Security strategy and reference architectures
- Resilience strategy against ransomware and other attacks: prioritise business-critical assets, business continuity and disaster recovery for hybrid and multicloud environments, secure backup and restore, handling security updates
- Microsoft Cybersecurity Reference Architectures and the Microsoft Cloud Security Benchmark as guardrails
- Protection against insider threats, external attacks and supply chain attacks
- Zero Trust adoption framework, Cloud Adoption Framework and Well-Architected Framework
- Azure landing zones, the DevSecOps process, strategy for the secure use of AI
Security operations, identity and compliance
- Detection and response with XDR and SIEM, centralised logging including Microsoft Purview Audit, monitoring hybrid and multicloud environments
- SOAR with Microsoft Sentinel and Defender XDR, processes for incident response, threat hunting and incident management
- Assess detection coverage against the MITRE ATT&CK matrices
- Identity and access management: Microsoft Entra ID hybrid and multicloud, external identities, modern authentication with Conditional Access and continuous access evaluation, agent identities via Entra Agent ID
- Secure privileged access: Enterprise Access Model, PIM, entitlement management and access reviews, hardening AD DS, secured administrative workstations
- Compliance: translate requirements into security controls, Microsoft Purview, Azure Policy, mapping to standards via Defender for Cloud
Infrastructure
- Security posture in hybrid and multicloud environments: Defender for Cloud, Secure Score, Azure Arc, Defender EASM, Security Exposure Management with attack paths
- Requirements for servers and clients: multiple platforms, mobile devices, IoT and embedded systems, Defender for IoT for OT and ICS environments, security baselines, Windows LAPS
- Requirements for SaaS, PaaS and IaaS: baselines, web workloads, containers and orchestration, security of Azure AI services
- Network security and Security Service Edge: Entra Internet Access as a secure web gateway, Entra Private Access
Applications and data
- Secure Microsoft 365: Secure Score, Defender for Office 365, Defender for Cloud Apps, Intune, Purview; data protection and compliance controls for Microsoft Copilot
- Application security: assess the application inventory, threat modelling, lifecycle strategy, secure development processes, workload identities, API management, Web Application Firewall
- Data security: discovery and classification, encryption of data at rest and in transit, Azure Key Vault, security for data in AI workloads, Azure SQL, Synapse, Cosmos DB and Azure Storage