Your security tightened, with every gap set out plainly.

We harden your servers and Microsoft 365 to CIS, Cyber Essentials or the Microsoft baselines, put the full set of Defender tools to work, and shrink who can reach what to the people who genuinely need it. You get the full picture of where you stand, including the findings most reviews leave out. Some of this work fixes an estate that was left exposed. Most of it takes one that is already sound and makes it materially harder to breach.

Most setups look secure until they are tested.

A standard Windows and Microsoft 365 build comes with a lot left open: line-of-business apps anyone can reach, admin rights handed out years ago and never pulled back, an IIS box exposed to the whole internet. Each one sits quietly until someone finds it. We go through the live environment ourselves, find where an attacker would actually get in and how far they could move, and close it. The aim is a build that holds, not a longer risk register.

What a security engagement covers.

Hardening, detection, identity and the network edge, set to what your business actually runs. We work to CIS, Cyber Essentials or the Microsoft baselines, whether or not you report to a regulator.

Servers and Microsoft 365 hardened to a baseline that fits what you run.

We tighten your servers and Microsoft 365 against CIS, the Microsoft baselines or Cyber Essentials, chosen by what your business needs and what your regulator asks for. Where we leave a setting open on purpose, you get the record of what was changed and what was left open and why, so each call reads as a decision rather than an oversight. The default settings most builds leave untouched are reviewed and corrected.

Least privilege enforced, and lateral movement closed off.

We find the accounts carrying far more access than the job needs and pull it back, then design out the easy paths an intruder uses to move from one machine to the next. The number of accounts that could do real harm drops sharply, so a single stolen password exposes one system rather than the whole estate.

Detection in place, and a team that responds when it triggers.

We put the full set of Defender tools to work across identity, endpoints, email and the cloud, and feed what they see into Microsoft Sentinel so an attack appears as a single correlated incident rather than scattered, disconnected alerts. Where you want eyes on it around the clock, we set up a SOC and managed detection and response. For endpoints we deploy and configure SentinelOne or Cybereason, tuned to your environment rather than installed on defaults, so the alerts you receive are ones worth acting on.

Your network edge configured properly and kept current.

We configure or refresh your firewalls on Fortinet, Cisco or Palo Alto, and verify what is actually reachable from outside, not just what the network diagram shows. Rules added piecemeal over the years are rebuilt into a clear, documented set. The web apps and servers facing the internet get audited, so access from the internet is limited to what genuinely needs it.

A second, independent look from Factor1.

This page is the security engineering inside our infrastructure work. Factor1 is the separate, independent review, the cybersecurity side of the Centraline Group, which audits what is there and pressure-tests what we have tightened. You can take either alone. Where both fit, they run side by side, agreed per piece of work and never bolted on by default.

Your team keeps the controls. We take the hard security work.

If you have an IT lead, they keep running the place day to day. We take the security architecture, hardening, the permission and access model, and the firewall and detection setup, the work an internal team rarely has time to complete. Where agreed, we maintain it as your environment changes, because a setup hardened once and left alone gradually loses ground. Findings come back in plain language your team can act on, not a report they have to decode.

On the first call we name the tools we would use, whether SentinelOne, Cybereason, Fortinet, Cisco or Palo Alto, and explain why each fits your setup.

Stays with you

  • The day-to-day service desk and your end users.
  • The Microsoft, insurer and auditor relationships you already hold.
  • The final call on every change before it lands.

Comes to us

  • Hardening your servers and Microsoft 365 to CIS or Cyber Essentials.
  • The permission cleanup and stopping lateral movement.
  • Defender, the firewalls and the detection setup.

The standards we harden you against.

Which one we work to depends on what your business needs, and on any regulator you answer to.

CIS Benchmarks

Our working reference for hardening across Windows and the Microsoft 365 surfaces in scope. You get each gap identified and the reason it matters, not just a pass-or-fail score.

Cyber Essentials

When you are going for the certification, we set the controls against what the assessment actually asks for, so the work is complete well ahead of the assessment deadline.

Microsoft baselines

Microsoft's own security baselines for Windows and Microsoft 365, applied where they suit you better than a generic standard.

Start by finding out where your security really stands.

A senior engineer goes through your security, with the work agreed before they start.

Server and Microsoft 365 hardening, the Defender and detection setup, identity and access, the firewall edge, least-privilege cleanup and lateral-movement prevention. You walk away with a plain-language read on where the real holes are, a fix list ranked by risk with the effort against each one, and the record of what was hardened and what was left open and why, so your team can take what it wants and hand us the rest.

Scope
Set with you on the first call. We review what you run before we agree the scope of work, not after.
Continuity
The engineer who identifies the issues is the one who resolves them, so you brief us once.
Commercials
Named engineer, fully managed, fixed fee or ad-hoc help. Agreed and quoted up front, with no work beginning until you approve it.
Book the review

The controls built on this page stay watched: Factor1 runs monitoring, response and scheduled testing.

Security is one piece. We look after the whole.

Under one agreement, the estate is watched, maintained and documented as a single thing, by the team behind this page.

Microsoft 365SecurityWindows ServerIdentityNetworks & accessBackup & DREmailDevices

…and everything between.

Tell us how your security stands today.

A short call with our engineers. Tell us what you are running, including any areas you suspect are weak. We will tell you plainly where we would start and what it would take.

Centraline logo Built from scratch & fully managed by Centraline