Identity
MFA coverage, privileged roles, joiner and leaver workflow, legacy authentication, shared accounts, recovery methods and administrator separation.
KaizenDubai helps organisations move from purchased security products to a working control system: known owners, usable logs, tested recovery and clear actions when something changes.
Multi-factor authentication is not complete because a licence was purchased. It must be enforced for the correct users, recovery methods must be controlled, exceptions must be visible and old accounts must leave the environment. The same principle applies to endpoint protection, email filtering, firewalls and backups.
We begin with identity and business-critical workflows, then work outward to devices, email, network boundaries, administrative access, third parties and recovery. The result is a prioritised control baseline rather than a list of every theoretical threat. Each finding includes an owner, evidence requirement and decision on whether the risk is fixed, accepted, transferred or scheduled.
MFA coverage, privileged roles, joiner and leaver workflow, legacy authentication, shared accounts, recovery methods and administrator separation.
Supported operating systems, patch status, encryption, endpoint detection, local administrator use, device inventory and response isolation.
Anti-phishing controls, forwarding rules, domain protection, external sharing, mailbox audit visibility and user reporting paths.
Firewall governance, VPN access, exposed services, segmentation, guest networks, branch links and configuration backup.
Backup coverage, protected credentials, retention, offline or immutable copies, restore testing and a decision process for ransomware events.
| Signal | First question | Immediate evidence |
|---|---|---|
| Suspicious sign-in | Is the user, location and device activity expected? | Identity logs, MFA result, session data and recent account changes |
| Malware or endpoint alert | Is the device isolated and what data or accounts were exposed? | Detection timeline, process tree, user activity and network connections |
| Email compromise report | Did the account send, forward or approve anything? | Mailbox audit, inbox rules, sign-ins, OAuth grants and message trace |
| Unexpected firewall traffic | Is this a new business service, misconfiguration or hostile activity? | Rule history, source and destination, application, logs and change record |
| Backup failure | Which recovery objective is now at risk? | Job history, protected workload, last successful copy and restore evidence |
We confirm assets, identities, internet exposure, administrative routes, critical data and current security tools. Unsupported assumptions are recorded.
Privileged access, exposed services, missing MFA, unsupported systems and untested recovery usually receive attention before lower-impact cosmetic settings.
Configuration evidence is combined with practical checks: alert routing, isolation, access removal, log availability and restoration.
Reviews, renewals, exceptions, vulnerability work and response contacts are added to an operating calendar.
We will separate urgent exposure from longer-term improvement and show what evidence is required to confirm each control.