Security embedded across the relationship

Cybersecurity & Risk

John Drake & Associates helps organizations and internal IT teams reduce risk through endpoint protection, identity and password security, employee awareness training, vulnerability testing, security-event visibility, and recovery planning.

EDR / MDR
Microsoft 365 security
Vulnerability management
Incident support
Integrated

Security approach

Identity

Microsoft 365 + access

Detection

EDR / MDR

Resilient

Backup + recovery

What we provide

Practical security across the environment.

Whether we manage your environment directly or work alongside your existing IT department, security responsibilities, escalation paths, and response priorities should be clearly defined.

Endpoint security & detection

Protect business devices and improve visibility into suspicious activity affecting computers, users, and other connected systems.

Identity & access

Strengthen account security through multifactor authentication, access controls, and password-management tools that help reduce credential-related risk.

Email & awareness

Help employees recognize phishing attempts, suspicious email, and common social-engineering tactics through practical security-awareness training.

Vulnerability Management & Penetration Testing

Identify security weaknesses through vulnerability scanning and controlled testing, then prioritize remediation based on the risks most relevant to the organization.

Incident Support, Backup & Recovery

Coordinate incident support, backup, and recovery planning to help the organization respond to disruptions and restore essential systems.

Security Visibility & SIEM

Introduce security information and event management capabilities that provide greater visibility into security activity and help identify issues requiring attention.

How we think about risk

Security decisions should be prioritized, explainable and connected.

Reduce the attack surface

Start with the basics that materially reduce exposure: patching, endpoint protection, secure configuration and vulnerability management.

Protect identity

MFA, conditional access and Microsoft 365 controls matter because identity is often the path into the environment.

Detect and respond

Security monitoring is effective when responsibilities are clear, potential threats are investigated, and the appropriate technical or internal IT team is engaged when action is required.

Plan for recovery

Backups, incident response and continuity planning matter because prevention cannot eliminate every disruption.

Security as an operating discipline

Assess, prioritize, operate and improve.

Periodic penetration testing helps validate security controls, identify exploitable weaknesses, and give business leaders and internal IT teams a clearer understanding of where remediation efforts should be focused.

01

Baseline

Understand the environment, current controls, exposures and business dependencies.

02

Prioritize

Separate material risk from noise and sequence improvements around impact and practicality.

03

Operate

Maintain controls, monitoring, patching and response responsibilities as ongoing work.

04

Review

Revisit risk as technology, insurance requirements and the organization itself change.

For business and IT leadership

Make risk visible without turning security into theater.

Executives need a clear view of business exposure and priorities. IT leaders need controls that can be operated, supported and integrated with the rest of the environment.

Security
Endpoint

EDR / MDR visibility

Identity

MFA and access controls

Awareness

People and email risk

Recovery

Backup and response

Want a clearer view of where security effort should go next?

Start with the environment, the controls already in place and the risks that matter most to the organization.