Security

    Your security - seen, hardened, and trusted.

    1ST2 brings your live security posture into one command centre, hardens it with a deliberately chosen security stack, and runs on infrastructure held to the same standard we help you reach. Here's all of it, in one place.

    Security command centre

    Tracked, documented, and reported - not just administratively accessible.

    Your Microsoft Secure Score, device compliance, and security posture already exist inside your Microsoft 365 - most businesses simply don't actively monitor them or have the admin access to check in day to day. 1ST2 surfaces that intelligence directly, tracks its progress over time, and documents it for board and leadership reporting: one live command centre that shows exactly where you stand and what to harden next.

    • Live Microsoft Secure Score, always current
    • Essential Eight progress at a glance
    • Device compliance and posture in one view
    • Microsoft Message Centre advisories surfaced proactively
    • One-click hardening actions surfaced directly from your score - each explained in plain English before you approve it
    1st2 · Security Command CentreLive
    0/ 100
    Secure Score
    ▲ +12 this quarter · target 85
    OctNovDecJanFebMar
    Essential EightMaturity L1 · 72%
    App control
    0%
    Patch apps
    0%
    MFA
    0%
    Backups
    0%
    Board reporting log
    March 2026 security reportGenerated Apr 1Sent to leadership
    February 2026 security reportGenerated Mar 1Sent to leadership
    January 2026 security reportGenerated Feb 1Sent to leadership

    Chosen deliberately, not for margin.

    Together with 1ST2, the capabilities below help greatly toward Essential Eight alignment - closing key gaps in endpoint protection, application control, identity security, awareness training, backup, and patching that no platform alone can cover. Each is presented individually during onboarding. Accept what fits. Decline with a recorded risk acknowledgement. Each is priced separately, in addition to your platform subscription. Every signal from the stack feeds straight back into your dashboard, so you and your IT Champion see what needs attention the moment it does.

    ~30%
    of cyber incidents against small businesses start with identity compromise - account takeover, business email compromise, or OAuth abuse. It's the reason Identity Threat Detection sits in the stack, not just endpoint protection.
    Endpoint Detection & Response

    24/7 human-monitored endpoint defence

    A lightweight agent on every enrolled device, monitored around the clock by a human Security Operations Centre. Ransomware, malware, and lateral movement - detected before damage occurs. Every alert is reviewed by a human analyst.

    • 24/7 Security Operations Centre, human-reviewed alerts
    • Threat intelligence from millions of protected endpoints
    • Detection before damage - not after the breach
    Covers · Endpoint protection
    Identity Threat Detection & Response

    Continuous Microsoft 365 identity monitoring

    Continuous monitoring of every Microsoft 365 identity for account takeover, business email compromise, suspicious sign-in patterns, and OAuth abuse. Identity-based attacks account for nearly 30% of cyber incidents against SMBs.

    • Detects account takeover & business email compromise
    • Flags suspicious sign-ins and OAuth app abuse
    • Closes the most common SMB attack vector
    Covers · Identity security
    Endpoint Security Posture Management

    Application control, built in

    Prevention-first endpoint security posture management - it governs which applications are allowed to run, blocks unauthorised and untrusted tools, and continuously validates that the security controls you think are active actually are. It flags end-of-life and vulnerable software, unauthorised remote access tools, and configuration drift before an attacker finds it first.

    • Application control - only approved applications run
    • Flags end-of-life software and unauthorised remote access tools
    • Validates your security controls are actually switched on, not just installed
    Essential Eight · Application controlAvailable late 2026
    Security Awareness Training

    Turn your people into a defence layer

    Automated phishing simulations and engaging monthly security training for every staff member. Built by Emmy-winning animators using real threat intelligence. Your people are your most exploited attack vector.

    • Automated phishing simulations
    • Engaging monthly training, Emmy-winning production
    • Content built from live threat intelligence
    Covers · Human risk
    Microsoft 365 SaaS Backup

    Independent backup for your Microsoft 365 data

    Delivered through our backup partner, daily automated backups cover Exchange, OneDrive, SharePoint, and Teams data, stored independently in Australia. Under Microsoft's own shared responsibility model, you own and are responsible for your data - native retention tools like the recycle bin are time-limited and designed for short-term recovery, not full protection against accidental deletion or ransomware. This gives you an independent, longer-term safety net, managed for you inside the 1ST2 platform. Point-in-time recovery means you can restore a single file or an entire mailbox.

    • Covers Exchange, OneDrive, SharePoint & Teams
    • Daily automated backups, point-in-time recovery, delivered via our backup partner AFI
    • Stored independently in Australia - protects against deletion & ransomware
    Essential Eight · Backups
    Autonomous Patch Management · third-party apps

    Close the most exploited gap

    Automated patching of Windows OS and hundreds of third-party applications - Chrome, Adobe, Zoom, and more - across every enrolled device. Unpatched third-party applications are among the most consistently exploited attack vectors.

