05Service line
IT infrastructure services and managed IT, designed and run securely
Onion Infosec designs, builds and manages servers, networks, endpoints, directories and Microsoft 365 for organizations that want IT run to a security standard. Least privilege, measured patching, hardened baselines and tested restores are the default for every system we manage.
- Line
- 05 of 07 · IT
- Shape
- Design → Build → Identity → Maintain → Recover
- Delivery
- Project, retainer or managed service
01Context
What the IT line covers
The IT line covers the systems an organization works on every day: servers and virtualization, networks, laptops and mobile devices, directories and identity, and Microsoft 365. It also covers the monitoring, patching, hardening and backup that keep those systems healthy. Consulting and architecture work addresses new offices, migrations, integrations and modernization.
Work is delivered as projects, as ongoing IT operations, or as a co-managed arrangement alongside an internal IT team. Delivery is remote and on site. Day-to-day support under a service agreement is described under Managed Services & Support.
- Routine hygiene prevents common incidents
- Unpatched servers, flat networks, shared administrator passwords and untested backups are the openings that commodity attacks rely on. Patching, hardening and least privilege close them at low cost.
- One team owns uptime and attack surface
- When IT and security sit with separate providers, gaps form at the handover between them. A single team accountable for both availability and exposure removes that gap.
- Recovery has to be rehearsed
- A backup counts only when a restore has been tested, and a disaster recovery plan only when it has been exercised. Both are operational disciplines with a schedule and an owner.
02Approach
How we work
Each engagement begins with a baseline: an asset inventory, a configuration review and a risk snapshot of the current estate. Urgent gaps such as a patching backlog, doubtful backups and loose administrator access are closed first.
Systems are then brought to documented, hardened standards and operated under change control, with regular reporting on health and security posture.
01
Secure by default
Least privilege, hardened baselines and logging are the starting configuration of every system we build or manage. They are part of the build, not a later project.
02
Documented and rebuildable
Configurations, network diagrams and procedures are written down and kept current. Where the platform allows, configuration is held as code.
03
Change with control
Changes are planned, reviewed, scheduled and reversible. Rollback steps are written before the change window opens.
04
Measured, then reported
Patch coverage, backup success, restore tests and inventory accuracy are measured and reported on a regular cadence.
03Capabilities
How IT work is organized.
Design
Architecture and standards for the estate.
Build
Servers, networks and the workplace.
Identity
Directories and the collaboration platform.
Maintain
Monitored, patched and hardened on a cadence.
Recover
Backups that restore and plans that are rehearsed.
Infrastructure & Servers
Design, build and lifecycle management of on-premises, virtual and hybrid server estates. Every build follows a hardened baseline and is documented so that it can be rebuilt.
- Server managementProvisioning, patching, hardening and lifecycle management for Windows and Linux servers. Each server has an owner, a baseline and a patch record.
- Virtualization and hybrid infrastructureDesign and operation of VMware, Hyper-V and hybrid cloud hosting, including capacity planning and host hardening.
- Storage and file servicesFile server, NAS and SAN administration with permission reviews and quota management. File shares are migrated to SharePoint or cloud storage where that fits.
- Infrastructure builds and refreshesPlanned builds, hardware refreshes, data center moves and server migrations, each with a cutover plan and rollback steps.
Networks
Wired, wireless and wide-area networks designed with segmentation and managed under change control.
- Network design and segmentationLAN, WAN and Wi-Fi design with VLAN and zone separation between users, servers, guests and management interfaces. Delivered as diagrams, addressing plans and configuration standards.
- Firewall and VPN managementRule-base administration, periodic rule reviews, firmware updates and remote-access VPN configuration on platforms such as Cisco, Fortinet, Palo Alto Networks and SonicWall.
- Switching, routing and wireless administrationDay-to-day administration of switches, routers and access points, with configuration backups and a record of every change.
- Secure remote accessIdentity-based remote access with MFA and device checks. It replaces shared VPN credentials and exposed remote desktop services.
