Services

Security Operations

Identity is the perimeter for a firm on Microsoft 365. We enforce it, take email authentication to enforcement, and work incidents from detection to a documented close.

Event timeline with one raised marker circled in amber against faint radar arcs

Where Incidents Actually Start

In our experience, the incidents that reach a professional-services firm are rarely exotic. A password is guessed across thousands of rotating addresses. A shared mailbox is still on basic authentication. A domain has DMARC in monitoring mode, so a spoofed invoice from the managing partner lands in the inbox. A single account without a second factor becomes the foothold for business email compromise. Security operations means closing those doors deliberately, one at a time, with the record to show it.

What We Do

Identity Enforcement

  • MFA and Conditional Access rolled out in waves, each account checked for a usable factor first
  • Passkeys and authenticator apps as the standard; SMS, email codes and legacy authentication removed
  • Password-spray exposure found and shut: basic authentication disabled on shared mailboxes, app passwords discovered and revoked
  • Privileged accounts placed inside a boundary automation cannot cross

Email Authentication

  • SPF, DKIM and DMARC published correctly for every domain, plus MTA-STS and TLS reporting
  • DMARC taken to quarantine and then reject on the basis of parsed aggregate reports, not on principle, so legitimate mail keeps flowing
  • Spoofing of your domain detected, traced to its source networks, and shut
  • Phishing that impersonates your own staff analysed, and the control that let it through corrected

Endpoints

  • Endpoint detection and response through Microsoft Defender for Business, with a managed review layer above it
  • Daily posture review: patch state, end-of-life systems, unexpected remote-access tools, local administrator changes
  • Workstation hardening scripted, reviewed and applied consistently
  • Device compliance reported monthly

Incident Response

  • Credential-spray attacks characterised from the perimeter device, not guessed at from the directory
  • Account compromise: sign-in blocked, sessions revoked, malicious inbox rules removed, forwarding checked, factors re-established, all verified
  • Business email compromise worked through containment, evidence collection and the documents your insurer and bank will ask for
  • A written incident record, in plain language, with what was found and what changed

People

  • Security awareness and phishing simulation through Microsoft Attack Simulation Training
  • Staff guidance for MFA rollouts written for the people receiving it, with the failure modes anticipated
  • User-reported phishing routed to someone who will actually look at it

Evidence, Monthly

Posture checks aligned to the CIS Microsoft 365 benchmark, external attack surface, email authentication and endpoint state are reported every month through Argos Security Assurance. Something defensible to show an auditor, an insurer, or a client.

How We Work

Every enforcement change goes through the same planned, gated and verified process as the rest of our Microsoft 365 operations. Rollouts are staged so that a mistake affects a wave, not the firm. Enforcement decisions are made from data we have parsed ourselves, and rollback is measured in minutes. Nothing is switched on because a checklist said so.

Find out where you stand.

A first posture report shows identity, email authentication, endpoint and backup state before anyone talks about a contract.