Home / Case Studies / JQZ Managed Cyber Security
Case Study · Property development and construction · Managed Cyber Security

JQZ extended an existing managed IT relationship into a stronger managed cyber security operating model

JQZ operates in a high-value, project-driven property and development environment, with technology supporting users, finance workflows, project documentation, external consultants, email-heavy communication and commercially sensitive information.

JQZ already relied on Inlight IT for managed services. The next requirement was a stronger security operating layer above the managed IT baseline — better visibility across endpoints and identity, clearer triage of security alerts, more structured response coordination and reporting that made the security posture easier to manage.

ENDPOINTSIDENTITYRESPONSE DETECTION / RESPONSE ENDPOINT SIGNALIDENTITY SIGNALRESPONSE JQZ / PROPERTY DEVELOPMENT & CONSTRUCTION / MANAGED SECURITY DETECT · TRIAGE · RESPOND
Engagement at a glance

JQZ — managed cyber security on a managed IT foundation

Security signals interpreted against the operating context the team already understood.

Client
JQZ
Industry
Property development and construction
Environment
Technology supporting users, finance workflows, project documentation, external consultants, email-heavy communication and commercially sensitive information
Starting point
A managed IT baseline already in place — support coverage, managed devices, Microsoft 365 administration and established IT processes
Engagement type
Managed Cyber Security — a security operating layer above the managed IT baseline
Focus
Endpoint visibility, identity monitoring, alert triage, response coordination and security reporting
Outcome
A more disciplined security operating layer extended from the existing managed IT relationship
Key project stats

Five operational layers, one operating relationship

5
operational layers

Endpoint, identity, alert handling, response and reporting connected as one operating model.

1
operating relationship

Security extended from the existing managed IT relationship, not run as a separate provider.

Entra ID
identity as a control point

Suspicious sign-ins, mailbox activity and authentication events under closer review and escalation.

Daily
security in operations

Detection, triage, escalation and response made part of how the environment is managed day to day.

Operating context

A security tool generates alerts — an operating model decides which ones matter

JQZ had moved beyond the point where traditional managed IT support was enough on its own. The business already had support coverage, managed devices, Microsoft 365 administration and established IT processes.

The cyber risk profile required a more active security layer above the managed IT baseline.

Because Inlight IT was already managing JQZ's environment, security signals could be interpreted against real operating context — users, devices, business workflows, support history. The managed cyber security layer was built on top of that knowledge, not in parallel to it.

Why this work mattered

Security needed to operate inside the managed IT relationship, not as a separate provider

A standalone security provider can monitor alerts. Alert visibility is only one part of response. JQZ needed a managed cyber security model that could detect relevant signals, triage them in context, coordinate response and report on security activity in a way leadership could understand.

01

Endpoint alerts needed review, prioritisation and escalation

Endpoint protection alone was not enough. Security alerts needed to move from passive notifications into active operational handling, with severity assessment, context and clear escalation pathways.

02

Microsoft 365 and Entra ID activity needed closer monitoring

Identity is one of the most important control points in a modern business environment. Suspicious sign-ins, account behaviour, mailbox activity and authentication events needed practical interpretation, not just dashboard visibility.

03

Alerts needed to be assessed in context

An alert is more useful when the team reviewing it understands the user, device, role, business function and operating environment. Without context, important signals can be missed and routine signals can be over-escalated.

04

Response pathways needed to be clear before a security event occurred

Response is not a moment of decision-making during an incident. It is a set of pathways established in advance: containment options, escalation contacts, communication patterns and remediation actions ready before they are needed.

05

Leadership needed visibility into security posture, not just ticket history

Reporting on tickets and uptime does not describe security posture. JQZ needed a structured view of what was being monitored, what alerts had been reviewed, what was escalated and where the environment should continue to improve.

What Inlight IT delivered

Five operational layers connecting endpoint, identity, alert handling, response and reporting

Inlight IT extended JQZ's managed services environment with a managed cyber security operating model. The work focused on practical security coverage across endpoints, Microsoft 365, identity, alert handling, response escalation and reporting. The aim was to make the existing environment more defensible and easier to operate securely.

01

Endpoint detection and response visibility

Endpoint security treated as an active operational control, not a passive software layer. Visibility strengthened across managed endpoints, with security alerts moved through an operational process rather than left as isolated tool notifications.

Included
Endpoint protection oversightAlert reviewIsolation pathwaysRemediation pathwaysManaged endpointsOperational cadence
02

Microsoft 365 and identity monitoring

Identity treated as a primary control point, not a secondary layer. Suspicious sign-ins, unusual access activity, authentication posture, mailbox behaviour, privileged access and user-level security events received closer review and escalation.

