Last updated: August 18, 2026
Security works better when the basics are consistent. Vulpine maintains a documented
baseline for the systems we manage so common protections are not left to chance or applied
differently from one device or client to another.
The exact controls vary by service package, licensing, platform, and regulatory
requirements. During onboarding we document the current state, identify gaps, and build the
work needed to bring the environment into alignment.
Our managed-security baseline
Managed endpoints
Supported operating systems, active monitoring and patch management, managed endpoint protection, and full-disk encryption where supported. Devices that can no longer be secured or reliably managed are documented for replacement or remediation.
Identity and MFA
Multi-factor authentication is enforced for administrative access, remote access, and supported cloud services. Administrative privileges are limited to people and systems that require them, and legacy authentication is disabled where supported.
Microsoft 365 and cloud security
Email and collaboration environments are configured with appropriate anti-phishing, anti-malware, access, sharing, forwarding, and audit controls based on the client's licensing and service package.
Network security
Business networks use managed firewalling, maintained firmware, secure remote-access methods, and separation of guest or untrusted devices where appropriate. Internet-facing services are not exposed unnecessarily.
Patching and vulnerability management
Operating systems and managed applications are kept current through automated patching and monitoring. Critical vulnerabilities are reviewed promptly, with remediation prioritized according to severity, exposure, and operational impact.
Backup and recovery
Covered systems and cloud data are backed up according to the client's service package. Backups are monitored, recovery procedures are documented, and scheduled restore testing is used to verify that protected data can actually be recovered where included in the service package.
Security awareness
Where included in the service package, users receive ongoing security-awareness training and phishing simulations. Security controls are reinforced with practical guidance instead of relying on training alone.
Incident response
Suspected compromises are investigated and contained as quickly as practical. Vulpine may isolate managed devices, disable access, reset credentials, or coordinate with other providers when necessary to protect the client environment.
Documentation and evidence
A security control is much more useful when you can prove it exists. We maintain
documentation appropriate to the services we manage, including configuration records,
security findings, backup and restore evidence, and other operational records used during
reviews, insurance renewals, and compliance work.
Exceptions
Not every environment can meet every control immediately. Legacy applications, vendor
requirements, unsupported hardware, and business constraints sometimes create exceptions.
When that happens, we document the issue, explain the risk, and recommend a practical path
forward rather than quietly treating the exception as normal.
Plain-English summary
This page is a plain-English summary of our general managed-security baseline, not a
guarantee that every listed feature is included in every package. It is not a contract. The
Master Services Agreement controls, followed by the Services Guide, and then the signed
Quote for client-specific commercial terms.