- Network monitoringAvailability, bandwidth and device health monitoring, with alert thresholds tuned to cut noise.
Endpoints & Asset Management
Laptops, desktops and mobile devices provisioned to a standard, kept compliant and tracked from purchase to disposal.
- Endpoint managementDevice provisioning, configuration baselines and compliance policies through Microsoft Intune or an equivalent MDM platform.
- Mobile device managementEnrollment, app protection and conditional access policies for corporate and personally owned phones and tablets.
- Endpoint protection deploymentRollout and policy configuration of EDR and disk encryption. Coverage reports show which devices remain unmanaged.
- Hardware and software asset managementAn inventory of hardware and software with lifecycle tracking and license position. The inventory is the reference for patching and vulnerability work.
- Device lifecycleStandard images or Windows Autopilot profiles for new devices, joiner and leaver handling, and secure wipe before reuse or disposal.
Identity & Directory
Operation and cleanup of the directories that control access to everything else. Work on Entra ID, Active Directory and IAM follows least privilege and is coordinated with the identity security practice.
- Microsoft Entra ID administrationTenant, user, group and application management, upkeep of conditional access policies and privileged role hygiene.
- Active Directory operationsDomain controller health, group policy, DNS, delegation cleanup and retirement of legacy protocols. Changes are staged and have rollback plans.
- Identity lifecycle automationJoiner, mover and leaver workflows linked to HR data, so that accounts and access are created, changed and removed on time.
- Single sign-on and MFA rolloutSSO for SaaS and internal applications using SAML and OIDC, with phishing-resistant MFA rolled out in phases.
- Access reviewsScheduled reviews of group membership, administrator roles and shared mailbox access. Removals are tracked to completion.
Microsoft 365
Administration of the Microsoft 365 tenant by people who also harden it. Configuration follows a security baseline from the first day.
- Tenant administrationLicensing, user and group management, mail flow, and Teams and SharePoint administration under change control.
- Exchange Online and emailMail routing, shared mailboxes and retention, plus SPF, DKIM and DMARC configuration for every sending domain.
- Migration to Microsoft 365Mailbox, file share and collaboration migrations from on-premises or other platforms. Users move in batches, with communication and rollback steps for each batch.
- SharePoint and Teams governanceProvisioning rules for sites and teams, external sharing settings, guest access reviews and lifecycle policies.
- Security and compliance configurationBaseline configuration of Defender for Office 365, sharing controls, audit logging, retention and data loss prevention policies.
Monitoring, Patching & Hardening
The recurring work that keeps an estate healthy. Each activity has a schedule, a coverage measure and a report.
- Infrastructure monitoringAvailability, capacity and health monitoring for servers, networks and services. Alerts are routed to the person who can act on them.
- Patch managementRisk-ranked patching of operating systems and third-party software on a set cadence, with coverage reports and an exception list.
- Hardening baselinesCIS-aligned configuration baselines for servers, endpoints and network devices, applied, documented and checked for drift.
- Vulnerability remediationScanner findings are triaged by exploitability and exposure, assigned to owners and closed with verification.
- Log forwarding for security monitoringSystem, directory and firewall logs are configured so that a SOC, ours or yours, receives usable telemetry.
Backup & Disaster Recovery
Backup and recovery designed around stated recovery objectives and proven by restore tests.
- Backup design and implementationBackup architecture for servers, Microsoft 365 and cloud workloads, with immutable or isolated copies and separate administrative credentials.
- Restore testingScheduled file, system and application restores with recorded results, so that recovery times are known before they are needed.
- Disaster recovery planningRecovery objectives agreed with the business, a documented DR plan and recovery runbooks for priority systems.
- DR exercisesPlanned failover and recovery exercises. Findings from each exercise are fed back into the plan.
- Backup monitoringDaily review of job status, rerun of failed jobs and tracking of storage capacity, available as a managed service.
IT Consulting & Architecture
Advice and design for changes to the IT estate, written by people who also build and operate it.
