1ST2 brings your live security posture into one command centre, hardens it with a deliberately chosen security stack, and runs on infrastructure held to the same standard we help you reach. Here's all of it, in one place.
Your Microsoft Secure Score, device compliance, and security posture already exist inside your Microsoft 365 - most businesses simply don't actively monitor them or have the admin access to check in day to day. 1ST2 surfaces that intelligence directly, tracks its progress over time, and documents it for board and leadership reporting: one live command centre that shows exactly where you stand and what to harden next.
Together with 1ST2, the capabilities below help greatly toward Essential Eight alignment - closing key gaps in endpoint protection, application control, identity security, awareness training, backup, and patching that no platform alone can cover. Each is presented individually during onboarding. Accept what fits. Decline with a recorded risk acknowledgement. Each is priced separately, in addition to your platform subscription. Every signal from the stack feeds straight back into your dashboard, so you and your IT Champion see what needs attention the moment it does.
A lightweight agent on every enrolled device, monitored around the clock by a human Security Operations Centre. Ransomware, malware, and lateral movement - detected before damage occurs. Every alert is reviewed by a human analyst.
Continuous monitoring of every Microsoft 365 identity for account takeover, business email compromise, suspicious sign-in patterns, and OAuth abuse. Identity-based attacks account for nearly 30% of cyber incidents against SMBs.
Prevention-first endpoint security posture management - it governs which applications are allowed to run, blocks unauthorised and untrusted tools, and continuously validates that the security controls you think are active actually are. It flags end-of-life and vulnerable software, unauthorised remote access tools, and configuration drift before an attacker finds it first.
Automated phishing simulations and engaging monthly security training for every staff member. Built by Emmy-winning animators using real threat intelligence. Your people are your most exploited attack vector.
Delivered through our backup partner, daily automated backups cover Exchange, OneDrive, SharePoint, and Teams data, stored independently in Australia. Under Microsoft's own shared responsibility model, you own and are responsible for your data - native retention tools like the recycle bin are time-limited and designed for short-term recovery, not full protection against accidental deletion or ransomware. This gives you an independent, longer-term safety net, managed for you inside the 1ST2 platform. Point-in-time recovery means you can restore a single file or an entire mailbox.
Automated patching of Windows OS and hundreds of third-party applications - Chrome, Adobe, Zoom, and more - across every enrolled device. Unpatched third-party applications are among the most consistently exploited attack vectors.
Each capability is presented individually during onboarding - accept what fits, decline with a recorded risk acknowledgement.
Each product here closes a specific gap the Essential Eight calls out - endpoint protection, application control, patching, backups, identity and human risk. Add what fits during onboarding; decline with a recorded risk acknowledgement. Your vCISO & Compliance workspace then tracks and evidences each one.
Each month, 1ST2 surfaces the highest-impact Secure Score actions for your environment. Your IT Champion reviews and approves. The score rises. Nothing happens without a tap - and everything is recorded.
Single-click OAuth consent, then an automated tenant assessment runs immediately - no manual Azure steps, no consultant engagement. Here is exactly what it checks, every time:
Issues resolved, AutoFix actions taken, new advisories, and anything awaiting approval - in one short email.
Tickets auto-resolved, hours saved, and Secure Score movement - quantified and shareable with leadership.
Immutable, timestamped record of every automated and approved action - for you, your auditor, or your insurer.
1ST2 runs on enterprise-grade infrastructure with data centres in Sydney, Australia. Your business data does not leave Australian shores.
For day-to-day monitoring and reporting, the platform reads only the Microsoft 365 configuration metadata, device information, and ticket content needed to deliver the service. It does not store or access your emails, files, or personal communications. Where the platform takes an administrative action on your behalf - like a device wipe during offboarding - that action is limited to exactly what you've approved, logged in full, and never extends to reading your mailbox or files.
All data is encrypted in transit (TLS 1.3) and at rest. No exceptions, on any surface of the platform.
Authentication is Microsoft SSO only. No email/password login. No password database to breach.
The platform is scoped to do its job and nothing more. It never reads or stores:
Administrative actions - like offboarding steps or a device wipe - are limited to what you explicitly approve, and are never used to access the content of your emails or files in the process.
1ST2 undergoes annual independent penetration testing. Any findings are remediated immediately - not scheduled for a future release cycle. We hold ourselves to the same security standard we help our clients achieve.
All 1ST2 team members are police checked. The business holds professional indemnity insurance and cyber liability coverage.
Get in touch and we'll walk you through the platform.