Why security architecture matters
Security tools get deployed one at a time. Different admins make changes, people change roles, documentation goes stale — and what you end up with is not what anyone designed.
Access nobody can account for
Administrative accounts and shared logins that outlived their reason, with no record of who approved them.
Rules nobody understands
Firewall entries and exceptions kept because removing them feels risky, not because anyone knows what they do.
Gaps you cannot see
Uneven MFA, thin monitoring and missing documentation — so problems are found by incident rather than by review.
The six domains a review covers
Each one is a place where decisions were either made deliberately or made by default.
Identity & Administrative Access
Review privileged accounts, administrator roles, multi-factor authentication, conditional access, emergency access accounts, and administrative workstations.
Network Security
Review firewall policies, remote access, VPN, network segmentation, VLAN design, wireless security, and Internet connectivity.
Data Protection
Identify business-critical data, ownership, storage locations, external sharing, retention, backup, and recovery capabilities.
Endpoint Security
Review device compliance, operating system health, endpoint protection, encryption, patch management, and device lifecycle.
Email Security
Review phishing protection, spam filtering, attachment scanning, domain protection, and secure email configuration.
Monitoring & Logging
Review alerting, audit logs, security monitoring, log retention, incident response processes, and operational visibility.
Segmentation, in practice
Segmentation is the difference between one compromised device and a compromised business. A workable split for most organisations:
Server & Infrastructure
Critical servers, virtualization hosts, storage, backup infrastructure, and management systems.
IoT & Building Systems
Printers, cameras, conference rooms, HVAC, badge systems, and other operational devices.
User Network
Employee workstations and laptops.
Guest Network
Completely isolated Internet-only access for visitors and unmanaged devices.
What should be written down
The point of documentation is not the document. It is that troubleshooting does not depend on one person being reachable, and an audit does not become a research project.
When this guide applies
Want a second opinion on your environment?
This guide covers the whole picture. Where we work day to day is Microsoft 365 identity and configuration, network segmentation on Cisco Meraki, and backup and recovery. If you would like an honest read on any of those, we will take a look — no obligation.