Skip to content

A baseline only holds if someone keeps checking it.

Defender for Business and Defender for Microsoft 365 ship with sensible defaults. Ongoing care is about keeping that baseline active, explained, and reviewed—not about running a security operations centre from a monthly retainer.

Book a scoping call

Four things worth checking on a cadence.

  • Baseline

    Baseline policy state

    Standard protection policies remain enabled tenant-wide and have not been silently loosened.

  • Alerts

    Alert triage cadence

    New alerts get a monthly look and a recorded outcome, instead of accumulating unread.

  • Exclusions

    Exclusion accountability

    Every exception has a documented reason, an owner, and a reason it is still needed.

  • Devices

    Device coverage gaps

    New or changed devices are confirmed as enrolled and protected, not assumed.

Basics, kept current.

Basics kept current, not a security operations centre.

This is not managed detection and response, a staffed 24/7 monitoring desk, or an incident-response retainer, and no compliance certification is implied by keeping the baseline current. What ongoing care actually does is smaller and more honest: confirm the standard protections are still switched on, give new alerts a monthly look, and keep exceptions explained rather than accumulating silently.

That is enough to prevent the most common failure mode—a sensible default that quietly drifted out of place months ago and nobody noticed. It is not a substitute for a dedicated security program when the risk profile calls for one.

Five recurring checks.

  • Baseline protection policies still apply tenant-wide as configured
  • New alerts since the last review have been triaged and a plain outcome recorded
  • Every active exclusion still has a documented reason and a named owner
  • New or changed devices show current coverage rather than an assumed default
  • Anything beyond routine has a clear escalation path, agreed in advance

A formal posture review is a different, separately scoped service.

Deep hardening, a point-in-time security assessment, or a formal review against a specific standard is not something a recurring care retainer should quietly absorb. When that question comes up, it deserves its own defined scope rather than an implied add-on to routine administration.