Home / Case studies / VLI Managed Cyber Security
Client story · Security operations

From security alert to engineering fixManaged security across endpoints, Microsoft 365 and identity

We run an ongoing security service for VLI. Our engineers review sign-ins, endpoint alerts and Microsoft 365 activity, assess what matters and carry the fix into VLI's systems.

The brief

Strong controls need someone watching them, and an engineer ready to act when something needs attention

VLI supplies heavy equipment to mining and industrial customers, with people, devices and Microsoft 365 accounts that need to stay protected as the business moves. Security controls were in place. The next step was keeping them under active review as the business and its systems changed.

We set up a managed security service that links investigation with the engineers supporting VLI's systems. When a finding needs a change, it goes straight to the people who can make it.

How the service works

From signal to fix, in one connected loop

  1. 01 · Signal

    Activity across devices, accounts and Microsoft 365

    We keep endpoint protection, sign-in activity and Microsoft 365 security settings under review. Unusual activity is raised with the device and user details attached, so the assessment starts with context.

    • Endpoints
    • Microsoft 365
    • Entra ID sign-ins
  2. 02 · Assess

    Severity weighed against what it means for VLI

    Each confirmed signal is assessed for severity, the people and systems affected and the effect on operations. That assessment decides whether to contain, escalate or monitor, and who needs to hear about it.

    • Severity
    • Business context
    • Escalation
  3. 03 · Act

    Engineers carry the finding into the system

    Because our engineers work across VLI's environment, findings move straight into protection policies, authentication and access changes or Microsoft 365 configuration. Where an issue reaches further, the work extends into infrastructure or backup.

    • Policy changes
    • Access and authentication
    • Configuration
  4. 04 · Report

    Coverage, escalations and improvements on record

    Regular reporting covers the areas we monitor, alerts reviewed, escalations and the improvements in progress. It gives VLI's management a clear view of the service and supports governance and procurement conversations.

    • Monitored coverage
    • Alert reviews
    • Improvement actions
What we delivered

Where we focused the security review

01

Endpoint activity read with user context

We manage endpoint protection coverage and review suspicious activity alongside the user and related signals, so a finding is judged in the context of the wider environment.

  • Endpoint protection
  • User and device context
02

Microsoft 365 and Entra ID under active review

We review administrator privileges, MFA coverage and security configuration across Microsoft 365 and Entra ID. Sign-in patterns, identity risk signals and mailbox behaviour form part of ongoing oversight, bringing account activity and access controls into the same review.

Findings are carried through into MFA and authentication settings, administrator and user access, and Microsoft 365 configuration, with mailbox or account remediation where it is needed.

  • Administrator privileges
  • MFA
  • Sign-in patterns
  • Identity risk signals
  • Mailbox behaviour
The outcome

Security findings now travel all the way to the fix, inside the IT VLI relies on

Ongoing oversight

Endpoints, Microsoft 365 and identity under continued review, with engineering attention as the environment changes.

A defined response path

A clear route from a confirmed signal to assessment, escalation, communication and tracked follow-up.

Change that sticks

Findings turned into policy, access and configuration changes, with reporting that keeps improvements visible to management.

Service scope
Endpoint protectionMicrosoft 365Microsoft Entra IDAdministrator privilegesMFA and authenticationSign-in and identity riskMailbox behaviourAlert triageEscalationAccount and configuration remediationSecurity reporting
Work with Inlight IT

Bring security response and IT engineering together

We manage security across devices, identities and Microsoft 365, with engineers who can carry findings through into the systems and controls involved. Talk to us about the security support your business needs.

Prefer email? contact@inlightit.com.au