting?
Buying expertise for a defined piece of work rather than as a standing service: designing an architecture, deploying a platform, migrating a SIEM, answering to a regulator, or leading an incident. It ends with something built or decided, not with a subscription.
What do you mean by professional services?
The hands-on delivery half: deployment, migration, integration and configuration, mostly across the Microsoft security stack. Advisory tells you what to do; professional services is us doing it. Most engagements here are some of both, scoped together.
What is a Microsoft-funded workshop?
A structured engagement Microsoft pays a partner to deliver, designed to prove something on your own tenant rather than in a slide deck. We run six of them. Eligibility and funding are decided by Microsoft, so we will tell you upfront whether you are likely to qualify.
Do we have to buy your managed service afterwards?
No, and the engagement is scoped so it stands on its own. What you get either way is a design from people who operate this kind of environment daily, which tends to produce fewer things that look elegant and run badly.
How is this priced?
Day rate, fixed scope or retained depending on the work, and we will say which one fits before you ask. Nothing is quoted before the scope is written down, because a number without a scope behind it is guesswork on both sides.
Can you work alongside our existing partner?
Usually, and it is common on migrations and architecture work where an incumbent runs part of the estate. The boundary between who does what is agreed in writing at the start, which is the part that prevents the awkward conversation later.
Tell us what needs building
and we will scope it honestly.
Including whether Microsoft will fund the first engagement, and whether you need us for the whole thing or only the hard part. Nothing is priced before the scope is written down.