Available for work · response within 2 hrs Call Call back WhatsApp

Home/Case studies

Security incident response

Zero-trust rebuild after a suspected data theft

An incident exposed over-permissive access. The response rebuilt identity and device control from the ground up.

The challenge

A suspected data theft incident triggered an investigation. What it surfaced was more concerning than the incident itself: access across the Microsoft and CRM estate had grown flat and over-permissive over several years. Multi-factor authentication was applied inconsistently, privileged roles had accumulated well beyond what anyone needed, and there was no reliable way to establish who could reach what. The business could not answer basic questions about its own access model.

What I did

I ran the investigation first, establishing what had actually been accessed and by whom. From there I designed a zero-trust response rather than a set of point fixes. That meant Conditional Access policies governing when and from where a login is permitted, multi-factor enforced consistently rather than optionally, privileged roles stripped back to what each person genuinely required, and device compliance enforced through Intune so that only known, healthy devices could connect at all. Equivalent controls were applied across the CRM and ERP platforms, not just the Microsoft estate, because access does not stop at one system boundary.

The outcome

Access is now controlled and, importantly, demonstrable. The business can produce evidence of its controls rather than assert that they exist, which matters both for client due diligence and for insurance.

At a glance

  • Full investigation into the suspected incident
  • Conditional Access governing every sign-in
  • Multi-factor enforced consistently across the estate
  • Privileged roles reduced to genuine need
  • Device compliance enforced through Intune
  • Matching controls applied across CRM and ERP

Related service

This work falls under Security, compliance & zero-trust. If you are facing something similar, that page explains how I approach it.

Response times: within 2 hours during working hours, and never more than 24 hours.

Facing something similar?

Tell me what you are dealing with and I will give you a straight view on how I would approach it.