Microsoft is retiring SMS and voice MFA. Passkeys become the default on 1 September 2026; SMS and voice switch off on 1 February 2027. Book your free health check
IT Next Door
← Back
Zero Trust

Zero Trust, without rebuilding your office.

Most Singapore businesses already own the tools for this. It is in the Microsoft 365 license you pay for every month. What is usually missing is the configuration, the enforcement, and someone watching afterwards.

What it actually means

The old assumption no longer holds

Office IT was built on a simple idea: inside the office is safe, outside is not. Then the files moved to SharePoint, the phone system moved to Teams, and half the team started working from home and from personal laptops. There is no inside any more.

Zero Trust replaces that assumption with a check. Every sign-in proves who the user is. Every device proves it is patched and encrypted before it reaches company data. Every account gets only the access its job needs.

It is not a product you buy. It is a set of decisions, applied consistently, and kept applied as people join and leave.

See it first

What a posture review gives you

A scorecard against the Microsoft baseline: each of the six controls scored, then everything we found ranked by what an attacker would reach for first. Below is a worked example for a fictitious 62-user freight company — illustrative figures, real format.

63% Sample scorecard
Zero Trust posture scorecard

Six controls scored red, amber or green, then eight ranked findings with what we saw and what fixing each involves. Read-only assessment — nothing is changed.

Open sample →

Opens in a new tab and prints to PDF. No form, no email address required.

What we configure

Six controls, in this order

Identity

Multi-factor authentication on every account, no exceptions for directors. Conditional Access rules that block sign-ins from countries you do not operate in, and legacy protocols that skip MFA entirely.

Devices

Company laptops enrolled in Intune with a hardening baseline, disk encryption and enforced patching. Unmanaged personal devices get browser-only access, not full sync.

Access

Admin rights removed from daily accounts. Shared folder permissions rebuilt around roles. External sharing links given expiry dates instead of living forever.

Email

Anti-phishing and impersonation protection tuned to your domain, plus SPF, DKIM and DMARC set correctly so nobody can send invoices as you.

Data

Independent backup of Exchange, SharePoint, OneDrive and Teams. Microsoft replicates your data; it does not keep a copy you can restore from after a deletion or ransomware event. Read more →

Monitoring

Sign-in and endpoint alerts routed to our managed SOC, watched around the clock by people who can disable an account at 3am rather than email you about it. Managed SOC →

How it runs

Four steps, staged so nobody loses a working day

Assess We read your tenant as it is today and score it against the Microsoft baseline. You get the findings in plain language, ranked by what an attacker would use first.
Agree We walk through the list with you and decide what gets enforced, what gets an exception, and in what order. Nothing is switched on without your sign-off.
Enforce Rules go live in report-only mode first, then in enforcement, department by department. Your staff get a short note explaining what will change on their phone before it changes.
Watch Configuration drifts as people join, leave and buy new laptops. We re-check the baseline on a schedule and report what moved.

Questions we get

Do we need to buy new licenses?

Often not. Most of what matters is included in Microsoft 365 Business Premium. If you are on Business Standard we will tell you exactly which controls you are missing and what the upgrade costs before you decide. Since July 2026 the gap between Standard and Premium is USD8 per user per month, and it buys Conditional Access, Intune, EDR and mail security. Read the plan comparison →

Will MFA slow everyone down?

On a registered device, most staff approve one prompt every few weeks. The friction lands on sign-ins from unfamiliar devices and locations, which is the point.

We are too small to be a target.

Nobody picked you. Credential stuffing and phishing kits run against whole domain lists at once, and a 30-person firm with weak MFA is a cheaper result than a bank. The Cyber Security Agency of Singapore recorded 165 ransomware cases in 2025, up from 159 the year before, and noted that SMEs continue to be disproportionately affected because of lower cybersecurity maturity and limited resources. Its 2024/2025 Singapore Cyber Landscape report singled out professional services firms — consulting, legal and accounting — as particularly targeted.

Start with the assessment, not the invoice.

We look at your tenant, tell you where it stands, and scope the work from what we find. Managing IT for Singapore businesses since 2015, from helpdesk to security operations, with one team behind all of it.