Capability

Threat protection and detection

Deploying Defender and Sentinel is the easy part. Making them detect the things that matter, without drowning your team or your budget, is the work.

Most estates we look at have the licences and have done the deployment. What they often do not have is confidence that anything would actually fire. Analytics rules switched on at onboarding and never revisited, attack surface reduction rules left in audit mode indefinitely, exclusion lists that have grown quietly for years, and log ingestion nobody has costed against what it detects.

What we assess

  • Actual coverage. Which devices, identities and mailboxes are genuinely onboarded, against how many licences you are paying for. The gap is usually larger than expected.
  • Policy quality. Attack surface reduction rules still in audit mode, exclusions that have accumulated without review, and whether tamper protection is on.
  • Sentinel workspace design. Table tiering, retention settings, and what you are ingesting against what any rule actually queries.
  • Detection coverage. Which analytics rules are enabled and tuned, and how that maps to real technique coverage rather than to a count of enabled rules.
  • Connector health. Whether the data you believe you are collecting is arriving, and has been arriving continuously.
  • What happens next. Incident handling, automation and playbooks, and who is actually looking at two in the morning.

What we do

  • Defender deployment and onboarding across endpoint, identity and Office 365, including the devices that never quite got enrolled
  • Moving attack surface reduction rules from audit into enforcement without breaking the business, in tracked stages
  • Sentinel design and deployment: workspace architecture, table tiering, retention and cost model
  • Analytics rule development and tuning, mapped to MITRE ATT&CK so coverage is a real measure rather than a count
  • Automation and playbooks for the incidents that follow a predictable path
  • Ingestion cost optimisation, which frequently funds the rest of the work

Found: A Sentinel workspace was taking roughly forty per cent of its ingestion volume from one verbose firewall table that no analytics rule referenced, and had no retention policy set against it.

Fixed: The table moved to an auxiliary tier with retention matched to how it was genuinely used, which was occasional investigation rather than detection. Ingestion spend dropped substantially and the data stayed queryable.

Detection quality and cost are the same conversation. Paying to ingest data that no rule reads is not buying you security, and the budget it frees usually covers the tuning work that does.

The rest of the stack

This does not sit on its own

The findings that matter most usually cross between these areas. We look at all of them, whether or not that is what you asked us to look at.

Want a look at your threat protection and detection?

An assessment can be scoped to this area alone, or to the whole estate. Tell us what is worrying you and we will tell you which is worth paying for.