Recruitment · Brighton · 90 staff
A 90-person recruitment consultancy in Brighton
The previous supplier had done no patch management: 12,000 open vulnerabilities, local admin logins, no antivirus and no backups. Moved to Microsoft 365 Business Premium with the Defender Suite, Entra ID and Autopilot, with RMM tooling to catch up on the patching. Cyber Essentials passed.
- Open vulnerabilities: from 12,000 to normal monthly churn
- Local admin logins: 90 to 0, Entra ID and Autopilot on every device
- Antivirus: none to Defender for Endpoint on every machine
- Backups: none to tested backups of Microsoft 365 and the remaining systems
- One licence, Business Premium with the Defender Suite, instead of four products
- Cyber Essentials: passed
The problem
A 90-person recruitment consultancy in Brighton with a long-standing IT supplier and no reason to think anything was wrong, until we looked. Nobody had been patching anything: the first scan found 12,000 open vulnerabilities across the estate. Staff signed in to their PCs with local accounts that had administrator rights. There was no antivirus. There were no backups.
For a business whose assets are candidate and client data, and whose staff live in their inbox, that is not a technical debt. It is an unreported incident waiting for a date.
What we did
Microsoft 365 modern work on Business Premium with the Defender Suite added, so identity, email, endpoint and data protection came from one licence rather than four products. Every device was enrolled in Entra ID and Intune through Autopilot, which ended local admin logins: staff sign in with their company identity, multi-factor authentication is enforced, and the device is encrypted and compliant before it opens company data. Defender for Endpoint replaced the absence of antivirus on every machine.
Twelve thousand vulnerabilities do not clear on their own. RMM tooling was deployed to catch up on the patching in waves, oldest and most exposed first, out of hours so the consultants kept working, with the count tracked week by week until it was down to the normal churn of new releases. Backups of Microsoft 365 and the remaining systems were set up and tested.
What changed
The vulnerability count went from 12,000 to the handful that appear and are patched each month. Nobody signs in as a local administrator. Every device reports to Defender and Intune, and a lost laptop is a remote wipe rather than a data breach. The backups have been restored from in a test, which is the only kind of backup that counts.
The consultancy then went for Cyber Essentials and passed. The controls it asks for, patching, access control, malware protection, secure configuration and firewalls, were the same ones the project had put in place, so certification was an assessment of work already done rather than a project in itself. The consultancy can now answer a client's supplier security questionnaire from evidence rather than hope, which for a recruitment business is increasingly the difference between winning a framework and not.