Cybersecurity & Risk
John Drake & Associates helps organizations and internal IT teams reduce risk through endpoint protection, identity and password security, employee awareness training, vulnerability testing, security-event visibility, and recovery planning.
Security approach
Microsoft 365 + access
EDR / MDR
Backup + recovery
Practical security across the environment.
Whether we manage your environment directly or work alongside your existing IT department, security responsibilities, escalation paths, and response priorities should be clearly defined.
Endpoint security & detection
Protect business devices and improve visibility into suspicious activity affecting computers, users, and other connected systems.
Identity & access
Strengthen account security through multifactor authentication, access controls, and password-management tools that help reduce credential-related risk.
Email & awareness
Help employees recognize phishing attempts, suspicious email, and common social-engineering tactics through practical security-awareness training.
Vulnerability Management & Penetration Testing
Identify security weaknesses through vulnerability scanning and controlled testing, then prioritize remediation based on the risks most relevant to the organization.
Incident Support, Backup & Recovery
Coordinate incident support, backup, and recovery planning to help the organization respond to disruptions and restore essential systems.
Security Visibility & SIEM
Introduce security information and event management capabilities that provide greater visibility into security activity and help identify issues requiring attention.
Security decisions should be prioritized, explainable and connected.
Reduce the attack surface
Start with the basics that materially reduce exposure: patching, endpoint protection, secure configuration and vulnerability management.
Protect identity
MFA, conditional access and Microsoft 365 controls matter because identity is often the path into the environment.
Detect and respond
Security monitoring is effective when responsibilities are clear, potential threats are investigated, and the appropriate technical or internal IT team is engaged when action is required.
Plan for recovery
Backups, incident response and continuity planning matter because prevention cannot eliminate every disruption.
Assess, prioritize, operate and improve.
Periodic penetration testing helps validate security controls, identify exploitable weaknesses, and give business leaders and internal IT teams a clearer understanding of where remediation efforts should be focused.
Baseline
Understand the environment, current controls, exposures and business dependencies.
Prioritize
Separate material risk from noise and sequence improvements around impact and practicality.
Operate
Maintain controls, monitoring, patching and response responsibilities as ongoing work.
Review
Revisit risk as technology, insurance requirements and the organization itself change.
Make risk visible without turning security into theater.
Executives need a clear view of business exposure and priorities. IT leaders need controls that can be operated, supported and integrated with the rest of the environment.
EDR / MDR visibility
MFA and access controls
People and email risk
Backup and response
Want a clearer view of where security effort should go next?
Start with the environment, the controls already in place and the risks that matter most to the organization.