VSS - Virtual Support Services

    Zero Trust Cybersecurity

    A Practitioner's Approach to End-to-End Security Adoption. Enabling customers to adopt Zero Trust principles across Identities, Devices, Data, Applications, Infrastructure, and Networks.

    Get Free Assessment

    Never Trust, Always Verify

    The era of the perimeter-based security model is over. Attackers rely on harvested credentials, compromised identities, and the implicit trust organisations extend inside their networks. VSS's Zero Trust Cybersecurity Framework provides a structured, repeatable, and business-aligned methodology for guiding customers through a complete Zero Trust transformation.

    As a Microsoft Gold Partner with certified expertise across Microsoft Entra, Intune, Defender, Sentinel, and Purview, VSS translates the complexity of Zero Trust architecture into a practical, phased, affordable adoption journey — from initial strategy through to continuous operational maturity.

    End-to-end Zero Trust security across all six pillars.

    End-to-end Zero Trust security across all six pillars.

    VSS Zero Trust Framework

    Aligned to MCRA (April 2025), NIST CSF v2, and CISA Zero Trust Maturity Model.

    Six pillars: Identity, Devices, Applications, Data, Networks, and SecOps.

    Nine structured services from assessment to annual SLA support.

    15+ years of cybersecurity practice across East Africa.

    Core Security Services

    Zero Trust Assessment

    2–3 day readiness workshop

    Identity & Access

    Entra ID, MFA, PIM, Conditional Access

    Endpoint Security

    Intune, Defender for Endpoint

    Security Operations

    Sentinel SIEM, Defender XDR

    Verify Explicitly. Least Privilege. Assume Breach.
    Zero Trust Framework

    Verify Explicitly. Least Privilege. Assume Breach.

    Implement a security architecture that verifies every access request using all available signals — identity, device, location, and risk.

    Read More

    Six Pillars

    Identity to SecOps coverage.

    Four Stages

    Foundation to optimisation.

    Compliance

    KDPA, GDPR, NIST, ISO 27001.

    AI-Integrated

    Security Copilot & Sentinel AI.

    The Threat Reality

    Why the perimeter-based security model is over

    The era of the perimeter-based security model is over. Attackers no longer rely on sophisticated zero-day exploits — they rely on harvested credentials, compromised identities, and the implicit trust that organisations still extend inside their own networks. For VSS's customers across East Africa and beyond, this threat reality is compounded by:

    Credential-based attacks dominate — phishing, password spray, and Business Email Compromise (BEC) are the leading attack vectors targeting SME and mid-market organisations
    Hybrid workforce has permanently removed the concept of a 'trusted network' — users access corporate data from personal devices, home networks, and public Wi-Fi
    Cloud-first operations mean critical data no longer lives behind an on-premises firewall — workloads are migrating to Microsoft 365, Azure, and third-party SaaS
    Regulatory pressure is growing — Kenya's Data Protection Act 2019, GDPR, ISO 27001, and sector-specific compliance requirements create urgent obligations
    AI amplifies both threats and opportunity — AI accelerates attacker capability while offering defenders powerful tools through Microsoft Security Copilot, Sentinel AI, and Defender XDR

    The VSS Position

    VSS is uniquely placed as a Microsoft Gold Partner (MPN ID: 6255974) with certified expertise across Microsoft Entra, Intune, Defender, Sentinel, and Purview to translate the complexity of Zero Trust architecture into a practical, phased, affordable adoption journey that creates measurable value for customers at every stage. Grounded in 15+ years of cybersecurity practice and the Microsoft Cybersecurity Reference Architecture (MCRA), our framework provides a structured, repeatable, and business-aligned methodology for guiding customers through a Zero Trust transformation.

    What Zero Trust Actually Means

    Zero Trust is not a product — it is a security strategy and architecture philosophy

    Verify Explicitly

    Every access request — from any user, any device, any location — must be authenticated and authorised using all available signals: identity, device health, location, application, and data sensitivity.

    VSS Implementation

    Microsoft Entra ID + Conditional Access + MFA + Identity Protection

    Use Least Privilege

    Access is granted with the minimum permissions required, for the shortest time necessary. Just-In-Time (JIT) and Just-Enough-Access (JEA) replace standing broad permissions.

    VSS Implementation

    Entra ID Governance, PIM/PAM, Conditional Access, Intune Compliance

    Assume Breach

    Design every system assuming attackers are already inside. Minimise blast radius through network segmentation, encrypt everything, and operate with continuous detection, response, and recovery readiness.

