This is the documented standard we use to evaluate and manage client environments. It doesn't mean every client must buy every product. It means we evaluate the same things every time, explain the risk clearly and recommend what fits your business.
Each area starts with the outcome you're paying for, followed by the controls that achieve it and the related NIST CSF function and CIS Control numbers.
Identity & access
Outcome: Stolen passwords can't be used to get in, and people only have the access they need.
NIST CSF: ProtectCIS Controls: 5, 6
- MFA on every supported account, phishing-resistant MFA where practical
- Microsoft Entra ID security policies and Conditional Access
- Least-privilege access and separate admin accounts
- Prompt removal of former employees and inactive accounts
- Password manager and strong password policy
Devices (endpoints)
Outcome: Computers are hardened, patched and watched for attacks around the clock.
NIST CSF: Identify · Protect · DetectCIS Controls: 1, 2, 4, 7, 10
- Managed endpoint detection and response (EDR), with MDR where appropriate
- Automated patching of operating systems and apps
- Full-disk encryption (BitLocker)
- Device compliance and mobile device management (MDM)
- Hardware and software inventory
Network
Outcome: Outsiders can't reach what they shouldn't, and guests stay off business systems.
NIST CSF: Protect · DetectCIS Controls: 4, 12, 13
- Business-grade firewall with current firmware
- Secure VPN or remote access
- Separate guest Wi-Fi and network segmentation
- DNS filtering
- WPA2/WPA3 wireless and review of exposed ports and services
Email & Microsoft 365
Outcome: Phishing and spoofed emails are stopped or flagged, and files aren't overshared.
NIST CSF: Protect · DetectCIS Controls: 3, 9
- SPF, DKIM and DMARC
- Anti-phishing, anti-spam, and link and attachment scanning
- External sender warnings
- SharePoint/OneDrive sharing restrictions
- Microsoft Secure Score reviews and audit logging
Backup & recovery
Outcome: You can recover from ransomware, deletion or hardware failure, and you know how long it takes.
NIST CSF: RecoverCIS Controls: 11
- Automated, encrypted, offsite backups
- Immutable or ransomware-resistant copies
- Backup monitoring and regular restore tests
- Documented recovery time (RTO) and recovery point (RPO) objectives
- Business continuity planning
Monitoring & response
Outcome: Threats are noticed quickly and handled with a plan, not panic.
NIST CSF: Detect · RespondCIS Controls: 8, 17
- Centralized security logging and alert monitoring
- Vulnerability assessments, prioritizing CISA KEV items
- Written incident response and escalation procedures
- Communication plan and post-incident review
People
Outcome: Employees recognize scams and report them.
NIST CSF: ProtectCIS Controls: 14
- Recurring security awareness training
- Phishing simulations
- Guidance on MFA, passwords, remote work and safe browsing
- Simple process for reporting suspicious activity
Vendors & policies
Outcome: Third parties are held to clear security expectations, and responsibilities are written down.
NIST CSF: GovernCIS Controls: 15
- Review of third-party and remote access
- Documented responsibilities between you and your providers
- Periodic access reviews
- Data handling and retention policies
Products serve outcomes
Tools like SentinelOne, Cisco Duo, Axcient and Microsoft 365 security features are how we deliver these outcomes, not the goal in themselves. We choose and configure technology to meet the baseline, and we can explain what each one does for you.
Last reviewed: October 2026. Laws and standards change; always confirm with the official source.
