Black Tower Cyber is built for active incidents, Microsoft 365 account compromise, business email compromise, cloud forensics, tenant cleanup, and incident readiness. When monitoring is needed, we hand clients into a SOC-as-a-Service model instead of pretending to be a full MSP.
ATO, BEC, phishing, suspicious access, or a security readiness review.
MFA, Conditional Access, enterprise apps, mailbox rules, admin roles, and email controls.
Ongoing MDR, ITDR, SIEM, SAT, reporting, and escalation back to BTC IR.
These services are designed around what BTC can deliver at a high level: incident response, Microsoft 365 investigations, tenant hardening, readiness documentation, and a clean handoff into monitoring when ongoing coverage is required.
Active incident triage, evidence preservation, timelines, root cause, and written reports.
Microsoft 365 compromise, mailbox abuse, forwarding rules, message trace, and impact review.
Audit logs, Entra ID, Exchange, SharePoint, OneDrive, OAuth, and cloud evidence exports.
MFA, Conditional Access, enterprise apps, admin roles, mailbox rules, and SOCaaS readiness.
Hands-on cleanup of risky tenant settings before attackers exploit them or before monitoring starts.
Playbooks, evidence folders, tabletop exercises, control validation, and questionnaire support.
Scope, severity, priority, and immediate containment path
Sign-ins, sessions, tokens, MFA, mailbox activity
Header analysis, message trace, IOC extraction, impact
Exports, screenshots, logs, chain-of-custody notes
Available EDR/MDR alerts, suspicious process activity
Timeline, root cause, impact, remediation steps
For active incidents involving suspicious access, malware alerts, phishing, account takeover, wire fraud, or cloud compromise.
Force sign-out, revoke refresh tokens, reset password
Re-registration, suspicious MFA methods, bypass review
Hidden rules, deleted folders, RSS, archive abuse
Identify impacted messages, recipients, and fraud attempts
Rogue apps, risky consents, suspicious permissions
Who was affected, what was accessed, what changed
For compromised Microsoft 365 accounts, suspicious mailbox activity, fraudulent invoices, wire fraud attempts, or client-reported suspicious email activity.
Start InvestigationUnified audit log, Exchange, SharePoint, OneDrive
Sign-ins, risk, conditional access, admin actions
Mailbox audit, delegation, forwarding, transport rules
External sharing, suspicious downloads, permissions
When needed, scoped cloud review and evidence export
First access, attacker actions, containment, recovery
Coverage, admin enforcement, weak methods
Baseline policies, gaps, legacy auth, named locations
User consent, risky apps, stale integrations
Forwarding, inbox rules, delegation, external access
SPF, DKIM, DMARC, spoofing controls
Priority matrix and SOCaaS readiness recommendation
A practical review for companies that need to know where they are exposed before an incident, insurance renewal, or managed monitoring onboarding.
Disable risky user consent and review existing apps
Clean stale, risky, or over-permissioned apps
Users, admins, break-glass planning, method cleanup
Policy recommendations and safe rollout approach
Least privilege review and stale admin cleanup
Documented changes and risk reduction summary
For companies that need hands-on remediation after an assessment, incident, insurance questionnaire, or before moving into managed monitoring.
Roles, responsibilities, escalation path, contact tree
Containment, evidence, client notifications, recovery
Isolation, backups, legal, insurance, restoration
MFA, EDR, SAT, backups, policies, diagrams
Cyber insurance and client security questionnaires
Guided incident drill with after-action notes
For companies that need playbooks, tabletop preparation, control evidence, and insurance-ready documentation before something happens.
Black Tower Cyber should not look like a broad MSSP. The cleaner model is: BTC investigates and hardens, then hands clients into a managed monitoring service when they need ongoing MDR, identity monitoring, SIEM visibility, phishing training, and alert escalation.
Endpoint monitoring and managed response.
Microsoft 365 identity threat detection.
Log visibility and security event correlation.
Security awareness and phishing training.
Start with a short scoping call. We will determine whether you need emergency response, an ATO/BEC investigation, a Microsoft 365 assessment, tenant cleanup, readiness work, or SOCaaS handoff.