Skip to main content
VSI Technologies

Technology Services

Controls that hold up when somebody actually looks.

Network, endpoint and identity security, with monitoring and incident response.

The problem

Why this comes up

Security posture is usually a set of tools nobody has correlated. Endpoint says one thing, identity says another, and the network layer has rules from three staff changes ago that nobody dares remove. The gap only becomes visible during an audit, a questionnaire from a customer, or an incident.

The tooling is rarely the gap. Most organisations of any size already own capable products at every layer, the endpoint agent is fine, the identity provider supports conditional access, the firewall is modern. What is missing is that no single person or system can answer the question an auditor actually asks: what can this account reach, and how would you know if it did.

The reason is structural rather than negligent. Each tool was bought to solve the problem in front of it, configured by whoever owned that layer, and reviewed on its own console. The correlation between them was always somebody’s intention and never anybody’s job. So the endpoint console shows a clean fleet, the identity console shows sensible policies, and the combination permits a path neither of them was asked about.

The network layer is where this accumulates most visibly. Firewall rule sets grow monotonically because adding a rule is a five-minute change with a clear requester and removing one is a risk with no owner. After a few years the rule set encodes the organisational history rather than the current business, and nobody will touch it because the blast radius of being wrong is a production outage with your name on it.

The joiner-mover-leaver process is the quiet one. Joining works, because somebody complains immediately if it does not. Moving accumulates, people keep the access from their last role because removing it is nobody’s ticket. Leaving mostly works for the identity provider and mostly does not for the eleven systems that were integrated separately. The result is a population of accounts with more access than any current person needs, which is the precondition for most of the incidents worth worrying about.

None of this is visible from inside until something forces a look: a customer security questionnaire with real teeth, a cyber-insurance renewal, a public-sector bid, or an incident. The first three are inconvenient. The fourth sets the timetable for you.

Recognise any of these

What it looks like from inside

If three or more of these are true, this page is about your estate.

  • Three consoles have to be opened to answer one question about a user
  • Nobody will remove a firewall rule because nobody can prove what it does
  • People who changed roles a year ago still have their old access
  • The incident runbook exists as a document and has never been rehearsed
  • A customer questionnaire took two weeks and several people to complete
  • Privileged accounts are shared because setting up individual ones was slower

What we build

Specifically

  • Identity as the control plane, conditional access, privileged access, and joiner-mover-leaver that actually fires
  • Endpoint detection with response paths defined before they are needed
  • Network segmentation that reflects how the business works now
  • Logging and monitoring correlated across layers rather than sitting in three consoles
  • Incident runbooks tested rather than written

What it integrates with

Named platforms, not categories. If you run one of these, this is the conversation.

  • Palo Alto Networks
  • Cisco
  • Microsoft Defender
  • Microsoft Entra ID
  • CrowdStrike
  • Splunk

Identity as the control plane

Access decisions get made in one place, against conditions, who, from what device, in what posture, reaching what. That includes privileged access with elevation that expires, and a joiner-mover-leaver process that fires against every integrated system rather than against the directory alone. Identity is where this starts because it is the only layer that sees every request, and because the most common serious incident is a legitimate credential used by the wrong person.

Endpoint response, decided in advance

Detection without a decided response is an alert queue. Response paths, isolate, collect, reimage, escalate, get defined and authorised before they are needed, so the person on shift at two in the morning is executing a decision rather than making one. That authorisation conversation is the difficult part and it belongs in the design phase, not in the incident.

Segmentation that reflects the current business

Segmentation gets designed from how the organisation actually works now: which populations need to reach which systems, and which flows exist only because of a project that ended. Rules get removed as well as added, in controlled batches with monitoring, because a rule set that only grows is a rule set that will eventually be replaced wholesale in an emergency.

Correlation, not consoles

Logs from identity, endpoint, network and the platform land somewhere they can be queried together, with retention set against the actual requirement rather than the default. The value is not the dashboard, it is that a question about an account can be answered in one place, which is the difference between a two-hour investigation and a two-week one.

Runbooks that have been rehearsed

Each runbook gets exercised against a simulated incident, with the people who would actually be on shift. Rehearsal finds the things writing never does: the contact who left, the escalation number that goes to a disconnected desk, the recovery step that requires a credential only one person has. A runbook that has never been run is a document, not a control.

