Get in touch

Your IT provider keeps the lights on. Nobody guards the door.

The operational layer is covered. Organisational oversight usually is not.

What you receive

A complete account and privilege review
A clear view of responsibilities outside provider scope
Inactive and orphaned accounts identified
Administrative access mapped and risk rated
A security design and prioritised remediation plan
Every finding explained and documented in full
44%¹
of larger NZ businesses (50+ staff) attacked in 2025. Financial losses up 118% in Q3 alone.
$500k²
proposed personal liability for directors of critical infrastructure operators under NZ reform.
99%³
of identity attacks blocked by phishing resistant MFA, per Microsoft's 2025 Digital Defense Report.
¹ Kordia NZ Cyber Security Report 2026 ↗ ² Bell Gully, Director Liability, March 2026 ↗ ³ Microsoft Digital Defense Report 2025 ↗
Most NZ businesses find the problem after something has gone wrong. The ones that act early avoid becoming the next case study.
Find hidden Microsoft 365 risk →
Device governance
Licensing strategy
Vendor evaluation
Microsoft 365 and Entra ID
Identity governance
IPP 3A
ISO 27001 aligned
No lock in
NZ specialist
Everything yours to keep
Device governance
Licensing strategy
Vendor evaluation
Microsoft 365 and Entra ID
Identity governance
IPP 3A
ISO 27001 aligned
No lock in
NZ specialist
Everything yours to keep
Typically outside the scope of a standard managed service agreement

Infrastructure support is covered.
Governance oversight is not.

Standard managed service agreements keep systems available. Ownership of identity, security decisions, and organisational risk often remains undefined.

Standard MSP scope
Outside standard MSP scope
Devices and software staying online
Former staff accounts still active in the system
Microsoft 365 email and helpdesk support
Who actually has admin access right now and why
Backups being configured
Whether backups have ever actually been tested
Software updates and patching
Brand impersonation and domain monitoring
Day to day operational issues
Governance documentation and director liability exposure

Access sprawl across MSPs and third parties is one of those risks that only becomes visible when something goes wrong. Good to see someone building a practice specifically around that gap.

Laurent Halimi Founder and CEO, CYBERR

How PureLayer works

One operating model.
Two distinct layers.

Strategic layer
PureLayer
Independent security oversight.
Security architecture designed around the organisation before remediation begins. Identity, endpoint protection, backup, and cloud controls are selected and validated against business risk and compliance requirements.
Identity governance Risk remediation Security architecture Cloud configuration and implementation Compliance advisory Device governance Director visibility Transition and recovery ISO 27001 aligned architecture
Infrastructure provider
Essential infrastructure management.
Monitoring, patching, backups, and helpdesk remain essential services. PureLayer complements that work with independent oversight and can take responsibility for this layer directly when required.
Monitoring Patching Backups Microsoft 365 Device management

Source: MSP Trends 2026, Worksent, March 2026

When a provider relationship ends

When a provider relationship ends, organisations can be left without working backups, endpoint protection, complete documentation, or clear ownership. PureLayer restores visibility, designs the remediation plan, and carries out the technical work directly. Vendor relationships and approvals are managed throughout so the right controls return in the right order.

Identity and access governance

Find out who actually has
the keys to the business

01
Every account reviewed
Every user, administrator, service account, and shared mailbox assessed. Inactive identities, excessive privilege, Entra ID roles, and conditional access are reviewed.
A verified view of every identity and privilege
02
Systems and ownership mapped
Platforms, providers, credentials, and responsibilities documented in one organisational record.
Clear ownership across the environment
03
Prioritised remediation plan
Authentication, email security, and backup improvements defined in the order that matters most.
Practical direction based on business risk
04
Documentation yours to keep
Decisions, controls, responsibilities, and next steps documented in full. No lock in.
Knowledge remains with the organisation
Security architecture hardening

The uplift that closes
every open door.

Once the gaps are understood, each control is strengthened in sequence. The work covers identity, cloud configuration, devices, protection, recovery, and staff capability, aligned with the control areas ISO 27001 expects.

