Skip to content
Atlas
GET IN TOUCH

C://SECURE32Identity Security

Identity is the
new perimeter.

Identity security governs who can sign in, from where, on what device, and with what privileges. It is the control set that decides the outcome of most modern attacks. It is for organisations still treating the network as the boundary while their data sits in the cloud.

Most breaches now begin with a valid login rather than a broken firewall, and a stolen password does not set off any alarms.

The cost of leaving this alone is rarely one visible failure. It is the slow accumulation: the workaround that became the process, the thing only one person knows, the renewal nobody questioned.

Our starting point is always the same: establish what is actually true today, then decide what to change. Work scoped against an assumption tends to solve a problem you do not have.

  • 01Nobody owns itIt sits with whoever touched it last, which is not the same as being managed.
  • 02No current pictureWhat you have, what it costs, and who has access are all slightly out of date.
  • 03Only handled when it breaksAttention arrives after the disruption rather than before it.

What the engagement covers

Scoped before it starts, so you know what is included and what is not.

  • 01

    Multi-factor everywhere

    Enforced across every account, including the service accounts and administrator accounts that usually get an exemption and are exactly the ones worth attacking.

  • 02

    Conditional access

    Sign-ins evaluated on device, location, and risk, so an unusual attempt is challenged and a normal one is not. Good conditional access is invisible to honest users.

  • 03

    Privileged access

    Administrative rights granted when needed and removed afterwards, rather than held permanently by four people who once needed them.

  • 04

    Lifecycle automation

    Access granted on hire and removed on exit by process rather than by someone remembering on their last afternoon.

Baseline, remediate, monitor, evidence

Four stages with a written output at each one. You always know which stage you are in and what comes next.

  1. 01Week 1

    Baseline

    What is configured today, measured against a recognised standard, with gaps ranked by real-world risk rather than vendor score.

  2. 02Weeks 2 – 6

    Remediate

    Gaps closed in the order that buys the most safety fastest, with each change recorded.

  3. 03Ongoing

    Monitor

    Tuned to your environment so alerts mean something, and every alert has a named owner.

  4. 04Quarterly

    Evidence

    A written report you can hand to an insurer, a customer, or your board without translating it first.

What you should expect

  • Someone other than you owns it, with that written down.
  • The current state is documented and stays documented.
  • Cost is planned ahead rather than discovered at renewal.
  • Decisions are made against evidence rather than assumption.

Questions we get asked

01What is identity security?

Identity security governs who can sign in, from where, on what device, and with what privileges. It is the control set that decides the outcome of most modern attacks. It is for organisations still treating the network as the boundary while their data sits in the cloud.

02What is multi-factor authentication and why does everyone insist on it?

It means signing in needs something you know, your password, plus something you have, usually your phone. It matters because passwords leak constantly, from breaches at other services and from convincing fake login pages, and multi-factor turns a leaked password from a crisis into a nuisance. It is the single highest-value security control available to a small business, and for most organisations it is already included in what you pay Microsoft or Google.

03Can attackers get past multi-factor authentication?

Some forms, yes. Codes by text message can be intercepted, and there are phishing kits that sit in the middle and capture a code in real time. It is still enormously better than nothing. Where it matters most, use an authenticator app with number matching or a hardware key rather than text messages, and pair it with conditional access so an unexpected sign-in gets challenged even with a valid code.

04Our staff find multi-factor authentication annoying. Is there a way around that?

Yes, and the annoyance is usually a sign it has been configured bluntly. Prompting on every sign-in from a known device in the office is unnecessary friction. Configured properly, people are prompted when the risk signals warrant it and left alone otherwise, which is both more secure and considerably less irritating than a fixed daily prompt.

05What actually happens when a former employee keeps their access?

Usually nothing, right up until it matters. The realistic risks are a departing salesperson taking the customer list, an account nobody is watching being used as a quiet way back in, and a licence you keep paying for. The fix is not vigilance, it is process: access removal tied to the payroll exit so it happens whether or not anyone remembers.

06Is single sign-on worth it for a small business?

Usually yes, and not mainly for convenience. One identity across your applications means one place to enforce multi-factor, one place to see who has access to what, and one action to remove someone completely. Without it, offboarding is a list of systems somebody has to work through by hand, and that list is never complete.

07How much does identity security cost in New Zealand?

We quote after scoping rather than before. Anyone pricing this work without looking at your environment is guessing, and the guess is rarely in your favour. Scoping itself is quick, and we tell you what it costs before we start it.

08How long does it take to get started with identity security?

A first conversation takes about half an hour and costs nothing. Scoping is usually a week or two of our time depending on the size of the environment, and we agree the delivery dates with you before anything is booked in.

09Can you deliver identity security alongside our existing IT team or provider?

Yes, and it is common. We are happy to work as an extra pair of hands under your internal team, or alongside an incumbent provider on a defined piece of work. We will set out in writing where the responsibilities split, so nothing falls between us.

10Do we have to move our whole IT contract to Atlas?

No. This can be delivered as a standalone piece of work for an organisation we have never worked with before, or folded into a managed agreement if you already have one with us. Plenty of clients use us for one thing and keep everything else where it is.

11Can you support us if we are not based in Auckland?

Our team is based in Auckland and we attend sites across the wider region. Most of this work is delivered remotely, so we support organisations throughout New Zealand, and we will say up front where being on site genuinely matters.

12Who will we be dealing with when something actually happens?

Named people, not a queue. You get a lead who knows your environment and stays with it, which is the difference between explaining your business once and explaining it every time you make contact.

13What happens after it is in place?

You keep the documentation regardless, and anything registered in your name stays in your name. Whether we stay involved is your call. Some clients take it in house from there, others move it onto an ongoing agreement with us. We would rather you left cleanly than stayed because leaving was difficult.

Start with a conversation.

Tell us what you are dealing with and we will tell you whether this is the right service for it, and what it would take.

← All services