MFA, logging, and backups you can actually restore
Written by AERVIO, a Montreal studio. Human-reviewed before publish. Contact: hello@aervio.io · +1 438-498-3913.
Most “cybersecurity” decks we inherit are a PDF, a tray icon, and a story about Quebec SMBs. None of that restores a mailbox. Alerting and hardening at AERVIO is three unglamorous loops: MFA where it belongs, logs a human reads, backups restored on a date you can point at.
We do not put security “at the heart of everything” as a slogan. We put it on the 365 workplace, the desk, and the site so a Tuesday incident has a runbook.
MFA is a policy, not a checkbox in a demo
Privileged roles: required, phishing-resistant if the platform allows, no leftover SMS for global admin if a better method exists. Everyone else: required on a schedule, with a help path that does not dump them on the founder.
Exceptions are written (a warehouse scanner, a vendor). Exceptions that last a year are not exceptions. They are holes.
Lost phone process is part of onboarding, not a LinkedIn post after the incident.
Logs nobody reads are storage costs
We keep:
- Sign-in failures and MFA fatigue patterns
- Admin role changes
- Mailbox forwarding rules (the quiet exfil)
- Backup job failures
Those go to a place a named person sees on business days. If the volume needs a SIEM, we will say so and cost it. We will not drop you into a portal with 4,000 red badges and call it “monitoring and reacting.”
Backups are restores
A job that says “Completed” is not a restore. A restore is: pick a date, bring back a mailbox or a library or a database, time it, write the minutes.
Cadence we like for a small Montreal company:
- Weekly restore of something unimportant (proof)
- Quarterly restore of something you would cry about
- After any tooling change, one extra restore
The site and CRM need the same discipline. A WordPress host backup you have never opened is a rumour. Next.js on a platform without a datastore restore story is a rumour.
Hardening that fits a 20-person company
- Admin count in the single digits
- Guest accounts with an expiry
- Forwarding restrictions
- Device encryption on company laptops
- A leaver checklist that kills the token the same day
- DNS locked at the registrar
We will not sell you a “zero trust journey” with seven phases if you still share a password in the WhatsApp group. Order matters.
Incidents, honestly
Default coverage is Montreal business hours. If you need more, we write the hours and the escalation. Ransomware theatre (paying, not paying) is a counsel and insurer conversation. Our job is to make restore a real option so that conversation is not your only option.
What we hand you
A one-page picture: identities, where mail lives, where files live, where the website lives, last restore date, who gets the alert. If that page does not exist, you have tools, not a program.
If your last “security deliverable” was a 60-page PDF, send the executive summary (or even the table of contents) to hello@aervio.io. We will tell you which three loops are missing before we talk about tools.
Phishing is a people drill, not a poster
We would rather run two short drills a year than hang a “think before you click” PDF. The drill is: a fake (labelled, internal) message, who reported it, how fast we killed the session. Shame is not the metric. Reporting is.
If you cannot restore, drills still matter, but restore is the cheaper incident. Order: restore, MFA, then theatre.
Vendor access
Every agency, accountant, and “temporary” developer with global admin is a hole. We inventory them. We put expiry on guests. We do not let a theme vendor keep owner on the Microsoft tenant because they installed a plugin in 2021.
What an alert looks like when it is useful
“Impossible travel on a global admin, 10:14 ET, account X, we disabled the session, call us.” Not a CSV of 900 ‘low’ items. If your current tool cannot say that sentence, we will not ‘tune’ it forever. We will change what is watched.
A PDF table of contents is still enough to start.
Questions
Do you offer a 24/7 SOC?
Not as a default. We offer alerting a named human reads in Montreal hours, plus a written after-hours slice if you buy it. A SOC logo on a small invoice is usually fiction.
Will you run a penetration test?
We can schedule an independent tester. We do not sell ourselves as the attacker and the defender on the same week.
Is antivirus enough?
No. MFA on privileged roles, tested restores, and leavers that actually leave matter more than a tray icon.
Read next
Let's write the next step.