A financial-services client wanted to replace a costly, fragmented estate of legacy on-premise security products with one modern platform they were already licensed for. Multiple consoles, overlapping tools and coverage gaps were slowing the team down and inflating spend.
We delivered the migration to a consolidated Microsoft Defender stack, treating it as a chance to start clean: auditing and rationalising legacy policy so only the relevant configuration moved across, and hardening the new estate with Attack Surface Reduction and antivirus controls. We also built custom detection rules in KQL, so the SOC was alerted to suspicious activity the old tooling would have missed. Delivered in structured sprints, the cutover landed with no disruption to the business.
Key Achievements
- Planned and led a dedicated delivery squad using agile methodology, running structured sprints and stand-ups to ensure on-time delivery
- Reviewed and rationalised legacy policies before recreation, ensuring only relevant configurations were migrated to the new Microsoft tooling
- Designed and implemented supporting controls across Attack Surface Reduction (ASR), antivirus, and application control
- Developed custom KQL detections to enhance visibility and strengthen threat detection coverage
- Oversaw both strategic delivery and hands-on engineering activities to ensure a seamless transition with no disruption to business operations
Ready to strengthen your defences?
Whether it's SOC maturity, detection and response, or a security project that needs hands-on delivery - let's discuss how SecurityBakedIn can help.