    VSS Implementation

    Microsoft Sentinel, Defender XDR, Purview, Backup & Recovery, Incident Response Playbooks

    Five Zero Trust Business Scenarios

    Adapted from the Microsoft Security Adoption Framework (SAF)

    01

    Secure Remote & Hybrid Work

    Users working from unmanaged devices and uncontrolled networks; credential theft through phishing; password fatigue

    M365 Business Premium + Entra ID + Intune + MFA/SSO
    02

    Identify & Protect Sensitive Business Data

    Client data, financial records, and PII exposed through uncontrolled sharing, unsanctioned apps, and no classification

    Microsoft Purview AIP + DLP + Sensitivity Labels
    03

    Rapidly Modernise Security Posture

    No visibility into security health; unsure what is exposed; failing regulatory audits; no baseline to measure against

    Secure Score Assessment + Compliance Manager + Hygiene Baseline
    04

    Meet Regulatory & Compliance Requirements

    Growing compliance obligations under KDPA 2019, GDPR, ISO 27001, and sector-specific regulations

    Purview Compliance Manager + Audit + eDiscovery + Policy Automation
    05

    Prevent / Reduce Breach Damage

    No incident response plan; no detection capability; no segmentation; attackers can move laterally unchallenged

    Microsoft Sentinel SIEM + Defender XDR + Incident Response Playbooks

    Four-Stage Implementation Model

    Progressive stages aligned to the Microsoft SAF staging model

    Stage 1Weeks 1–4

    Foundation & Visibility

    Assess current state. Identify risks, gaps, and regulatory requirements. Establish MFA, SSO, and basic identity hygiene. Deploy Microsoft Secure Score. Set leadership expectations and define KPIs.

    Stage 2Weeks 5–12

    Controls & Hygiene

    Deploy device management (Intune), implement Conditional Access, introduce DLP and classification labels, inventory digital estate, begin compliance tracking.

    Stage 3Months 4–6

    Automation & Detection

    Deploy SIEM (Sentinel) and XDR capabilities. Automate labelling and DLP enforcement. Implement insider risk management. Establish security dashboards and threat hunting.

    Stage 4Month 7+

    Continuous Optimisation

    Passwordless authentication rollout. Extend protection to SaaS and on-premises. Formalise incident response playbooks. AI-assisted threat monitoring. Ongoing Secure Score reviews.

    The Six Zero Trust Pillars

    VSS implements controls across all six interconnected pillars, aligned to MCRA and NIST SP 800-207

    VSS Zero Trust Service Portfolio

    Structured services that can be scoped and combined to match each customer's budget, maturity level, and risk priorities

    ServiceDelivery FormatDescription
    Zero Trust Readiness Assessment2–3 Day WorkshopCurrent state architecture review across all six pillars. Secure Score baseline. Regulatory gap analysis. Prioritised remediation roadmap delivered as a formal written report with executive summary.
    Identity & Access Modernisation4–8 WeeksEnd-to-end Entra ID deployment: MFA, SSO, Conditional Access, Hybrid AD Connect, PIM. Includes device registration, basic Intune compliance, and knowledge transfer to IT admins.
    M365 Security Premium Uplift2–4 WeeksLicensing upgrade from M365 Business Standard to Premium. Activation of Defender for Business, Intune, AIP, and advanced compliance features included in Premium SKU.
    Data Protection & DLP Programme4–8 WeeksPurview sensitivity label taxonomy design, DLP policy deployment, Teams secure configuration, Compliance Manager regulatory tracking. Includes user training on data classification.
    Endpoint Security & Intune3–5 WeeksFull Intune MDM/MAM deployment: device enrolment, compliance policies, App Protection for BYOD, Defender for Endpoint EDR, and Conditional Access device compliance integration.
    Microsoft Sentinel SIEM Deployment4–8 WeeksSentinel workspace setup, data connector configuration, analytic rules, UEBA, incident management workflow, and 30-day threat hunting engagement. Includes incident response playbook templates.
    Zero Trust Network Access (ZTNA)2–4 WeeksMicrosoft Entra Private Access and Internet Access deployment replacing legacy VPN. Identity-aware network access control with device compliance enforcement.
    Security Awareness Training ProgrammeOngoingMicrosoft Cybersecurity Awareness Kit deployment, phishing simulation campaigns via Defender Attack Simulator, and quarterly training completion reporting.
    Annual Zero Trust SLA12-Month RetainerQuarterly Secure Score reviews, monthly Sentinel threat summary, patch management advisory, policy update service, and prioritised support SLA (P1: 1hr, P2: 4hr, P3: 8hr response).