How the engagement runs

The exposure loop, and what runs against it

Your estate todayWhat VSI runs against it
01

Identify

Assets, identities and data flows, what actually exists, not what the diagram says.

VSI delivers

Continuous inventory and access review, with the gaps queued as work rather than findings.

02

Protect

Segmentation, hardening, least privilege and MFA across the estate.

VSI delivers

Controls implemented to the framework you are audited on, with evidence captured as they run.

03

Detect

Signals correlated across endpoint, identity and network.

VSI delivers

Monitoring engineered against your MTTD baseline, tuned so alerts stay actionable.

04

Respond

Contain, eradicate, recover, with the business still running.

VSI delivers

Playbooks rehearsed on your systems, measured by time-to-contain in the exercises.

Identify, protect, detect, respond, the loop every security programme walks. The navy rail is what VSI engineers and operates at each stage; every stage reports against the baseline taken before the work began.

How it deploys

The shape of the engagement

And what we need from you at each step. A timeline with no client obligations in it is a timeline that slips.

  1. 01Weeks 1-2

    Posture review across identity, endpoint and network

    Posture review across identity, endpoint and network.

  2. 02Weeks 3-6

    Gaps closed in priority order, with the rationale written down

    Gaps closed in priority order, with the rationale written down.

  3. 03Week 7

    Runbooks tested against a simulated incident

    Runbooks tested against a simulated incident.

  4. 04Ongoing

    Monitoring, review and change control

    Monitoring, review and change control.

What you provide

  • Current tooling inventory and licence position
  • Access to identity and endpoint consoles
  • A named owner for decisions that will inconvenience someone

How this goes wrong

The four ways it fails

Published because it is only writable by somebody who has had the failure. Each of these has happened on this kind of work, and each has a specific thing that prevents it.

The programme delivers a report and nothing changes

Why it happens
Findings were handed to a team with no authority to make the changes that would inconvenience other teams.
What prevents it
A named owner who can arbitrate, agreed before the review starts. This is the single item on the "you provide" list that most determines whether the engagement works.

A control gets rolled back a month after go-live

Why it happens
It was designed against the org chart rather than the workflow, and it blocked something real. Usually conditional access or a segmentation rule.
What prevents it
Design from observed access patterns, pilot with the affected population, and stage enforcement, report-only first, then block. A control that surprises people is a control that gets an exception.

Monitoring produces alerts nobody triages

Why it happens
Detections were enabled at vendor defaults, tuned to a generic environment rather than to yours.
What prevents it
Tuning as part of deployment, and a deliberately smaller set of detections that someone has actually agreed to action. An unread alert is worse than no alert, because it creates the belief that somebody is watching.

The leaver process still misses systems

Why it happens
Some applications were integrated with the identity provider and some were connected directly with local accounts, and only the first group is in the deprovisioning path.
What prevents it
An application inventory that records how each one authenticates, and a deliberate programme to move local-account systems behind the identity provider. The inventory is the unglamorous half and it is the half that works.

Return on investment

Where the return comes from

Every lever names the mechanism and how it is measured against your own baseline, captured before the work starts. That is how the return stays a number your finance team can audit rather than a promise on a slide.

  1. 01

    Detection and response time

    The cost of an incident scales with how long an attacker operates unseen. We baseline mean time to detect and mean time to respond against your current tooling, then engineer correlation and playbooks against those two clocks, and report them quarterly, from your own logs.

  2. 02

    Control coverage against the framework you are audited on

    Security spend returns twice: once as risk reduction, once as audits and questionnaires that stop consuming engineering weeks. Controls map to the framework your customers and regulators actually test, with evidence collected continuously, so the measurement is assessment-preparation time falling.

  3. 03

    Attack-surface reduction

    Dormant accounts, standing privilege and unmanaged assets are risk that costs nothing to hold and everything to keep. Identity hygiene and asset inventory are run as recurring jobs, measured as counts that trend to zero: orphaned accounts, admin rights without a review date, unknown devices.

  4. 04

    Insurance and questionnaire posture

    Underwriters and enterprise customers price your controls. MFA coverage, EDR coverage, tested backups and response plans are exactly what their forms ask; we build to the form and keep the evidence current, measured in renewal terms and security-review cycle time.

