Cybersecurity & Risk
You have cybersecurity in place. How well do you understand where you stand?
Most organizations already have security in place.
MFA. Backups. Endpoint protection. Email security. An MSP. Maybe MDR, cyber insurance and Microsoft 365 security tools.
Good.
The harder question is whether the right protections are in place, whether they’re working the way leadership thinks they are, and whether anyone understands the whole picture.
Marshall Technology helps leadership understand where the organization really stands, identify meaningful cybersecurity risks, recognize what is already working, decide what deserves attention and turn those decisions into action.
Security tools are only part of the picture.
Cybersecurity is broader than passwords, antivirus and phishing emails.
A company can have good security products and capable technology providers and still have gaps.
- An administrator is excluded from MFA.
- A former employee account is still active.
- A critical system isn’t being patched.
- A backup runs every night, but nobody has tested whether it can actually be restored.
- A vendor has more access than it needs.
- Sensitive information is being shared externally without anyone realizing it.
- A security alert goes to an inbox nobody checks.
- A business application sits outside the MSP’s responsibility.
- The incident response plan exists, but nobody knows what to do with it.
Backed up ≠ recoverable.
The important question isn’t only whether the backup completed. It’s whether the business can recover what it needs when it matters.
31% of breaches started with exploitation of software vulnerabilities.
Individually, many controls may be working exactly as intended. The gaps often appear where responsibilities overlap, where nobody is quite sure who owns something, or where everyone assumes someone else has it covered.
Cybersecurity involves leadership, internal IT, HR, employees, MSPs, security providers, software vendors and other partners.
“Our MSP handles that.”
Good. What exactly does “that” include?
Cybersecurity problems often live between the systems, vendors and people responsible for protecting the business.
Someone needs to look across the whole picture.
Your cyber insurance application is asking some uncomfortable questions.
- Is MFA enforced?
- Are backups protected? When were they tested?
- Is endpoint detection in place?
- Is there an incident response plan?
- How is privileged access managed?
- What monitoring exists?
- How do outside vendors access systems?
Sometimes you know the answers.
Sometimes you think you know the answers.
And sometimes the questionnaire reveals that a control isn’t implemented the way everyone believed it was.
Marshall Technology can help interpret what the questionnaire is asking, verify the technology and processes behind the answers, identify gaps and determine what would be required to address them.
The objective isn’t to find the answer the insurer wants to hear. It’s to make sure the answer is accurate.
Where a gap exists, we can help determine the appropriate next step and build it into a practical plan.
Start with the risk. Then look at the technology.
Cybersecurity decisions make more sense when they begin with the business.
What information matters? Which systems are critical? Who has access? What happens if something becomes unavailable? What protections are already in place? Are they appropriate for the risk?
That perspective also matters when things are going well.
If MFA is strong, endpoints are properly managed, backups are sound, Microsoft 365 is well configured or your MSP is doing a good job, leadership should know that too.
Security spending should be driven by what the organization actually needs, not by the assumption that more products always mean better security.
No cybersecurity program, technology or provider can eliminate every risk or guarantee that an incident will never happen.
Organizations can understand the meaningful risks, reduce them where appropriate, prepare for what could happen and make informed decisions about the risk that remains.
Some risks require immediate attention. Others can be reduced through configuration changes, better processes, another control, contracts, insurance or a different way of working. Some may be reasonable for leadership to knowingly accept.
The important thing is that those decisions are informed and intentional.
Cybersecurity Risk Assessment
For organizations that want an independent view of their cybersecurity position, the Marshall Technology Cybersecurity Risk Assessment looks across the technology environment, the controls protecting it and the people and providers responsible for it.
The assessment focuses on five broad areas.
Identity, Access & Microsoft 365
Accounts, MFA, privileged access, authentication, Microsoft 365 and Entra controls, account lifecycle and how access is granted and removed.
Devices, Network & Infrastructure
Endpoints, servers, networks, patching, vulnerabilities, security tooling and the systems the business depends on.
Data Protection, Backup & Recovery
Sensitive information, access and sharing, backup protections, retention and whether critical systems and data can actually be recovered.
Monitoring, Response & Preparedness
Security monitoring, alerts, escalation, incident response, recovery planning and whether responsibilities are understood before something happens.
Governance, People & Third Parties
Policies, security awareness, vendor access, MSP and security-provider responsibilities, cyber insurance requirements and oversight.
