foundry
Managed security

Foundry Secure

Foundry manages your security posture — identity, endpoints, email, DNS, patching, backups and incident response — so the handful of controls that stop real attacks are always on.

Cybersecurity marketing is full of fear. Reality is simpler: most attacks succeed through a handful of paths — weak or reused passwords, phished logins, unpatched systems, and backups that turn out not to exist. Close those paths and you're most of the way safe. Foundry Secure is the ongoing management of exactly that: not "we installed a product", but "your security posture is someone's job".

Prevent → Detect → Respond → Recover

Every control we run sits somewhere in this loop, and every part of the loop is covered. Prevention alone fails eventually; recovery alone means you've already lost a week.

StageWhat we manage
PreventMFA and Conditional Access on identity. Secure configuration of Microsoft 365 or Google Workspace. Device encryption. Patch and vulnerability management. Email authentication (SPF, DKIM, DMARC) and DNS filtering. Business password manager rolled out and trained. Security awareness for your people.
DetectManaged endpoint detection and response on every device. Security logging and alerting across identity, email and endpoints. Monitoring for impossible travel, new admin accounts, mail-forwarding rules and the other tells of a compromised account.
RespondA defined incident response process: isolate the device, revoke sessions, reset credentials, trace what happened, tell you what it means in plain English.
RecoverIsolated, versioned, ransomware-resistant backups — including Microsoft 365 and Google Workspace — with restores tested on a schedule. See Foundry Cloud for Recovery Assurance.

What's covered

  • Identity: MFA, Conditional Access, privileged-account control, account lifecycle, sign-in monitoring.
  • Microsoft 365 / Google Workspace security: tenant hardening, sharing defaults, external forwarding blocked, legacy authentication disabled.
  • Endpoints: managed EDR/XDR, disk encryption, secure configuration baselines, patching.
  • Email: phishing and malware protection, impersonation defence, domain authentication.
  • DNS and web: DNS security filtering, TLS certificates managed and renewed, web application firewall on everything you publish.
  • Vulnerabilities: regular scanning, prioritised fixes, exceptions reported rather than buried.
  • People: password manager, security awareness, sensible policies that people actually follow.
  • Backup protection: backups isolated from the environment they protect, so ransomware can't reach them.
  • Compliance: Cyber Essentials and Cyber Essentials Plus readiness, and evidence for cyber-insurance questionnaires.

Security that doesn't slow you down

These controls are chosen because they barely interrupt anyone's day. Certificates renew themselves. Passwords autofill. MFA is one tap. Security that fights your team always loses. Security that flows with it sticks.

Frequently asked questions

Find out what your technology is actually costing you.

Thirty minutes with an engineer about your current environment: the biggest risks, the inefficiencies, and what you’re paying for that you don’t use. No obligation, no sales script. See what the first call covers.