Guide
Cyber Security
The security domain holds the strategy and the operations that carry it out. It opens with Zero Trust, which is the strategy the rest of this library implements and is not a product anybody can sell you: what it actually is, where the idea came from and where it takes you, what it changes about the working day for the people signing in and the people running the estate, and an honest reading of the market beyond Microsoft. The second series turns to detection and response bought rather than built, and reads the managed market by the architecture each provider actually runs rather than by where it sits on somebody’s ranked list.
Zero Trust
4 articles
Zero Trust Is Not a Product
Nobody sells Zero Trust, including the vendors who say they do. Microsoft says so on its own documentation, NIST needed 24 organizations and 19 distinct builds to demonstrate one, and the man who coined the term has spent a decade saying you cannot buy it. What you can do is practice it.

From the Perimeter to the Access Decision
The castle-and-moat model was a reasonable design for a world that stopped existing. Where Zero Trust actually came from, the 2010 report that flipped the mantra, Google's proof that it works at scale, and the destination: every access is a per-session decision, made on evidence, by a policy engine.

What Zero Trust Changes About How You Work
A strategy you cannot buy still has to show up somewhere. Here is where: the sign-in, the VPN that quietly disappears, the admin rights that expire, the office network that stops being special, and the operational loop that keeps all of it honest. The lived experience of Zero Trust, costs included.

The Landscape: Frameworks, Stacks, and the Names Worth Knowing
The frameworks that define Zero Trust, the Microsoft stack mapped honestly to them, and the non-Microsoft names a practitioner should recognize: Zscaler, Netskope, Palo Alto, Cato, Cloudflare, Fortinet, CrowdStrike, Okta, Illumio. Plus the one question that cuts through every vendor claim.
MDR
12 articles
Managed Detection and Response: Buying Operators, Buying a Stack, or Both
The MDR question is not which provider is best. It is whether you are buying a second security stack, operators for the one you already own, or a provider who replaces the layer your security data lives in, and who holds the authority to act inside your tenant.

Arctic Wolf: The Concierge and the Open Platform
The name that comes up first in most mid-market conversations, and the reason is the delivery model rather than the technology. The platform question and the delivery question have different answers, and the second one gets less scrutiny than it deserves.

Microsoft Defender Experts: The First-Party Answer
Microsoft operating Microsoft is the baseline case every other provider is implicitly priced against. What Defender Experts declines to cover is the fastest way to work out what you actually need from anyone else.

CrowdStrike Falcon Complete: The Second Stack, Fully Operated
The most complete version of the buy-a-second-stack answer, and the most architecturally consequential provider in this series for a Microsoft estate. CrowdStrike now sits inline in the Entra authentication flow, which makes it a second policy decision point in front of the one you built.

Huntress: Operating the Licenses You Already Own
What does an organisation with Business Premium, no security staff and a few hundred endpoints actually do? Huntress operates the Microsoft licences you already hold rather than selling a replacement for them, and that constraint has produced some of the most practical engineering in this series.

Expel: Authority With Guardrails
The purest expression of the operate-your-stack model: no agent, no platform to adopt, judgement sold against the tooling you already run. Expel has also done the best job in this market of writing down what its analysts may do and what happens when it goes wrong.

Red Canary Under Zscaler: When Your Zero Trust Vendor Owns Your SOC
Red Canary was the reference implementation of vendor-neutral managed detection until Zscaler bought it in August 2025. That transaction turns a straightforward evaluation into a question about what happens when your zero trust enforcement vendor also holds your detection contract.

Critical Start: The Only Service Level With a Clock and a Remedy
Critical Start publishes what nobody else in this market does: a response time with a defined start, a defined stop, and service credits when they miss. Plus the known-good registry that makes resolving every alert economically possible, and the question you should ask about it.

Palo Alto Unit 42 Managed XSIAM: Buying a Security Data Platform With Operators Attached
Palo Alto is the mirror image of the endpoint replacement. They leave your Defender agents alone and replace the layer above, which makes this a security data platform decision wearing a managed service label.

What the Contracts Actually Say: Authority, SLAs, Overlap, and the GenAI Claim
Eight providers, one set of questions, and the answers do not line up the way the marketing suggests they should. Where the real differences sit, which published numbers mean anything, what an E5 organisation ends up paying for twice, and how to run an evaluation that produces a decision.

Build Sheet: MDR Readiness in Your Own Tenant
A managed detection provider inherits your logging gaps on the day they onboard. Establish what your tenant actually produces and retains before you take a single vendor demonstration, so the evaluation compares providers rather than measuring your own instrumentation.

Build Sheet: The Evaluation Scorecard and Proof-of-Value Plan
Most MDR evaluations are decided by a demonstration and a reference call, which between them test the vendor sales engineering and their choice of referee. A scorecard you can defend to a board, and a provider-neutral proof-of-value plan that measures what actually comes back.



