Security Architecture Guide

What a well-architected security environment actually looks like — identity, network segmentation, data protection, endpoints, email, and monitoring — and the documentation that keeps it consistent as an organization grows.

Last updated: August 2026 · A practical reference you can read end to end.

Why security architecture matters

Security tools get deployed one at a time. Different admins make changes, people change roles, documentation goes stale — and what you end up with is not what anyone designed.

Access nobody can account for

Administrative accounts and shared logins that outlived their reason, with no record of who approved them.

Rules nobody understands

Firewall entries and exceptions kept because removing them feels risky, not because anyone knows what they do.

Gaps you cannot see

Uneven MFA, thin monitoring and missing documentation — so problems are found by incident rather than by review.

The six domains a review covers

Each one is a place where decisions were either made deliberately or made by default.

Identity & Administrative Access

Review privileged accounts, administrator roles, multi-factor authentication, conditional access, emergency access accounts, and administrative workstations.

Network Security

Review firewall policies, remote access, VPN, network segmentation, VLAN design, wireless security, and Internet connectivity.

Data Protection

Identify business-critical data, ownership, storage locations, external sharing, retention, backup, and recovery capabilities.

Endpoint Security

Review device compliance, operating system health, endpoint protection, encryption, patch management, and device lifecycle.

Email Security

Review phishing protection, spam filtering, attachment scanning, domain protection, and secure email configuration.

Monitoring & Logging

Review alerting, audit logs, security monitoring, log retention, incident response processes, and operational visibility.

Segmentation, in practice

Segmentation is the difference between one compromised device and a compromised business. A workable split for most organisations:

Server & Infrastructure

Critical servers, virtualization hosts, storage, backup infrastructure, and management systems.

IoT & Building Systems

Printers, cameras, conference rooms, HVAC, badge systems, and other operational devices.

User Network

Employee workstations and laptops.

Guest Network

Completely isolated Internet-only access for visitors and unmanaged devices.

What should be written down

01 Administrative roles, privileged accounts, and who owns each one.
02 Network topology — sites, VLANs, firewalls, wireless, and how they connect.
03 Firewall policy: inbound and outbound rules, NAT, VPN, and every exception.
04 Microsoft 365 tenant configuration, including access policies and their exclusions.
05 Backup scope, retention, recovery objectives, and when recovery was last tested.
06 Disaster recovery priorities, procedures, and who is called in what order.
07 Asset inventory: servers, endpoints, network gear, licences, and lifecycle dates.
08 Change history — what changed, who approved it, and how to roll it back.

The point of documentation is not the document. It is that troubleshooting does not depend on one person being reachable, and an audit does not become a research project.

When this guide applies

01 A new office or site is being built and the environment is still a blank page.
02 Growth has added users, locations or services faster than the design kept up.
03 Ageing systems are being replaced and the architecture is open for change anyway.
04 Identity, network or data protection needs strengthening after a near miss.
05 An audit or governance requirement needs documentation that does not exist yet.
06 Due diligence before a project or acquisition needs an honest picture of what is there.

Want a second opinion on your environment?

This guide covers the whole picture. Where we work day to day is Microsoft 365 identity and configuration, network segmentation on Cisco Meraki, and backup and recovery. If you would like an honest read on any of those, we will take a look — no obligation.