Run your own numbers in the ROI calculator

An unbranded badge reader on a concrete wall in a secured corridor.

Timing

Now, soon, or not yet

Most of the value in this decision is in when, not whether. Find the row that matches your situation.

When to start cybersecurity work
CriterionVerdictWhy
A cyber-insurance renewal or customer security questionnaire is dueNowBoth will ask questions you cannot currently answer quickly. Answering them badly has commercial consequences that outlast the review.
You are bidding for public-sector or regulated workNowControl evidence is a gate, not a differentiator. Starting during the bid means starting too late.
Someone with broad access has left, or is about toNowThis is the moment the deprovisioning gap becomes concrete rather than theoretical.
A major identity or endpoint platform change is plannedSoonDo the posture review first so the migration lands on a design rather than replicating the current configuration into a new product.
Nothing has changed, no audit is pending, and the estate is small and staticIt can waitA full programme would be overhead. Fix the leaver process and privileged access, which are cheap and where the real exposure is.

Buying for a public-sector body

Public-sector work changes the order of operations. Control selection follows the framework the agency is actually assessed against, so the review starts from that catalogue rather than from a generic posture model, and the output is written as control-by-control evidence rather than as a risk score, because a risk score is not something an assessor can accept. Continuous monitoring is a requirement rather than a maturity goal, which means the logging design has to satisfy it from day one. We will also tell you which findings are genuinely material versus which are documentation gaps; conflating the two is how remediation budgets get spent on paperwork.

The federal profile

Objections

What you are probably thinking

We already have tools for this.
Most organisations do. The finding is rarely a missing tool; it is three tools that do not agree, and no single view of what a given user can actually reach. The review starts from what you own.
A security programme will slow everything down.
Some of it should, privileged access is meant to be slower. The rest is designed around how the business works, which is why the review comes before the change and why we ask for an owner who can arbitrate.
We need a specific certification.
Then the programme is scoped against that framework from the start. We will tell you plainly which controls you already meet and which will take real work, rather than producing a readiness score.

Questions

Asked often enough to answer here

Will you tell us to replace our security tools?
Rarely, and never as the opening move. The review starts from what you already own and what you are already paying for, because in most estates the finding is configuration and correlation rather than capability. Where a genuine capability gap exists we will name it, and we will also tell you when the honest answer is that you own the right product and are using a fraction of it.
How do you avoid breaking things when you tighten access?
Staged enforcement. A conditional access or segmentation change goes in report-only first, so you can see who it would have blocked before it blocks anyone, then to enforcement for a pilot population, then to the full estate. It is slower, and it is the reason controls stay in place rather than being rolled back after the first complaint.
What do you actually do during an incident?
What the runbook says, because the decisions were made in advance, that is the whole point of rehearsing them. Practically: contain according to the pre-authorised response path, preserve evidence before remediating, keep a timeline as you go rather than reconstructing it later, and escalate to the named person rather than to a distribution list. If we hold a monitoring engagement, the detection and the first response are ours; the decision to notify regulators or customers is always yours.
Can you scope this against a specific control framework?
Yes, and it is the better way to run it when you have one. The review is then written control by control against that catalogue, with an honest position on each: met, partially met with the gap named, or not met with the work estimated. What we will not produce is a readiness percentage, it aggregates away exactly the detail an assessor is going to ask about.
Do you provide monitoring, or just the design?
Either. Design-only is a legitimate engagement and some organisations should take it, particularly where an internal team has the capacity but not the bandwidth to do the design work. Where monitoring is ours, the escalation path reaches a named person rather than a queue, and the commitment behind that is published rather than implied.
How long before we see a difference?
The posture review takes about two weeks and produces the thing most organisations are missing on day one: a single accurate picture. Remediation is sequenced by exposure, so the changes that reduce real risk happen in the first few weeks and the longer programme is the documentation, the inventory and the platform work that prevents the gap reopening.

Stay current on our services

Occasional updates across every VSI service, new capabilities, new offerings, and what changed. No sales sequence; leaving is one reply.

Used only for these updates, see the privacy statement.

What it costs

Pricing

Posture review is a fixed-price engagement. Remediation and managed monitoring are scoped from what it finds.

Book a 20-minute assessment