    • Hundreds of third-party apps kept patched
    • Windows OS patching across every enrolled device
    • Full compliance reporting - no missed patches
    Essential Eight · Patch applications

    Each capability is presented individually during onboarding - accept what fits, decline with a recorded risk acknowledgement.

    Every capability maps to the Essential Eight.

    Each product here closes a specific gap the Essential Eight calls out - endpoint protection, application control, patching, backups, identity and human risk. Add what fits during onboarding; decline with a recorded risk acknowledgement. Your vCISO & Compliance workspace then tracks and evidences each one.

    See security & compliance together
    Continuous improvement loop

    Your Secure Score, going one direction: up.

    Each month, 1ST2 surfaces the highest-impact Secure Score actions for your environment. Your IT Champion reviews and approves. The score rises. Nothing happens without a tap - and everything is recorded.

    • Live Microsoft Secure Score monitoring
    • Monthly improvement actions, ranked by impact
    • Microsoft Message Centre advisories surfaced proactively
    • Target score of 85 - with a clear path to get there
    1
    Action surfaced
    "Block legacy authentication" - +6 Secure Score points, low user impact.
    2
    IT Champion reviews
    Plain-English explanation of what changes, who it affects, and the before/after state.
    3
    One-tap approve
    Applied directly to the device. 24-hour rollback available on every action.
    4
    Score rises, logged
    78 → 84. Recorded to the immutable audit trail with timestamp and actor.
    On connection

    A 13-point health check the moment you connect.

    Single-click OAuth consent, then an automated tenant assessment runs immediately - no manual Azure steps, no consultant engagement. Here is exactly what it checks, every time:

    01Multi-factor authentication enforced
    02Conditional Access policies
    03Endpoint threat protection
    04Device compliance monitoring
    05Admin role hygiene & least privilege
    06Legacy authentication blocked
    07Mailbox auditing enabled
    08External sharing controls
    09Self-service password reset
    10Security defaults & baseline
    11Inactive & guest account review
    12Anti-phishing & spoof protection
    13Audit log retention
    What the IT Champion receives

    A daily digest and a monthly report. Nothing silent.

    Daily digest

    What happened yesterday

    Issues resolved, AutoFix actions taken, new advisories, and anything awaiting approval - in one short email.

    Monthly report

    What 1ST2 saved you

    Tickets auto-resolved, hours saved, and Secure Score movement - quantified and shareable with leadership.

    Audit trail

    Every action logged

    Immutable, timestamped record of every automated and approved action - for you, your auditor, or your insurer.

    Infrastructure security

    How the platform itself is secured

    Australian data residency · Sydney

    1ST2 runs on enterprise-grade infrastructure with data centres in Sydney, Australia. Your business data does not leave Australian shores.

    Minimal data handling

    For day-to-day monitoring and reporting, the platform reads only the Microsoft 365 configuration metadata, device information, and ticket content needed to deliver the service. It does not store or access your emails, files, or personal communications. Where the platform takes an administrative action on your behalf - like a device wipe during offboarding - that action is limited to exactly what you've approved, logged in full, and never extends to reading your mailbox or files.

    Encrypted end to end

    All data is encrypted in transit (TLS 1.3) and at rest. No exceptions, on any surface of the platform.

    Microsoft SSO only

    Authentication is Microsoft SSO only. No email/password login. No password database to breach.

    Boundaries

    What 1ST2 does not access

    The platform is scoped to do its job and nothing more. It never reads or stores:

    • Your emails, calendar, or files
    • Your personal communications
    • Financial data or banking information
    • Customer records beyond IT support diagnosis

    Administrative actions - like offboarding steps or a device wipe - are limited to what you explicitly approve, and are never used to access the content of your emails or files in the process.

    Every capability is delivered by established security specialists

    Endpoint Detection & Response
    24/7 human-monitored Security Operations Centre, real-world threat intelligence from millions of protected endpoints globally.
    Identity Threat Detection & Response
    Continuous Microsoft 365 identity monitoring with automated threat response.
    Security Awareness Training
    Content built using live threat intelligence, Emmy-winning production quality.
    Microsoft 365 SaaS Backup
    Australian data storage, point-in-time recovery.
    Patch Management
    Automated patching with full compliance reporting.
    Endpoint Security Posture Management
    Prevention-first hardening controls, continuously enforced.

    Annual penetration testing

    1ST2 undergoes annual independent penetration testing. Any findings are remediated immediately - not scheduled for a future release cycle. We hold ourselves to the same security standard we help our clients achieve.

    Police-checked team, fully insured

    All 1ST2 team members are police checked. The business holds professional indemnity insurance and cyber liability coverage.

    Get in touch

    See the Security Command Centre for yourself.

    Get in touch and we'll walk you through the platform.