Security assessment and remediation
A security review found a set of critical vulnerabilities. We remediated them, then moved the firm onto managed services so the gaps stay closed.
Seven pieces of work we have built, secured, or run. Each one records what the situation was, what we did, and what changed. Every client is described by its sector rather than named, and we leave out any detail that would help an attacker or breach a client confidence.
Security reviews and remediation, Zero Trust and identity, certification, migrations to Microsoft 365 and to the cloud, and full desktop virtualisation. Different sectors, one accountable team behind all of it. Why each one is described by sector rather than named is set out below.
A security review found a set of critical vulnerabilities. We remediated them, then moved the firm onto managed services so the gaps stay closed.
Centralised authorisation on Entra ID, with device lockdown, single sign on, and Conditional Access policies applied consistently across every platform.
Migration from ageing on-premises servers to hosted cloud infrastructure: file server, Active Directory, and line of business apps, all reachable over secure VPN connectivity.
A migration from Google Workspace to Microsoft 365, with mailboxes, files, and user profiles moved across, staged and tested to minimise disruption to operations.
A standing start taken to certification: device management, a hosted VPN, written policies, regular patching, and a clean Cyber Essentials pass.
Taking organisations from a basic Microsoft 365 setup to a secured environment, with Defender, Intune, and Conditional Access deployed and configured.
Full desktop virtualisation for a remote first financial services team: work from anywhere, on any device, with the whole estate managed centrally.
Different problems, one way of working. We start by understanding what matters, fix the highest risks first, and build security and evidence in from the start rather than bolting them on. The responsibility stops with us.
We apply to ourselves the rule we set our clients: nothing goes on this page that would help someone attack the organisation it is about.
What was at stake and why it mattered, in business terms anyone can follow.
How we thought about it and what we did, without the operational detail an attacker could use.
What changed, and the limits of what we can show. We do not dress up figures or claim precision we cannot stand behind.
Every client above is described by its sector rather than named. That is not modesty: a named client alongside the detail of what was weak and what we changed is useful to anyone planning an attack on them, and it is their information to disclose, not ours. We name a client only with written consent, and none has been given for the work on this page.
Bring us the system to build, the risk to close, or the migration you have been putting off.
Hello, I am Ainsley, the AI assistant here at Dead Simple Computing. Ask me anything about managed IT, cyber security, software and AI, or governance and audit. I can also put you in touch with a person.
Replies are AI generated and can be wrong. Your messages are sent to a third-party AI service to produce them, and a member of our team can read this chat and may join it. Do not type anything confidential. See our privacy notice.