Security
Most security reviews tell you whether somebody could get in. I tell you something more useful: whether, if they did, you could prove what they took.
- Document
- WW-F-017
- Version
- 2.0
- Issued
- 2026-09-12
- Last revised
- 2026-09-12
- Scope
- Security engagements
- Authority
- Principal
I get called after it happens. This is what I wish had been in place
Every incident I work has a moment where somebody asks a reasonable question and the answer is "we don't know, and we can't find out". Which files did they actually open. Whether the mailbox was read before or after the wire went. What the leaver copied on their last Friday. How long they had been inside.
Those questions are answerable, cheaply, if a handful of settings were right beforehand. They are unanswerable at any price afterwards. That gap is the whole of this page.
A penetration test tells you where the doors are. It does not tell you that your audit log keeps thirty days against an intruder who sat inside for ninety, or that the setting recording which emails were actually read sits one licence tier above the one you bought — so after a compromise you are guessing at your notification obligation instead of bounding it. I see those two things constantly, and neither shows up in a security assessment.
What you get
Evidence readiness
I go through every log source you have and tell you what it records, how long it keeps it, what question it could actually answer, and what changing it costs. Mailbox and tenant auditing, endpoint telemetry, firewall and VPN, backup logs, and the licence tiers that quietly decide what exists at all.
You end up with a short list of changes — most of them free, some of them a licence line — and a clear statement of what you would be able to establish if something happened tomorrow. It is the best-value thing on this page and the one people put off, because nothing is visibly broken until the day it matters.
Usually 8–12 hours per tenant.
Insider risk and IP protection
The departing-employee problem, solved before there is a departing employee. What a leaver can currently take and by which routes. Where access reviews have quietly stopped happening. What your offboarding deletes, and on what timer — because the mailbox that auto-deletes on day thirty is usually the evidence you most wanted on day forty.
It ends with a written hold procedure: the one-page thing HR or IT follows that keeps a laptop out of the reimage queue when it matters. Most of the fixes cost nothing.
Usually 6–16 hours, starting with a bounded first block.
Tenant and identity hardening
Microsoft 365 or Google Workspace read against the configurations that actually turn up in incidents, rather than against a generic checklist. MFA coverage and the accounts that slipped through it. Legacy authentication still enabled. Conditional access. Mail forwarding and transport rules. OAuth applications somebody consented to in 2023. Privileged roles nobody has reviewed. Guest accounts from a project that ended.
Nearly every business email compromise I see traces back to something on that list.
Usually 8–14 hours per tenant.
Incident rehearsal
Half a day, your people, a scenario built around your business rather than a generic one. The value is not the exercise. It is the decision log, the list of things nobody could find, and the three phone numbers that turned out to be wrong — discovered on a Tuesday afternoon rather than at two in the morning.
$6,500, including the marked-up plan.
Standby
Conflicts cleared in advance against a named list, rates and terms fixed for the year, out-of-hours authorisation pre-signed, and a named contact who already knows your environment. Everything that is slow to arrange while something is on fire, arranged while nothing is.
$7,500 a year, credited in full against your first engagement.
Rates
| Work | Rate | Scope |
|---|---|---|
| Review, analysis, findings, anything I put my name to | $425/hr | The same rate as investigative work, because it is the same work. Quoted as an estimate against a ceiling you authorise, and I stop and report at 80% of it. |
| Configuration review, log inventory, collection, documentation | $175/hr | Routine work done under direction. The conclusions are still at the full rate, whoever gathered the material. |
| Out of hours and expedited | +35% | Outside 08:00–18:00 Eastern Mon–Fri, weekends and federal holidays, or a start inside 24 hours. Applies only to the hours actually worked out of hours. |
You get a written estimate and a ceiling before anything starts. I publish the usual hour ranges above so the estimate can be checked against something rather than taken on trust.
Why a forensics practice and not a security firm
Because I am the person who gets called when it has already gone wrong, and that changes what I look for.
A consultancy reviewing your tenant is working from a hardening guide. I am working from a memory of sitting in front of a client explaining that the answer to their question no longer exists anywhere, and watching them absorb what that means for their notification, their insurance claim and their case.
I also sell you nothing else. No product, no licence, no managed service, no commission from anyone whose software I might recommend. If a tool is the right answer I will name it and tell you I have no interest in whether you buy it — which is worth saying in a market where most advice arrives attached to a reseller agreement.