- IT assessment and roadmapCurrent-state review of infrastructure, tooling, cost and risk, delivered as a prioritized roadmap with effort estimates.
- Infrastructure architectureTarget designs for server, network, identity and end-user computing estates, including hybrid and cloud options.
- IT security architectureSecurity requirements designed into IT changes such as new offices, mergers, integrations and vendor onboarding.
- Modernization and migration planningPlans for retiring legacy systems, consolidating tools and moving workloads to cloud, with dependencies and sequencing mapped.
- Compliance preparation for ITIT controls are mapped to frameworks such as ISO 27001, SOC 2 and the CIS Controls, and evidence collection is built into routine operations.
04Process
How an IT engagement runs.
Baseline
Asset inventory, configuration review and risk snapshot of the current estate.
Stabilize
The urgent gaps are closed first: patching backlog, backup integrity and administrator access hygiene.
Standardize
Hardened baselines are applied, procedures are documented and the estate is brought under monitoring.
Operate
Day-to-day operations run under change control, with regular reporting on health, tickets and security posture.
Improve
Regular reviews set the modernization, cost and risk-reduction priorities for the next period.
What you receive
- Asset and configuration inventory
- Network diagrams, addressing plans and system documentation
- Hardening baselines, applied and documented
- Patch coverage and backup integrity reports
- Disaster recovery plan with tested recovery procedures
- Architecture designs and a prioritized roadmap
- Regular service and security posture reports
05Technical depth
Typical IT engagements, technology and methods.
IT baseline assessment
Short fixed-scope review that produces an asset inventory, a configuration and risk snapshot, and a prioritized plan.
Infrastructure or migration project
Defined project with design, build, cutover and handover phases. Examples are a Microsoft 365 migration, a network redesign or a server refresh.
Ongoing IT operations
Managed service under a service agreement that covers monitoring, patching, administration and reporting, with regular service reviews.
Co-managed IT
Shared operating model in which Onion takes defined areas, such as infrastructure and security tooling, while your team keeps applications and users.
Backup and DR program
Design and implementation project followed by a recurring schedule of restore tests and recovery exercises.
Technology areas
Servers and virtualization
Network and firewall
Identity and directory
Workplace and endpoint
Monitoring and automation
Backup and recovery
Technologies are named to describe the work. Naming a product does not indicate a commercial partnership.
Frameworks and methods
CIS Benchmarks
Configuration baselines for operating systems, network devices and Microsoft 365.
CIS Controls
Sets the order of hygiene work: inventory, patching, access control and backup.
ITIL practices
Structure for incident, change, problem and asset management.
ISO/IEC 27001 Annex A
Maps IT operational controls to the evidence auditors expect.
NIST SP 800-40
Reference for patch management planning.
ISO 22301
Reference for continuity planning and recovery objectives in DR work.
Microsoft security baselines
Starting configuration for Windows, Entra ID and Microsoft 365 hardening.
06Across lines
How security is built into IT work.
Every system Onion builds or manages starts from a hardened baseline, least-privilege access and logging that a SOC can use. Directory changes are coordinated with the identity security practice, and Microsoft 365 follows the Microsoft security baseline. Scanner findings flow into vulnerability management. When something suspicious appears, the same organization provides security operations and incident response.
07Questions
IT: questions we are asked
Security is the default configuration of everything we manage. Hardening, least privilege and usable logging are applied from the start, and the same organization can investigate when something suspicious appears.
Yes. In one common model Onion runs infrastructure and security tooling while your team owns applications and users. In another, Onion provides project capacity and after-hours cover. Responsibilities are written into a shared matrix.
Yes. Modern endpoint management, identity-based access and secure remote connectivity are part of standard operations.
You do. Inventories, diagrams, baselines, scripts and runbooks are handed over and kept current, so that your team or another provider can run the environment.
Delivery is remote and on site. On-site work is scheduled for builds, migrations, network changes and hardware tasks, and is agreed in the scope.
