Continual Security Uplift Program

Microsoft 365 Business Premium is the minimum. Security Uplift is non-negotiable. We decline freely.

MSPs sell fear. We sell a rising score.

Most MSPs leave Microsoft 365 half-configured, or worse, strand you on licences that cannot run real Conditional Access, Intune, and Defender. Microsoft 365 Business Premium is our minimum. The Continual Security Uplift Program is not optional décor. It is how we work.

The Stride IT Security Standard is informed by Microsoft Secure Score guidance, Business Premium capabilities, and selected industry frameworks (including Essential 8 concepts). It is our standard. Achievable, documented, renewable, not a government certificate.

Client filter

We only take clients who will uplift.

If this list makes you uncomfortable, good. Another MSP will take your money. We would rather stay excellent for the ones who mean it.

You will fit if

  • You will run Microsoft 365 Business Premium (or higher) as the floor, not a wishlist.
  • You will support Continual Security Uplift: controls finish, Secure Score moves, QBRs happen.
  • You want outcomes priced in, not a surprise invoice every time something breaks.
  • You will refresh devices or infrastructure when the Standard says they cannot keep up.
  • You want a named method and a mark you can show, not a vague promise to sort IT out.

We will decline if

  • You want the cheapest MSP who just keeps the lights on.
  • You refuse Business Premium and will not upgrade as part of uplift.
  • You want break-fix billing, ticket queues, and security left alone.
  • You want fear theatre and a checkbox PDF, not a rising Secure Score.
  • You want us to babysit consumer routers, ancient PCs, and hope.
  • You shop MSPs like commodities and treat security as optional décor.

We turn work away. That is not a marketing line. It is how we keep the Standard real for the clients who stay. Baseline is an application, not a shopping cart. We may say no.

Stride IT Security Standard

Twelve controls. Microsoft 365 Business Premium is the floor. With Stride SOC eyes on the alerts.

01

Microsoft Secure Score: up, not decorative

We baseline your Secure Score, pick the high-impact wins first, and report the trend every quarter. If the number is not moving, we are not done.

Proof you can see. Not a slide saying aligned.

02

Phishing-resistant MFA

Conditional Access with phishing-resistant methods (passkeys, FIDO2, Windows Hello for Business) so a stolen password and a text code are not enough.

Your users should not be the softest door in the building.

03

Conditional Access and legacy-auth kill switch

Entra ID policies that block ancient protocols, enforce compliant devices, and stop any device, any time access from becoming an open invitation.

Attackers love what your MSP never switched off.

04

Defender for Office 365: email that fights back

Safe Links, Safe Attachments, and anti-phishing policies tuned for Business Premium so the inbox is a filter, not a welcome mat.

Most breaches still start with something that looks legit.

05

Defender for Business: endpoint EDR

Every managed device onboarded to Microsoft Defender for Business with real detection and response, not just antivirus installed.

If nobody is watching the alerts, you do not have protection. You have hope.

06

Intune device compliance

Encryption, patch baselines, compliance policies, and Conditional Access that locks out non-compliant machines before they touch your data. Hardware has to be able to meet the bar. If it cannot, we schedule a refresh instead of pretending.

Security controls need machines that can run them. That is fairness, not snobbery.

07

Identity and admin hardening

Privileged accounts locked down, break-glass accounted for, guest access controlled, and admin sprawl cleaned up.

One over-privileged mailbox can undo a year of good intentions.

08

User protection that sticks

Phishing simulations, short drills, and habits that raise the human firewall without death-by-PowerPoint fear theatre.

Training that changes behaviour beats posters that collect dust.

09

SOC-style monitoring (Stride eyes on Defender)

We triage Microsoft Defender alerts, escalate what matters, and close the loop so signals become action, not a dashboard nobody opens.

A SOC without response is a screensaver.

10

Backup and recovery proof

M365 and critical data protected, restores tested, recovery times documented, because a backup you have never restored is a bedtime story.

Ransomware does not care that the invoice said backup included.

11

Data loss guardrails

Sensitivity labels and DLP patterns where Business Premium supports them so customer data does not wander into the wrong share or inbox.

Clients trust you with their secrets. Act like it.

12

Quarterly uplift reviews

QBRs with Secure Score trend, open risks, and the next uplift batch: continual improvement, not a one-off project that dies at go-live.

Security that stops improving starts decaying.

The Stride Uplift Mark

The Stride Uplift Mark indicates a signed client self-assessment that they adhere to Stride IT Security Standard recommendations under the Continual Security Uplift Program. It is not an ACSC, DISP, Microsoft, or government certification.

Show your clients you take security seriously. With a mark that means you met a named standard and keep meeting it, not that you bought another scare campaign.

Client website example

Uplift Mark popup

Same example badge on this site. Clients who earn the Stride Uplift Mark get their own proof page and badge. With the disclaimer baked in.

The Stride Uplift Mark indicates a signed client self-assessment that they adhere to Stride IT Security Standard recommendations under the Continual Security Uplift Program. It is not an ACSC, DISP, Microsoft, or government certification.

Phase deliverables

1. Baseline

Honest picture of where you stand, Secure Score and all.

M365/environment audit, Secure Score baseline, Stride IT Security Standard gap map, tailored uplift plan and schedule.

2. Stabilise

Stop the bleeding. Fix what breaks trust today.