01
Identity and access
Microsoft Entra ID configured correctly. MFA enforced, administrator roles reviewed, and privilege reduced to what each person needs.
Identity controls applied consistently
02
Cloud configuration
Microsoft 365 settings reviewed across mail flow, domain records, conditional access, and licensing, then configured to match how the organisation operates.
Configuration matched to the organisation
03
Device management
Microsoft Intune brings devices under consistent policy, with security settings applied and monitored centrally.
Consistent control across every enrolled device
04
Endpoint protection
Microsoft Defender for Business deployed across enrolled devices to detect malware, ransomware, and unusual activity.
Endpoint protection working across the fleet
05
Firewall and network
Firewall and network settings reviewed, documented, and hardened where controls are missing or no longer appropriate.
Network controls verified
06
Backup and recovery
Backup implemented for email, files, and Teams content, kept separate from the live environment and tested so recovery is possible when needed.
Recovery designed and verified
07
Password management
A password manager introduced across the organisation, replacing exposed or shared records with a controlled vault.
Secure handling of shared credentials
08
Staff training
Practical training delivered through a private digital hub with guided learning, quick references, and completion tracking so the new controls hold in daily work.
Staff understand the controls they use
09
Ongoing visibility
Microsoft Secure Score, audit logging, alerting, and Entra risk signals configured to provide a continuing view of the environment.
Ongoing visibility after the uplift
Ongoing threat advisory response

When a vendor flags a threat,
someone actually checks it.

Insurers, vendors, and CERT NZ issue security advisories constantly. PureLayer assesses what applies to the organisation, checks the actual environment, and gives a clear response based on evidence.

01
Advisory assessed
The notification is mapped against the organisation's systems, services, and infrastructure to establish whether it applies.
Relevance established before action begins
02
Exposure verified
Headers, DNS records, ports, versions, and configurations are checked directly to confirm the exposure.
An answer supported by evidence
03
Ownership resolved
Where ownership or purpose is unclear, the gap is escalated and resolved before the advisory is closed.
Every affected system accounted for
04
Response documented
What was checked, what was found, and what was done is recorded for the board, insurer, or auditor.
A clear record of the decision and response
What actually changes

Before the engagement.
After the engagement.

Microsoft 365 environment before and after a PureLayer governance engagement Two panels showing the state of a Microsoft 365 environment before and after engagement. Before Typical Microsoft 365 environment After Post governance engagement User accounts Unknown. Never fully audited. Former staff access Multiple accounts still active Admin access Shared. Undocumented. Untested. MFA enforcement Not enforced for any account Email authentication SPF, DKIM, DMARC absent Governance documentation None exists Identity Secure Score Typically 25% or below User accounts Every account verified and documented Former staff access All identified, staged for closure Admin access Named owners. Privileges mapped. MFA enforcement Enforced. Conditional access defined. Email authentication SPF, DKIM, DMARC configured Governance documentation Full framework. Organisation owns it. Identity Secure Score Remediation plan in place
What changes after the assessment

Organisational exposure
identified and owned.

01
Former staff accounts resolvedFormer staff accounts are identified, documented, and prepared for closure.
02
Responsibility gaps exposedEvery responsibility outside standard provider scope is named, prioritised, and assigned.
03
Ownership establishedSystems, accounts, credentials, and provider relationships are documented with clear owners.

Client reviews

★★★★★
5.0 · Google Reviews
★★★★★

"Absolutely outstanding service. Lee went above and beyond to help us resolve a serious issue, and did it quickly, professionally, and without any fuss. What really stood out was the level of care and attention to detail and genuinely wanted the best outcome for us. Communication was clear the whole way through, and handled everything with confidence and expertise, which gave us a lot of peace of mind during a stressful situation. It's rare to come across someone this reliable, I wouldn't hesitate to recommend Lee to anyone needing help in this space."

G
Google Review
Verified client · 5 stars
★★★★★

"Outstanding service from Lee and she's very knowledgeable on how to protect businesses from cyber threats, definitely recommended!"

W
Will · Local Guide
Verified client · 5 stars · 11 weeks ago
★★★★★

"Lee is amazing and very knowledgeable. Highly recommend."

M
Marie Healy
Verified client · 5 stars
Start the conversation

Start with
an assessment.

Share your name and email to begin. Nothing changes without your approval.

Responds within 24 hours, usually the same day.
All engagements are confidential.
Information handled under the NZ Privacy Act 2020.
Or email directly: lee@purelayer.co.nz

No obligation. Lee responds within 24 hours.

Thanks, that is through to Lee.
She will be in touch within 24 hours.
1