Rossair
IT support, the phone system and a website that brings in enquiries, all looked after by one team.
0333 335 5020letstalk@networklondon.co.ukRemote supportClient portal
Most firms of 20 to 250 people run on Microsoft 365, and much of the security in the licence is off by default. Network London reviews your tenant, switches on what matters and keeps it that way: multi-factor authentication, conditional access, email protection, device management and the audit logs your clients ask about.


Does any of this sound familiar?
Most of the Microsoft 365 breaches we see needed nothing clever. A setting was off. We switch them on.

First, multi-factor authentication for every account with no exceptions, and legacy sign-in methods blocked so it can't be bypassed. Then conditional access: sign-ins allowed only from managed devices and expected countries, with admin accounts held to a stricter standard. Email protection next: SPF, DKIM and DMARC so your domain can't be spoofed, plus anti-phishing, safe links and safe attachments. Sharing limits so files can't be shared with anyone on the internet by default. Devices enrolled in Intune, encrypted and checked for compliance before they can reach company data. And the audit log switched on and kept, so when a questionnaire asks what you log, there is an answer.
We do this as part of looking after your IT, document what is set and why, and review it when Microsoft changes things, which is often. What can be switched on depends on your licence. One thing no licence includes is a backup of your data: Microsoft keeps the service running, but deleted or encrypted files are your problem. We add a separate backup, charged per user per month. Our security work is led by Ian Welch, a certified ethical hacker and CISSP, and Network London holds Cyber Essentials Plus.
Tell us which licence you're on and we'll tell you what it already includes that you're not using.
Tell us what you needBusiness Premium includes most of what a firm of your size needs: Intune, Defender for Business and conditional access. We make sure you're using it before anyone sells you more.
Settings drift as people join, leave and ask for exceptions. We review the tenant on a schedule and keep the exceptions list short and written down.
Who has access, what is enforced, what is logged and for how long, documented in the form a client questionnaire or an insurer asks for.
Three of the 100+ businesses we look after, and what we do for them.
IT support, the phone system and a website that brings in enquiries, all looked after by one team.
Everyday support for 180 people, with access reviews and backup testing built into how they work.
A small team with serious duties to investors. We shaped their IT and cyber security policy and look after it day to day.
Jessica, our Operations Director, replies the same day. We agree access and review your tenant's identity, email, sharing, device and logging settings against what your licence includes.
What is on, what is off, what is risky and what it would take to fix, in plain English, with the quick wins first.
We make the changes in stages so nobody is locked out, test them with your team, and document the result for your records and your next questionnaire.
Every user and every admin, with legacy sign-in blocked so it can't be bypassed. Shared mailboxes and service accounts handled properly rather than exempted.
Sign-ins allowed from managed devices and expected locations, risky sign-ins challenged or blocked, admin accounts held to a stricter standard.
SPF, DKIM and DMARC set in your domain's DNS, with anti-phishing, safe links and safe attachments switched on and tuned. Ongoing DMARC monitoring and management is an add-on through Hornetsecurity or Sendmarc.
External sharing limited to what you intend, links that expire, and sensitive data labelled so it can't leave by accident.
Laptops and phones enrolled, encrypted, kept up to date and checked for compliance before they can reach company data.
The fewest admins possible, each with their own account, and an emergency account kept offline for the day something goes wrong.
The unified audit log switched on and retained. With our managed security package, the signs of an account takeover (new forwarding rules, impossible travel, mass downloads) are monitored, alerted on and dealt with.
Mail, OneDrive, SharePoint and Teams backed up separately from Microsoft, and tested, so a deleted or encrypted file is a restore rather than a loss. Charged per user per month.
Jessica, our Operations Director, reads every enquiry and replies personally the same day. The first step is a conversation about your business, what's working and where you need help.
Prefer to talk? Call 0333 335 5020. A real person answers, always.
LM04.202, The Leather MarketThank you. Your message has been received and we'll be in touch shortly.
Something went wrong sending that. Please call 0333 335 5020 or email letstalk@networklondon.co.uk.
Tell us which licence you're on and roughly how many people you have. Jessica, our Operations Director, replies to every enquiry personally, the same day.
Tell us what you needNot in the way most people assume. Microsoft keeps the service running and keeps deleted items for a limited time, but it is not a backup of your data against deletion, ransomware or a leaver clearing their mailbox. We add a separate, tested backup, charged per user per month.
Microsoft 365 Business Premium includes Intune, Defender for Business and conditional access, which covers most of what a firm of 20 to 250 people needs. Everything on this page apart from DMARC management is available on Business Premium and above. If you're on Business Standard or Basic, we'll tell you what you're missing and whether it's worth the upgrade.
It's the most important single setting, and it's often less complete than it looks: exempt accounts, legacy sign-in methods still allowed, and admins without a stricter standard. Conditional access, email protection, sharing limits and logging close the gaps that MFA alone leaves.
Rules about who can sign in, from where and from what. For example: company data only from managed, encrypted devices; no sign-ins from countries you don't operate in; admin access only from certain machines. It's included in Business Premium and is the setting that stops a stolen password being useful.
The review itself takes a few days. Making the changes is done in stages over two to four weeks so nobody is locked out and your team is told what is changing. You get a written record at the end.
Yes. We can review and secure the tenant as a project and hand the documentation to your provider. Most firms who come to us this way move their IT to us afterwards, because keeping the settings right is a continuous job.

Penetration testing scoped to what your clients asked for, with the findings fixed by the same team.

What Cyber Essentials and Cyber Essentials Plus cost, and how we get you through them.

ISO 27001 consultancy led by a lead implementer, from gap analysis to the audit.

We look after your cyber security and help you answer the security questions your clients, insurers and investors send you.
Most of them are free. We'll send you our list of resources you and your team can use to improve your cyber security straight away. No technical knowledge needed.