Skip to content
← All Solutions
Solution pillar

Security & Infrastructure

Azure landing zones, Defender XDR, Sentinel and tested recovery, built as evidence an auditor can open: GDPR Article 32, DORA Article 9, NIS2 Article 21.

Review 38 risk-weighted checks from the ITSailor Microsoft 365 baseline, with a directional crosswalk to DORA, NIS2, GDPR and NIST CSF 2.0.

The short version

What this covers

Azure and GCP landing zones, Microsoft Defender XDR, Sentinel, Microsoft 365 hardening, and backup with rehearsed recovery. Controls mapped to their sources.

Who it is for

Operators under DORA, NIS2 or GDPR scrutiny, and any team whose last audit answer was a screenshot folder and a spreadsheet nobody trusts.

Where to start

Start free with the security scorecard, or book the €499 Architecture Workshop: a 2-hour live session in your tenant and a written deliverable in 5 days.

How it ends

Every engagement closes with an Exit Kit: control register, Terraform source, runbooks and the evidence trail, in your hands.

Where it fails

Before you buy another security tool, configure the ones you have already paid for. The common failures are ordinary: unfinished rollouts with no written record.

The Microsoft licences you bought never got a documented hardening pass. Conditional Access is opt-in, Defender XDR is half onboarded, and retention is whatever an admin clicked through years ago.

A written baseline pass with each control recorded: configuration, owner, exception and rollback.

Control register mapped to Microsoft, NIST and EU sources

Backup jobs report green, but nobody has restored anything under pressure. Whether the business actually recovers is untested.

Restore drills with observed timing, integrity checks and business acceptance, repeated on a schedule.

Recovery drill runbook with dated drill evidence

GDPR Article 32, DORA Article 9 and NIS2 Article 21 ask for proof of controls. What exists is last quarter's screenshots and a spreadsheet that has not been touched in six months.

Controls tied to their deployed settings so the evidence regenerates instead of going stale.

Source-linked control mapping for the audit binder

Solution narratives

3 narratives: full pitch with deliverables, scope and case context

Services in this pillar

7 discrete engagements: fixed scope, written deliverables

Measured engagement

Lifecycle automation

Offboarding became an execution log, not an email thread.

Power Automate connected HR status changes to Microsoft 365 offboarding: session revocation, mailbox conversion, licence recovery, OneDrive archive, and audit trace.

Anonymised outcomes from the founder's prior operating roles in regulated industry, stated as such, not ITSailor client engagements.

On the record
  • Offboarding runs HR-triggered, with no engineer time
  • Clean access-termination result in the first internal audit after rollout
  • ~€1,500 per month in reclaimed licences
Chart the course

Four steps, one destination.

The same sequence on every engagement. It starts read-only and it ends with the Exit Kit in your hands, so the exit is designed before the work begins.

  1. AuditRead-only discovery in your tenant. Findings arrive in writing, with sources.
  2. DecideThe €499 Architecture Workshop: a 2-hour live session and a written deliverable in 5 days. You own the plan.
  3. BuildFixed scope, agreed change windows, evidence recorded as the work lands.
  4. Hand overExit Kit within 24 hours. Runbooks, source, credentials inventory, architecture record.
Questions buyers ask
Will hardening lock our users or administrators out?

The delivery model is built to reduce that risk: read-only discovery first, named emergency-access exclusions, pilot users, report-only evaluation where Microsoft supports it, agreed change windows and post-change sign-in review. No method can promise zero disruption, so dependencies and reversal options are written into the control register before enforcement.

Does a successful backup job prove we can recover?

It proves the job reached a successful state. Recovery proof also needs a selected recovery point, an approved target, integrity checks, application checks, observed timing and business acceptance. That is what the restore drill produces.

What happens when a restore drill fails?

The workload is not marked recoverable. The failure becomes an owned issue with evidence, residual risk, a due date and a re-test condition. Finding that gap before an incident is the point of the drill.

Is native Microsoft 365 retention a backup?

No. Microsoft's shared-responsibility model places data recovery in the tenant administrator's court. Third-party backup exists because a regulated operator cannot self-attest to trusting the recycle bin under GDPR Article 32.

Do we need Sentinel from day one?

Not always. Defender XDR covers detection and response for most estates first. Sentinel is scoped separately when log sources, retention needs and the operating model justify a SIEM.

Can our auditor talk to you directly?

Yes. The control register is written to be opened in front of an auditor: each control names its source, its deployed setting and its evidence. Walking an auditor through it is part of the engagement, not an extra.

Ready when you are

Start with the diagnostic. Decide with the workshop.