A Data Governance Approach to Microsoft Purview
Why Microsoft Purview with Bridewell?
- Implementing Microsoft Purview for Effective Data Governance and Compliance: Our approach to implementing and deploying Microsoft Purview is driven by data governance, with a focus on ensuring your organization is compliant with relevant data privacy regulations. Our Microsoft, Cloud, and Data Privacy experts will work alongside you to understand regulatory risks within your environments and remediate them through Purview’s data, compliance, and governance capabilities.
- Expertise in Cloud Security and Threat Protection with Microsoft Purview: As one of Microsoft’s leading cybersecurity partners, our team are designated solution partners for Security. We hold specialisms in Cloud Security and Threat Protection and have extensive experience in deploying Purview for some of the UK’s largest and most highly regulated organizations.
The Benefits of Purview
Our team will help you deploy Microsoft Purview quickly and effectively, so you enjoy the following benefits.
Identify Risks to Your Data
Assess your current data privacy programme for any ongoing risks.
Identify Risky User Behaviour
Identify any user behaviour that risks non-compliance or a data breach.
Achieve Best Practice for Data Protection
Meet relevant requirements for regulatory compliance and industry best practice.
Ease the Pressure on Your Security Team
Our SOC team will take on responsibilities from your in-house security team, allowing them to dedicate time and resources to other activities.
In 2022, a leading cryptocurrency company were looking for a cyber security partner who could provide them with 24x7 detection and response capabilities and an assessment of the security of their infrastructure through a threat-led testing engagement.
The Challenge
As a security first business, our client is fully aware of the importance of 24/7 security operations and incident response capabilities. Building on their already strong in-house Security Operations teams and security credentials – including ISO 27001, SOC 2 and Cyber Essentials Plus certification – they were looking for a managed security services (MSS) partner who could help them drive further improvements in their security operations.
Specifically, they were looking for an MSS partner who could help them achieve 24x7 Managed Detection and Response (MDR) across their entire enterprise and SaaS ecosystem, expand the scope of their security coverage, and help them increase the value of their in-house security team by owning more tactical elements of the Security Operations processes.
Our client recognised that finding, recruiting, and/ or training new staff to deliver these capabilities in-house would be a lengthy and time-consuming process. With this in mind, they determined that working with an external partner could help them achieve these outcomes at pace. Working with a partner would also allow them to assess the effectiveness of their current capabilities through regular penetration testing.
The Solution
To select the right partner, our client sought proposals from several MSS providers. They subsequently reviewed the proposals against their selection criteria and chose the most suitable: Bridewell.
Our client felt that Bridewell was the best fit, due to their agile methodology and experience within the financial services sector. Instead of providing a standardised service, Bridewell tailored the solution around their individual requirements and pain points. Bridewell also leveraged their experience within the financial services sector and with SaaS providers to deliver a customised service that incorporated insights and expertise from their security analysts, who have years of experience securing organisations with similar challenges.
Our client already had a cloud based SIEM in place, however Bridewell was able to rapidly integrate this into their security operational processes and DevOps pipelines for content development, management and distribution.
Following this, Bridewell’s Offensive Testing team also performed an Assumed Breach Test. In comparison to more traditional penetration testing, this assessed Cryptocurrency Company’s capabilities to defend against a cyber attack once their users or devices are already compromised, using threat intelligence to mimic the behaviours of a real-world threat. This provided them with true insight into the potential impacts of an attacker bypassing their external perimeter and their defence and response capabilities.
Throughout the engagement, Bridewell’s SOC and Offensive Testing teams worked closely with our client to ensure that the was minimal impact to their daily operations and that all projects were delivered promptly.
The Results
As part of Bridewell’s SOC, our client now has 24x7 visibility across their entire estate: including enterprise and customer SaaS environments. They are now benefitting from a range of security technologies and higher-fidelity alerts that reduce the number of low-level tickets that require attention.
Partnering with Bridewell has also enabled them to take a more proactive approach to cyber security, allowing them to make better use of threat intelligence and industry information. Our client has leveraged Bridewell to develop threat hunting for indicators of compromise and behaviours within their environment, and these are used to close any potential vulnerabilities that are commonly attributed to relevant malicious actors.
Start your Microsoft Purview Journey with Bridewell
Speak with one of our consultants to see how we can support your organization with Microsoft Purview.
How it Works
Data governance isn’t just about technology, but how organizations use, process and secure data. Our Purview deployments prioritize understanding how your employees handle data so we can implement policies that support their ways of working.
Data Discovery
Our cloud security and data privacy teams will hold discovery workshops to understand:
- Your current approach to data classification, retention and data loss
- Any challenges with how your users access and share data
- Your goals with Purview
Our team will review your current approach against applicable data protection legislation and best practice standards.
Any areas of non-compliance or data risk will be highlighted immediately.
Design and Implementation
Based on our findings, we will recommend updates to relevant policies and provide a test deployment of our proposed labelling solution to address these shortcomings.
This test deployment ensures there is no risk to your current operations and allows our team to optimize your Purview deployment before it is moved to a live environment.
Why Us?
180+ Security Specialists
Our team have diverse experience across sectors and disciplines, and hold accreditations from numerous industry bodies.
Certifications
Our people and services are highly accredited by leading industry bodies including CREST, the NCSC, and more. Our SOC holds extensive accreditations from CREST (including for CSIR and SOC2) and works closely with our cyber consultancy services.
Partnerships
As a Microsoft Partner, we also hold advanced specialisms in Cloud Security and Threat Protection. We’ve also implemented some of the UK’s largest deployments of the Microsoft Security stack, inc. Sentinel, Defender, Purview and more.