Security & Infrastructure
Azure landing zones, Defender XDR, Sentinel and tested recovery, built as evidence an auditor can open: GDPR Article 32, DORA Article 9, NIS2 Article 21.
Review 38 risk-weighted checks from the ITSailor Microsoft 365 baseline, with a directional crosswalk to DORA, NIS2, GDPR and NIST CSF 2.0.
What this covers
Azure and GCP landing zones, Microsoft Defender XDR, Sentinel, Microsoft 365 hardening, and backup with rehearsed recovery. Controls mapped to their sources.
Who it is for
Operators under DORA, NIS2 or GDPR scrutiny, and any team whose last audit answer was a screenshot folder and a spreadsheet nobody trusts.
Where to start
Start free with the security scorecard, or book the €499 Architecture Workshop: a 2-hour live session in your tenant and a written deliverable in 5 days.
How it ends
Every engagement closes with an Exit Kit: control register, Terraform source, runbooks and the evidence trail, in your hands.
Before you buy another security tool, configure the ones you have already paid for. The common failures are ordinary: unfinished rollouts with no written record.
The Microsoft licences you bought never got a documented hardening pass. Conditional Access is opt-in, Defender XDR is half onboarded, and retention is whatever an admin clicked through years ago.
A written baseline pass with each control recorded: configuration, owner, exception and rollback.
Control register mapped to Microsoft, NIST and EU sources
Backup jobs report green, but nobody has restored anything under pressure. Whether the business actually recovers is untested.
Restore drills with observed timing, integrity checks and business acceptance, repeated on a schedule.
Recovery drill runbook with dated drill evidence
GDPR Article 32, DORA Article 9 and NIS2 Article 21 ask for proof of controls. What exists is last quarter's screenshots and a spreadsheet that has not been touched in six months.
Controls tied to their deployed settings so the evidence regenerates instead of going stale.
Source-linked control mapping for the audit binder
Solution narratives
3 narratives: full pitch with deliverables, scope and case context
Services in this pillar
7 discrete engagements: fixed scope, written deliverables
Lifecycle automation
Offboarding became an execution log, not an email thread.
Power Automate connected HR status changes to Microsoft 365 offboarding: session revocation, mailbox conversion, licence recovery, OneDrive archive, and audit trace.
Anonymised outcomes from the founder's prior operating roles in regulated industry, stated as such, not ITSailor client engagements.
On the record- Offboarding runs HR-triggered, with no engineer time
- Clean access-termination result in the first internal audit after rollout
- ~€1,500 per month in reclaimed licences
Four steps, one destination.
The same sequence on every engagement. It starts read-only and it ends with the Exit Kit in your hands, so the exit is designed before the work begins.
- AuditRead-only discovery in your tenant. Findings arrive in writing, with sources.
- DecideThe €499 Architecture Workshop: a 2-hour live session and a written deliverable in 5 days. You own the plan.
- BuildFixed scope, agreed change windows, evidence recorded as the work lands.
- Hand overExit Kit within 24 hours. Runbooks, source, credentials inventory, architecture record.
Will hardening lock our users or administrators out?
The delivery model is built to reduce that risk: read-only discovery first, named emergency-access exclusions, pilot users, report-only evaluation where Microsoft supports it, agreed change windows and post-change sign-in review. No method can promise zero disruption, so dependencies and reversal options are written into the control register before enforcement.
Does a successful backup job prove we can recover?
It proves the job reached a successful state. Recovery proof also needs a selected recovery point, an approved target, integrity checks, application checks, observed timing and business acceptance. That is what the restore drill produces.
What happens when a restore drill fails?
The workload is not marked recoverable. The failure becomes an owned issue with evidence, residual risk, a due date and a re-test condition. Finding that gap before an incident is the point of the drill.
Is native Microsoft 365 retention a backup?
No. Microsoft's shared-responsibility model places data recovery in the tenant administrator's court. Third-party backup exists because a regulated operator cannot self-attest to trusting the recycle bin under GDPR Article 32.
Do we need Sentinel from day one?
Not always. Defender XDR covers detection and response for most estates first. Sentinel is scoped separately when log sources, retention needs and the operating model justify a SIEM.
Can our auditor talk to you directly?
Yes. The control register is written to be opened in front of an auditor: each control names its source, its deployed setting and its evidence. Walking an auditor through it is part of the engagement, not an extra.