48% of breaches involved a third party.
The assessment gives leadership a practical view of what is working, where meaningful exposure exists, why it matters, what deserves attention first, what can wait and what should happen next.
Finding → Decision → Action
Identifying a problem is only useful if someone decides what to do about it.
Once leadership agrees that something should be addressed, Marshall Technology can help evaluate the options, coordinate the appropriate internal team, MSP, vendor or specialist, and verify that the agreed improvement actually happened.
The engagement doesn’t have to end with:
Here’s your report. Good luck.
Sometimes you already know where you need help.
A full Cybersecurity Risk Assessment isn’t always the starting point.
Marshall Technology can also provide focused help when the concern is already clear.
Microsoft 365 Security Review
Review identity, MFA, Conditional Access, privileged access, sharing and other Microsoft 365 and Entra security controls.
Cybersecurity Governance & Policies
Develop or improve practical policies, responsibilities and governance around how technology and information should be protected.
Incident Readiness
Review whether the organization knows how to recognize, escalate, communicate and respond when a cybersecurity incident occurs.
Vendor & MSP Security Oversight
Clarify responsibilities, access, security expectations and coverage across MSPs, software vendors, security providers and other technology partners.
Sensitive information brings additional responsibilities.
Organizations handling health information, employee records, personally identifiable information, financial data or other sensitive information may have regulatory, contractual or industry requirements that affect how technology must be managed.
Marshall Technology can help evaluate whether technology practices support obligations involving HIPAA, PII, employee and financial information, contractual security requirements and other relevant sensitive-data concerns.
Our role is to help make sure technology practices support the obligations the business has.
Where legal interpretation, certification or specialized compliance expertise is required, we work alongside the appropriate professionals.
The answer should follow the risk, not the product.
Another security product may be exactly what the organization needs.
Or the better answer may be configuring technology you already own correctly, changing a process, clarifying a vendor’s responsibility, improving employee training or bringing in specialized expertise for a particular problem.
Marshall Technology is not tied to a particular security platform.
And when the situation calls for specialized penetration testing, digital forensics, incident response, 24/7 security monitoring or another dedicated cybersecurity capability, we can help bring the right resource into the broader plan and coordinate the work.
The recommendation starts with the problem that needs to be addressed.
What does leadership get back?
Executive Risk View
A clear picture of the cybersecurity issues that matter to the business and enough context to understand why they matter.
Responsibility & Accountability
A clearer understanding of who is responsible across internal teams, MSPs, security providers, vendors and leadership.
Prioritized Recommendations
Practical recommendations based on risk, business impact and urgency rather than an undifferentiated list of security findings.
Remediation Roadmap
A path from the current environment to the agreed improvements, including the people and providers needed to get there.
Ultimately, leadership should be able to answer a much more useful question:
What do we need to do next?
Experience from both sides of the problem.
Marshall Technology’s cybersecurity perspective comes from both hands-on technical work and broader technology leadership.
Early in my career, cybersecurity sometimes meant dealing directly with malware outbreaks, suspicious files and the technical problems created by them. That included working directly with antivirus vendors during active malware events, investigating suspicious files and finding practical solutions when the standard security tools weren’t enough.
As my responsibilities grew, the cybersecurity questions grew with them: identity and access, Microsoft 365 security, infrastructure, backups and recovery, security awareness, vendors, MSP and security-provider oversight, regulated information, governance, cyber insurance and explaining technology risk to executive leadership.
That combination shapes how Marshall Technology approaches cybersecurity today.
I understand the technical side. I also understand the business that has to live with the decision.
A few sources we pay attention to
NIST Cybersecurity Framework 2.0
A widely used framework for understanding and managing cybersecurity risk.
Verizon Data Breach Investigations Report
Annual analysis of real-world security incidents and breaches.
Microsoft Digital Defense Report
Research and observations drawn from Microsoft’s view of global security activity.
CrowdStrike Global Threat Report
Research into current adversary activity, attack techniques and trends.
Cybersecurity risk doesn’t have to be a mystery.
Every organization carries some level of cybersecurity risk. No product, provider or security program eliminates all of it.
Leadership can understand where the meaningful risks are, make sure appropriate safeguards are in place, prepare for what could happen and make deliberate decisions about what deserves attention.