Critical patches, phishing-resistant MFA path, Defender onboarding, backup verification, help desk SLAs live.

3. Uplift

Lift each control against the Stride IT Security Standard.

Conditional Access, Intune compliance, email protection, SOC triage, user drills, Secure Score lift.

4. Mark

Earn the Stride Uplift Mark: signed self-assessment and public proof.

Signed self-assessment against the Standard, mark badge for your site, public proof page linked from the badge.

5. Continual

Keep lifting. Security that stops improving starts decaying.

QBRs, Secure Score trend, roadmap updates, mark renewal criteria tracked.

Business partners shaking hands after a successful meeting

Photo: LinkedIn Sales Solutions / Unsplash

How to use the mark

  • Display on your website footer or security page using artwork provided by Stride IT.
  • Include in proposals alongside your Secure Score trend and Standard narrative.
  • Always pair with context: Stride IT Security Standard met, not ACSC or Microsoft certification.
  • Do not alter colours or imply government endorsement.

FREQUENTLY ASKED QUESTIONS

What is the Continual Security Uplift Program?

It is Stride IT's named five-phase program: Baseline, Stabilise, Uplift, Mark, and Continual. We lift your environment against the Stride IT Security Standard using Microsoft 365 Business Premium as the minimum stack, and we keep lifting after go-live.

What is the Stride IT Security Standard?

It is Stride IT's security baseline for clients on Microsoft 365 Business Premium or higher: Secure Score lift, phishing-resistant MFA, Conditional Access, Defender for Office and endpoints, Intune compliance, SOC-style alert triage, user protection, backup proof, and quarterly reviews. Informed by Microsoft guidance and selected frameworks, not an official certification.

What is the Stride Uplift Mark?

The Stride Uplift Mark is shown when a client has a signed self-assessment on record affirming they adhere to Stride IT Security Standard recommendations under the Continual Security Uplift Program. The badge links to that public proof. It is not an ACSC, DISP, Microsoft, or government certification.

Is Microsoft 365 Business Premium required?

Yes. Business Premium is our minimum licence for managed clients. It is the floor that makes identity, Intune, Defender for Business, and Defender for Office 365 workable as one stack. If you are on a lower licence and will not upgrade as part of uplift, we are not the right fit, and we will say so early.

Will you take clients who skip the Security Uplift?

No. We decline on purpose. Ticket-only, break-fix, or “keep it cheap and hope” engagements undermine the Stride IT Security Standard. If you will not support the Continual Security Uplift minimum, we say no early so we can stay excellent for the clients who will.

What about older laptops and PCs?

Devices need to be fit for the Standard. Able to patch, encrypt, and enrol in Intune so Defender and Conditional Access actually work. If hardware is holding the uplift back, we do not shame anyone. We put a practical refresh plan on the roadmap and sequence it with the rest of the uplift.

What about routers, firewalls, and Wi‑Fi?

Infrastructure needs to be something we can monitor and secure. Business-class firewalls, switches, and access points with proper logging, segmentation, and remote management. Consumer home networking products are not a foundation we can uplift. If that is what you have today, we map a practical swap onto the roadmap. No snobbery, just what the Standard requires.

How do we start?

Apply for an Uplift Baseline Review. We capture Secure Score, confirm Business Premium readiness, check device and infrastructure fitness for the Standard, and give you a tailored uplift plan and schedule. Baseline is an application. We may decline if you will not support the minimum.

The Stride Uplift Mark™ is a Stride IT program mark. It indicates that a client has completed a signed self-assessment affirming they adhere to Stride IT Security Standard recommendations under our Continual Security Uplift Program, and that Stride IT has recorded that attestation at the stated review date. The Standard is informed by Microsoft 365 Business Premium capabilities, Microsoft Secure Score guidance, and selected industry frameworks (including ACSC Essential 8 concepts). It is not an Australian Cyber Security Centre certification, not a Microsoft endorsement, not a DISP approval, and not a guarantee of security or regulatory compliance. Proof for each issuer is published on this site and linked from the badge.

Security Uplift Phases

Five named phases. From Baseline to Continual. Microsoft 365 Business Premium is the minimum. Secure Score that actually moves.

  1. 1

    Baseline

    Honest picture of where you stand, Secure Score and all.

    M365/environment audit, Secure Score baseline, Stride IT Security Standard gap map, tailored uplift plan and schedule.

  2. 2

    Stabilise

    Stop the bleeding. Fix what breaks trust today.

    Critical patches, phishing-resistant MFA path, Defender onboarding, backup verification, help desk SLAs live.

  3. 3

    Uplift

    Lift each control against the Stride IT Security Standard.

    Conditional Access, Intune compliance, email protection, SOC triage, user drills, Secure Score lift.

  4. 4

    Mark

    Earn the Stride Uplift Mark: signed self-assessment and public proof.

    Signed self-assessment against the Standard, mark badge for your site, public proof page linked from the badge.

  5. 5

    Continual

    Keep lifting. Security that stops improving starts decaying.

    QBRs, Secure Score trend, roadmap updates, mark renewal criteria tracked.

Still here? Apply for Baseline.

Baseline is an application, not a shopping cart. We confirm Business Premium readiness, map Secure Score to the Stride IT Security Standard, and show a tailored uplift plan and schedule. If you will not support the minimum, we decline. Early, clearly, and without drama.