JQZ extended an existing managed IT relationship into a stronger managed cyber security operating model
JQZ operates in a high-value, project-driven property and development environment, with technology supporting users, finance workflows, project documentation, external consultants, email-heavy communication and commercially sensitive information.
JQZ already relied on Inlight IT for managed services. The next requirement was a stronger security operating layer above the managed IT baseline — better visibility across endpoints and identity, clearer triage of security alerts, more structured response coordination and reporting that made the security posture easier to manage.
- Client
- JQZ
- Industry
- Property development and construction
- Environment
- Technology supporting users, finance workflows, project documentation, external consultants, email-heavy communication and commercially sensitive information
- Starting point
- A managed IT baseline already in place — support coverage, managed devices, Microsoft 365 administration and established IT processes
- Engagement type
- Managed Cyber Security — a security operating layer above the managed IT baseline
- Focus
- Endpoint visibility, identity monitoring, alert triage, response coordination and security reporting
- Outcome
- A more disciplined security operating layer extended from the existing managed IT relationship
JQZ — managed cyber security on a managed IT foundation
Security signals interpreted against the operating context the team already understood.
Five operational layers, one operating relationship
Endpoint, identity, alert handling, response and reporting connected as one operating model.
Security extended from the existing managed IT relationship, not run as a separate provider.
Suspicious sign-ins, mailbox activity and authentication events under closer review and escalation.
Detection, triage, escalation and response made part of how the environment is managed day to day.
A security tool generates alerts — an operating model decides which ones matter
JQZ had moved beyond the point where traditional managed IT support was enough on its own. The business already had support coverage, managed devices, Microsoft 365 administration and established IT processes.
The cyber risk profile required a more active security layer above the managed IT baseline.
Because Inlight IT was already managing JQZ's environment, security signals could be interpreted against real operating context — users, devices, business workflows, support history. The managed cyber security layer was built on top of that knowledge, not in parallel to it.
Security needed to operate inside the managed IT relationship, not as a separate provider
A standalone security provider can monitor alerts. Alert visibility is only one part of response. JQZ needed a managed cyber security model that could detect relevant signals, triage them in context, coordinate response and report on security activity in a way leadership could understand.
Endpoint alerts needed review, prioritisation and escalation
Endpoint protection alone was not enough. Security alerts needed to move from passive notifications into active operational handling, with severity assessment, context and clear escalation pathways.
Microsoft 365 and Entra ID activity needed closer monitoring
Identity is one of the most important control points in a modern business environment. Suspicious sign-ins, account behaviour, mailbox activity and authentication events needed practical interpretation, not just dashboard visibility.
Alerts needed to be assessed in context
An alert is more useful when the team reviewing it understands the user, device, role, business function and operating environment. Without context, important signals can be missed and routine signals can be over-escalated.
Response pathways needed to be clear before a security event occurred
Response is not a moment of decision-making during an incident. It is a set of pathways established in advance: containment options, escalation contacts, communication patterns and remediation actions ready before they are needed.
Leadership needed visibility into security posture, not just ticket history
Reporting on tickets and uptime does not describe security posture. JQZ needed a structured view of what was being monitored, what alerts had been reviewed, what was escalated and where the environment should continue to improve.
Five operational layers connecting endpoint, identity, alert handling, response and reporting
Inlight IT extended JQZ's managed services environment with a managed cyber security operating model. The work focused on practical security coverage across endpoints, Microsoft 365, identity, alert handling, response escalation and reporting. The aim was to make the existing environment more defensible and easier to operate securely.
01Endpoint detection and response visibility
Endpoint security treated as an active operational control, not a passive software layer. Visibility strengthened across managed endpoints, with security alerts moved through an operational process rather than left as isolated tool notifications.
02Microsoft 365 and identity monitoring
Identity treated as a primary control point, not a secondary layer. Suspicious sign-ins, unusual access activity, authentication posture, mailbox behaviour, privileged access and user-level security events received closer review and escalation.
