Why it matters
Most incidents we see did not need a sophisticated attacker. They needed one account without MFA, one server that had not been updated in a year, or one computer where the protection had been switched off because it was slow.
How we work
We do the basics fully and keep them that way. Every account that matters has MFA. Every computer and server has protection that reports to us, so we see when it stops. Updates are applied on a schedule and the exceptions are written down with a reason.
Firewall rules are a document, not a memory. When something changes, the document changes with it.