Too many organisations treat NIS 2 as a policy exercise for the security team. Aaron Smith, Lead InfoSec Consultant at Smarttech247, on why the real shift is leadership accountability, and the three questions every board needs to be able to answer.


In many Microsoft environments, the deployment stage is not where things start to slow down. By the time we speak with most organisations, Sentinel is live, Defender is deployed, and the identity schema is already established. From a tooling perspective, the environment is well covered.
The pressure appears later.
When our analysts begin working inside a new customer environment, the friction almost always shows up at investigation. Signals from identity, email, cloud, SIEM, and endpoint each exist, but investigating across all of them is not a joined-up experience. Each source has its own portal, its own context, its own workflow. Pulling a complete picture of an incident requires moving between them manually.
That is where the operating model needs work. Without proper structure around telemetry inputs, detection engineering, investigation, and escalation, analysts get buried in volume rather than focused on the issues that actually matter. The tools are capable. The operational layer connecting them is not there yet.
The environments that perform best are those where the Microsoft toolset has been shaped into a practical operating model that reflects the customer's risk profile. That means detections are not generic out-of-the-box rules but tuned to what risk looks like for that specific organisation. It means investigation follows a consistent workflow regardless of which signal source triggered it. And it means escalation and response paths are defined in advance, not improvised under pressure.
Getting there does not require new tools. It requires taking what is already deployed and building the structure around it that turns capability into performance.
Tooling investment is high. Operational return on that investment is lower than it should be. The gap is not a Microsoft problem. It is a design problem, and it is solvable.
That is the work we do with organisations through VisionX MDR for Microsoft: taking an environment that is well covered from a tooling perspective and building the operating model that makes it perform. Detection engineering tuned to your risk profile. Investigation across identity, email, cloud, SIEM, and endpoint in a single workflow. Escalation and response paths that reflect how your organisation operates, not a generic template.
The environment you have is capable of more than it is currently delivering.
We protect your on-premise/cloud/OT environments - 24x7x365