Motor retail · Horsham · 25 staff
A 25-person car dealership in Horsham
Phished and impersonated on an old copy of Office, SMTP mail and local Windows logins. Full migration to Microsoft 365 Business Premium with the Defender Suite and our Defender monitoring, PCs joined to Entra ID with no local admin, patched by RMM, and Microsoft 365 backed up.
- Email: unprotected SMTP to Exchange Online with Defender for Office 365
- Logins: local Windows accounts to Entra ID with MFA and no local admin
- Office: out-of-support local install to current Microsoft 365 apps
- Patching: none to RMM-managed on every PC
- Backups: none to tested Microsoft 365 backup
- Defender Suite with Black Sheep Defender monitoring
The problem
A 25-person car dealership in Horsham that had been phished and impersonated. The set-up made it easy: staff signed in to Windows PCs with local accounts, email came through a hosted SMTP service with no protection in front of it, and an old locally installed version of Office was long out of support. There was no patching, no device management and no backup.
For a dealership, impersonation is not a nuisance. Deposits, finance paperwork and part-exchange settlements all move by email, and a convincing message from a director or a supplier is exactly how money goes missing.
What we did
A full migration to Microsoft 365 Business Premium: mailboxes moved off the SMTP service to Exchange Online, the old Office replaced with current apps, and files into SharePoint and OneDrive. The Defender Suite was added on top of Premium and the whole thing connected to our Defender monitoring service, so impersonation attempts, risky sign-ins and malware are watched and acted on rather than discovered after the money has gone.
Every PC was joined to Entra ID and managed through Intune, with local admin removed. Staff sign in with their company identity, multi-factor authentication is enforced, and Conditional Access keeps company data on managed devices only. RMM tooling keeps Windows and the applications patched, and Microsoft 365 is backed up outside Microsoft and tested.
What changed
The attack path that worked before is closed: a stolen password alone no longer opens a mailbox, impersonation of the directors and suppliers is flagged by Defender before staff see it, and nobody can install anything on a PC because nobody is a local administrator any more. The dealership is on supported software, patched, monitored and backed up.
Most of that came from one licence configured properly, with the monitoring on top. It is the same stack we recommend to nearly every business of this size, because the problems are the same.