- Resources
- Why a Minimum Security Baseline is essential
Why a Minimum Security Baseline is essential
Written by Anthony McMahon, July 2026
The days when cybersecurity was an individual business concern are long gone. Instead, every organisation is part of a broader whole, where staying secure becomes something like worker’s solidarity: an injury to one is an injury to all. As a Managed Service Provider, we have a clear responsibility and duty of care - every client environment must meet a minimum-security standard. It’s essential so your business operates in an orderly fashion, because if you’re hacked consequences flow to your customers, your partners, and your suppliers.
This point is driven home by Microsoft, which has noted that up to 98% of hacks are preventable by focusing on the basics. Those basics are a minimum baseline.
While we have always maintained a high standard of security including our ISO27001 certification, we've now defined minimum security baseline for all our customers.
What this means in practice is that managing security risk requires that every environment we support meets a defensible, modern standard protecting not only your direct interests (data, applications and business processes) but also those of every member of your wider interconnected digital ecosystem.
Why now?
As an MSP, we manage endpoints, identities, cloud platforms, backups, networks, and administrative access across many organisations at once. We also work across multiple vendors and with a variety of service delivery partners. This is fundamental to our value proposition of efficiency and scale in technology service delivery. It also means we are responsible for the security of many of the services, technologies and data your organisation relies on for the conduct of business.
If your environment lacks fundamental protections, it presents a risk to your business as well as ours; as an MSP, we really, really don’t want your technology compromised because, quite frankly, aside from being unpleasant and expensive for you, it isn't a good look for us either!
While highly unlikely given how we structure service delivery, compromised credentials, unmanaged devices, weak email security, or insufficient backups can even allow threats to move laterally into tools, processes shared across environments.
A minimum security baseline is among the most effective ways to reduce risk. It establishes clear boundaries, limits ‘blast radius’, and maintains consistent basic containment controls. It’s essential for your organisation, and essential for ours.
What a Security Baseline actually means
A baseline defines the floor, not the ceiling, and includes:
- Reliable, monitored backups to support recovery
- Foundational endpoint and device protection
- Identity and access hygiene
- Core email and perimeter protections
- Consistent patching and lifecycle management.
These controls do not eliminate risk (full elimination is impossible) but instead substantially reduce the likelihood of compromise. That’s confirmed by the linked Microsoft study above, as well as bitter experience which confirms that most hacks happen in the absence of basic security protocols.
Importantly, your organisation already has some or all of the elements necessary for a Minimum Security Baseline in place. Just as importantly, many of these elements are more a question of configuration rather than any new product or service.
A baseline simply formalises what modern IT environments should already expect as standard.
Managing operational risk
Coming back to Lancom Technology’s point of view: For any MSP, supporting environments that fall below a minimum standard introduces operational risk, reputational risk, and ethical risk. It becomes increasingly difficult to guarantee service quality, incident response effectiveness, or even basic reliability when foundational controls are missing.
A clearly defined baseline creates transparency. You know what is expected, we know what we are accountable for, and conversations shift from whether security is required to how far your organisation might need to go beyond the minimum.
Essentially, a Minimum Security Baseline establishes a trust framework protecting individual clients, strengthening the broader supply chain, and enabling us to deliver reliable, resilient services in an increasingly hostile digital world.
About Anthony McMahon
As Chief Customer Offier, Anthony McMahon leads our Customer Success teams, focusing on pairing technology to business strategy and driving exceptional customer experiences, maximizing retention, and driving growth. As a strategic thinker, Anthony applies forward looking technology planning, shifting from reactive to proactive service delivery, while aligning budgets and achieving more from every dollar.
Our Microsoft Expertise
With multiple Microsoft Partner designations, Lancom Technology are experts at designing, building, migrating and operating complex Microsoft Azure environments and delivering successful cloud projects for companies of all sizes, across all industries. Contact us to find out more.