Included
Entra ID monitoringSuspicious sign-in reviewMailbox behaviourPrivileged accessAuthentication postureSuspicious mailbox rule detection
03

Alert triage and contextual assessment

Alerts assessed for severity, context and required action. Triage considered the affected user or device, the type of alert, whether the activity matched normal behaviour, whether endpoint, Microsoft 365 or identity signals were connected, and whether immediate containment or escalation was required.

Included
Severity assessmentContextual reviewCross-signal correlationNormal-behaviour comparisonContainment decisionsEscalation decisioning
04

Response coordination and remediation

Clearer response pathways established for security events that required action: escalation handling, containment coordination, remediation steps and communication with relevant client stakeholders — all aligned with business context because Inlight IT already managed the IT environment.

Included
Escalation handlingContainment coordinationCredential and account responseSession and rule removalDevice isolationStakeholder communication
05

Security reporting and operating-model integration

Reporting designed to make the security operating model clearer, not paperwork for its own sake: alert review and escalation summary, posture visibility, and material to support insurance, governance and procurement conversations — connected back to users, devices, access controls and Microsoft 365 configuration.

Included
Alert review summariesEscalation reportingPosture visibilityInsurance and governance supportProcurement conversationsManaged IT integration
Delivery approach

Detection, triage, escalation and response made part of how the environment is managed day to day

Select a stage to trace how security operations were built into the managed IT relationship.

Market context

Alert visibility is only one part of response

A standalone security provider can monitor alerts. An alert is more useful when the team reviewing it understands the user, device, role, business function and operating environment — without context, important signals can be missed and routine signals can be over-escalated. JQZ needed a model that could detect relevant signals, triage them in context, coordinate response and report on security activity in a way leadership could understand.

5

Five operational layers — endpoint, identity, alert handling, response and reporting — connected as one operating model.

1

One operating relationship: security signals interpreted against the same user, device and business context the team already understood.

Daily

Security connected to the way the environment is managed day to day rather than running as a separate service tier.

5

Five stages, from coverage assessment to a reporting cadence embedded in how the environment is managed.

JQZ managed cyber security engagementInlight IT delivery record
What changed for the client

JQZ gained a more mature security operating model inside its existing managed services relationship

The uplift improved visibility across endpoints, Microsoft 365 and identity activity. It gave security alerts a clearer triage process. It strengthened response coordination. It gave leadership a better view of security posture and improvement areas.

O·01

Stronger endpoint visibility

Security activity across managed devices reviewed and escalated through a structured process rather than left as isolated tool notifications.

O·02

Improved Microsoft 365 and identity oversight

Identity and Microsoft 365 activity received closer attention as part of the managed security operating model, not as separate workstreams.

O·03

Contextual alert triage

Alerts assessed for severity, context and required action rather than treated as isolated notifications without prioritisation.

O·04

More disciplined response coordination

Security events had clearer pathways for escalation, containment, remediation and communication, rather than being improvised as situations developed.

O·05

Better reporting for governance and insurance

JQZ gained a more structured view of security activity, control posture and improvement areas to support management, insurer and governance conversations.

O·06

A stronger cyber-first managed services model

Security became more integrated with the way the environment was managed day to day, rather than running as a separate service tier.

Net position

The value was not more alerts. It was security integrated with the way the environment was managed day to day, rather than running as a separate service tier.

Project outcomes

What managed services context gave the engagement

Outcome 01

Alerts reviewed in context

Security alerts reviewed against real user, device, role and operating context.

Outcome 02

Triage before escalation

Triage applied severity, context and cross-signal correlation before escalation.

Outcome 03

Identity as a primary layer

Identity treated as a primary security layer, not a secondary check.

Outcome 04

Pathways pre-established

Response pathways pre-established, not improvised during incidents.

Outcome 05

Findings actioned

Findings actioned through the live environment rather than parked in reports.

Outcome 06

Cadence for governance

Operating cadence supported leadership, governance and insurer conversations.

Technology and service scope

The work connected endpoint, identity, response and security reporting

Endpoint security

6
  • Endpoint protection
  • Detection and response visibility
  • Alert review
  • Device isolation
  • Remediation pathways
  • Managed endpoints

Microsoft 365 & identity

6
  • Microsoft 365 security
  • Entra ID monitoring
  • Identity and MFA
  • Suspicious sign-in review
  • Suspicious mailbox rule detection
  • Privileged access review

Triage & response

7
  • Alert triage
  • Severity assessment
  • Cross-signal correlation
  • Escalation handling
  • Containment coordination
  • Credential and account response
  • Session and rule removal

Reporting & governance

6
  • Security reporting
  • Posture visibility
  • Alert and escalation summaries
  • Insurance and governance support
  • Improvement tracking
  • Managed IT integration
Practical next step

Need stronger security operations around your managed IT environment?

Managed cyber security matched to your environment across identity, endpoints and response.

Explore Managed Cyber Security