Services
Four services, one goal: an environment that holds up when it matters
Bastion focuses on Microsoft environments, because that is where most Swiss SMEs do their work: email, files, Teams, devices. Everything we offer revolves around one question: Will your environment withstand an attack, and what happens if it doesn't?
Secure
Building and securing Microsoft 365
ICT · Protect
The problem
Most Microsoft 365 environments grow over years and are never systematically secured. Accounts without multi-factor authentication, admin rights left over from old projects, no rules about which device may sign in from where. Attackers look for exactly these environments; the protection needed has long been included in most licences.
What we do
We build your environment from scratch or harden the existing one, following a documented procedure:
- Identities and access: clean up Entra ID, multi-factor authentication for everyone, Conditional Access, switch off legacy remnants such as legacy authentication
- Devices: management via Intune, encryption, update rules
- Detection: enable and configure Microsoft Defender XDR at every level (email, endpoints, identities, cloud apps)
- Data: protection against leakage via Purview policies, retention and backup properly governed
- Email: protection against phishing and spoofing (SPF, DKIM, DMARC), rules against automatic forwarding
What you get
A documented, traceably configured environment. Every setting has a stated reason, every deviation is recorded. This documentation also serves as your evidence for auditors and your cyber insurer.
Monitor
Security operations, continuous monitoring
ICT · Detect
The problem
A hardened environment generates alerts. Without someone who reads them, assesses them and acts, they are worthless. A dedicated security team doesn't pay off for an SME; the alerts come anyway, day and night.
What we do
We monitor your environment with Microsoft Defender XDR, Microsoft Sentinel and Tenable. Alerts converge in our SOAR platform (Security Orchestration, Automation and Response): AI-assisted threat analysis handles the first triage and proposes a classification; the decision is made by one of us. Real threats we remediate ourselves (lock the account, end the session, isolate the device), with a clear recommendation on what to do next.
This includes regular vulnerability scans, keeping detection rules up to date and a monthly report in plain language: what happened, what we did, where your environment stands.
What you get
A level of security that would otherwise require an in-house team, at costs that fit an SME. We define availability and response times together in a service agreement — honestly, and without promises two people cannot keep.
Respond
Incident response and forensics
ICT · Respond
The problem
An employee clicks on a phishing email, an account suddenly starts sending messages, the insurer wants a report. In this situation, two things count: limit the damage immediately and preserve the traces before they disappear.
What we do
We take over the incident from the first hour to the final report:
- Contain: lock compromised accounts, revoke sessions and tokens, remove malicious rules and app permissions, isolate affected devices
- Analyse: forensically examine sign-in logs, mailbox access, mail flows and endpoints; verify the attacker's point of entry; determine whether data was exfiltrated
- Clean up: eliminate the attacker's persistence, remove phishing emails from all mailboxes, notify affected recipients, harden the environment against recurrence
- Report: forensic report with timeline, root cause, extent of data exposure and measures taken, prepared for the cyber insurer, management and, where necessary, the authorities
We also assess your reporting obligations with you: the notification to the Federal Data Protection and Information Commissioner (Art. 24 FADP) and, for critical infrastructure, the report to the National Cyber Security Centre within 24 hours.
What you get
A contained incident and a report the insurer can use as the basis for settling the claim. The AI-assisted pre-analysis in our SOAR platform shortens the investigation from weeks to days; that lowers the cost and delivers answers while they are still useful. The forensic assessment is done by us personally.
Active incident?
Don't delete anything; write down what you noticed. More on the contact page
Assess
Audits and assessment
ICT · Identify

The problem
"Are we secure?" cannot be answered without an assessment. Many SMEs don't know what gaps their environment has, which of them are urgent and what their cyber insurer requires of them.
What we do
We examine your environment and make its state visible:
- Microsoft 365 security check: configuration of Entra ID, Defender, Exchange and Intune checked against recognised standards
- Gap audit against the Swiss federal ICT minimum standard: where your company stands in the areas of Identify, Protect, Detect, Respond and Recover
- Insurability check: your environment measured against the minimum requirements of Swiss cyber insurers (multi-factor authentication, backup concept, update processes, device protection, training)
What you get
A report in two parts: a summary for management without jargon, and a technical list of measures, prioritised by risk and effort. You can implement the measures yourself, with your IT partner or with us.
Insurers & brokers
Forensics and reports for your claims
Cyber insurers and brokers bring us in on their clients' claims: for the forensic analysis, the damage assessment and the report on which the case is settled. We work fast, document to a court-admissible standard and write so that claims handlers without a security background can follow the case. Talk to us about working together:
info@bastionsecurity.chNot sure where to start?
We'll find out in a free initial consultation.