    AI and Zero Trust — The Symbiotic Imperative

    AI and Zero Trust have a symbiotic relationship — each strengthens the other

    How AI Changes the Threat Landscape

    • AI amplifies attackers: More convincing phishing, automated credential stuffing, deepfake social engineering at scale
    • AI increases data sensitivity: AI queries against poorly governed data can surface sensitive information to unintended users
    • New attack surface: Prompt injection, data leakage, and model manipulation risks from AI applications

    How VSS Leverages AI for Defence

    • Security Copilot: AI-powered incident summarisation, threat intelligence correlation, and guided incident response
    • Sentinel AI Analytics: ML-powered multi-stage attack detection correlating signals across identity, device, and network
    • Defender XDR AI: Automatic investigation and correlation of alerts into incidents, reducing analyst triage time

    Four AI Security Imperatives (MCRA 2025)

    1.Expect, plan for, and track attacker use of AI
    2.Provide AI security policy and education to all staff
    3.Adopt AI-powered security capabilities (Security Copilot, Sentinel AI, Defender XDR AI)
    4.Protect business AI data and applications — ensure Purview data governance before enabling Copilot

    Regulatory Compliance & Zero Trust

    VSS maps Zero Trust controls to the regulatory frameworks most relevant to customers in East Africa

    Kenya Data Protection Act 2019

    Kenya

    Data discovery and classification (Purview), DLP policies, data subject rights support, encryption, audit trails, breach notification readiness

    GDPR

    EU / Global

    Sensitivity labels with rights management, DLP policies, data residency controls, eDiscovery and audit, consent and subject rights management

    ISO/IEC 27001

    International

    Comprehensive security management via Compliance Manager with built-in ISO 27001 assessment across all six Zero Trust pillars

    NIST CSF v2

    International

    Full alignment: GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER — mapped across all Zero Trust pillars

    PCI-DSS v4.0

    Payment Industry

    Network segmentation, encryption, strong authentication (MFA/CA), access logging (Sentinel), vulnerability management

    SWIFT CSP

    Financial Sector

    Privileged access security (PIM, PAWs), endpoint hardening, anomaly detection (Sentinel UEBA), network segmentation

    Trust Indicators

    Microsoft Gold Partner

    MPN ID: 6255974 with security specialisation

    Certified Professionals

    CEH, CCNP, CRISC, ITIL certified team

    15+ Years Experience

    Cybersecurity practice across East Africa

    Framework Aligned

    MCRA, NIST CSF v2, CISA ZT Maturity

    Success Story

    98% Reduction in Phishing Susceptibility

    A leading banking institution in East Africa partnered with VSS to transform their security posture. Through comprehensive security awareness training, Microsoft Defender deployment, and Zero Trust implementation, we dramatically reduced their vulnerability to social engineering attacks.

    98%
    Phishing Reduction
    Zero
    Breaches Post-Implementation
    100%
    DPA Compliance

    Recommended First Steps

    01

    Zero Trust Readiness Assessment

    2–3 day workshop producing a written readiness report with Secure Score baseline, gap analysis, and prioritised 12-month roadmap.

    02

    Sponsor Alignment Session

    90-minute executive briefing to align CEO/CIO/CISO on the Zero Trust business case, regulatory obligations, and investment roadmap.

    03

    Identity & MFA Quick Win

    Deploy Microsoft Entra MFA and Conditional Access for all users within 30 days — the fastest and most impactful security investment available.

    04

    Licensing Review

    Microsoft 365 licensing review to identify security features you've already paid for but haven't activated (Defender, Intune, AIP, Compliance).

    Start Your Zero Trust Journey

    Zero Trust is a journey, not a destination. Every customer starts somewhere — and every improvement matters. VSS meets you where you are, prioritises based on real risk, and delivers controls that work invisibly for your users.

    Get a Free Zero Trust Assessment

    Frequently asked questions

    Common questions about cybersecurity and Zero Trust for businesses in East Africa.

    Zero Trust is a security model based on the principle 'never trust, always verify.' Instead of assuming everything inside the corporate network is safe, every access request — from any user, device, or location — is authenticated, authorised, and continuously validated. VSS implements Zero Trust across six pillars: identity, devices, applications, data, networks, and security operations.

    Featured services and technologies

    Microsoft Defender XDR

    Identity Protection