03Alert triage and contextual assessment
Alerts assessed for severity, context and required action. Triage considered the affected user or device, the type of alert, whether the activity matched normal behaviour, whether endpoint, Microsoft 365 or identity signals were connected, and whether immediate containment or escalation was required.
04Response coordination and remediation
Clearer response pathways established for security events that required action: escalation handling, containment coordination, remediation steps and communication with relevant client stakeholders — all aligned with business context because Inlight IT already managed the IT environment.
05Security reporting and operating-model integration
Reporting designed to make the security operating model clearer, not paperwork for its own sake: alert review and escalation summary, posture visibility, and material to support insurance, governance and procurement conversations — connected back to users, devices, access controls and Microsoft 365 configuration.
Detection, triage, escalation and response made part of how the environment is managed day to day
Select a stage to trace how security operations were built into the managed IT relationship.
Alert visibility is only one part of response
A standalone security provider can monitor alerts. An alert is more useful when the team reviewing it understands the user, device, role, business function and operating environment — without context, important signals can be missed and routine signals can be over-escalated. JQZ needed a model that could detect relevant signals, triage them in context, coordinate response and report on security activity in a way leadership could understand.
Five operational layers — endpoint, identity, alert handling, response and reporting — connected as one operating model.
One operating relationship: security signals interpreted against the same user, device and business context the team already understood.
Security connected to the way the environment is managed day to day rather than running as a separate service tier.
Five stages, from coverage assessment to a reporting cadence embedded in how the environment is managed.
JQZ gained a more mature security operating model inside its existing managed services relationship
The uplift improved visibility across endpoints, Microsoft 365 and identity activity. It gave security alerts a clearer triage process. It strengthened response coordination. It gave leadership a better view of security posture and improvement areas.
Stronger endpoint visibility
Security activity across managed devices reviewed and escalated through a structured process rather than left as isolated tool notifications.
Improved Microsoft 365 and identity oversight
Identity and Microsoft 365 activity received closer attention as part of the managed security operating model, not as separate workstreams.
Contextual alert triage
Alerts assessed for severity, context and required action rather than treated as isolated notifications without prioritisation.
More disciplined response coordination
Security events had clearer pathways for escalation, containment, remediation and communication, rather than being improvised as situations developed.
Better reporting for governance and insurance
JQZ gained a more structured view of security activity, control posture and improvement areas to support management, insurer and governance conversations.
A stronger cyber-first managed services model
Security became more integrated with the way the environment was managed day to day, rather than running as a separate service tier.
The value was not more alerts. It was security integrated with the way the environment was managed day to day, rather than running as a separate service tier.
What managed services context gave the engagement
Alerts reviewed in context
Security alerts reviewed against real user, device, role and operating context.
Triage before escalation
Triage applied severity, context and cross-signal correlation before escalation.
Identity as a primary layer
Identity treated as a primary security layer, not a secondary check.
Pathways pre-established
Response pathways pre-established, not improvised during incidents.
Findings actioned
Findings actioned through the live environment rather than parked in reports.
Cadence for governance
Operating cadence supported leadership, governance and insurer conversations.
The work connected endpoint, identity, response and security reporting
Endpoint security
6- Endpoint protection
- Detection and response visibility
- Alert review
- Device isolation
- Remediation pathways
- Managed endpoints
Microsoft 365 & identity
6- Microsoft 365 security
- Entra ID monitoring
- Identity and MFA
- Suspicious sign-in review
- Suspicious mailbox rule detection
- Privileged access review
Triage & response
7- Alert triage
- Severity assessment
- Cross-signal correlation
- Escalation handling
- Containment coordination
- Credential and account response
- Session and rule removal
Reporting & governance
6- Security reporting
- Posture visibility
- Alert and escalation summaries
- Insurance and governance support
- Improvement tracking
- Managed IT integration
Need stronger security operations around your managed IT environment?
Managed cyber security matched to your environment across identity, endpoints and response.
Explore Managed Cyber Security