01
Group and subsidiaries · Construction materials · Ongoing
Security Foundation
Operational Assurance
The foundation the AI work had to sit on
Situation
A group of operating companies on Microsoft 365, each subsidiary running its own footprint. Endpoint protection with nobody watching it. Microsoft’s own protections half-configured. No visibility into what left the network, including, it turned out, to AI tools.
What we ran
Modernized the foundation instead of replacing it. Configured the Microsoft tenant to do what it was already licensed to do. Put controls on what leaves the network. Consolidated management and remote access.
What changed
AI use on company devices now runs through a controlled path with policy and training attached. Before, nothing could see what left the network, so any policy would have been a document.
Read the detail
Everything above this layer assumes the environment underneath is sound. If identity, egress, and endpoint aren’t right first, AI adoption widens the blast radius of problems already there.
Coverage is end to end:
The network edge, and everything leaving it
Every endpoint on it
Every identity using it
Every device carrying it
A gap in one makes the others decorative. What sits in each is a vendor decision, chosen for real escalation paths and for what they let us hand off, because a small provider can’t staff an overnight analyst seat.
The egress layer is where the foundation and the AI work meet. The same control that filters web traffic determines which AI tools reach the network, so when the AI policy was written the mechanism to enforce it was already deployed.
Almost everything at this size runs on Microsoft 365, and we harden what’s there. A lot of what’s missing isn’t a product nobody bought. It’s capability already licensed and never switched on.
Same architecture at forty staff, fewer sites.