Services Overview

Identity & Zero Trust

Identity & Zero Trust Architecture

Zero Trust is a security model that trusts no user or device by default – regardless of whether they are inside or outside the corporate network. Every access request is individually verified, authenticated and limited to the minimum required permissions (Least Privilege). The NIST framework SP 800-207 is the foundation; Microsoft implements it via Entra ID, Intune and Defender for Endpoint.

  • Microsoft Entra ID – Design, Hardening & Migration
  • Conditional Access & Risk-based Authentication
  • Privileged Identity Management (PIM)
  • Multi-Factor Authentication & Passwordless
  • Device Compliance & Microsoft Intune MDM
  • Zero Trust Maturity Assessment
NIST SP 800-207 Implementation follows the official NIST guidelines and Microsoft's Zero Trust Adoption Framework.
Request Consultation

Comparison

Zero Trust vs. Classical Perimeter Security

Zero Trust vs. Classical Perimeter Security
Criterion Perimeter Security Zero Trust
Trust model "Inside the network = trusted" Never trust, always verify
Security perimeter Network boundary (firewall) Identity + device + context
Remote work VPN-dependent, error-prone Natively supported
Lateral movement Hard to detect Blocked by micro-segmentation
Cloud suitability Limited (designed for on-premises) Cloud-native optimised

Sources: NIST SP 800-207 Zero Trust Architecture · Microsoft Zero Trust Adoption Framework

Data Security & Purview

Data Security & Microsoft Purview

Microsoft Purview is the integrated data protection and compliance platform in Microsoft 365, helping organisations discover, classify and protect sensitive data automatically – without separate tools. From Sensitivity Labels to Data Loss Prevention (DLP), eDiscovery and Insider Risk Management: Purview covers the entire data protection lifecycle, fully integrated into your existing M365 environment.

  • Information Protection & Sensitivity Labels
  • Data Loss Prevention (DLP) – Policies & Fine-Tuning
  • Automatic Classification & Trainable Classifiers
  • eDiscovery & Audit Logs
  • Insider Risk Management & Communication Compliance
  • Data Lifecycle Management & Retention Policies

Sources: Microsoft Purview Documentation · ENISA – Data Protection Glossary

Request Consultation

Compliance Consulting & Implementation

Compliance Consulting & Implementation Support

NIS2 compliance means demonstrably implementing technical and organisational measures – not just documenting them. Regulatory requirements from NIS2, ISO 27001, GDPR and BaFin are analysed, prioritised and technically implemented. The result: audit-ready compliance documentation without an internal compliance team. Experience from Healthcare, Banking, Energy and Public Sector.

  • NIS2 Readiness Assessment & Implementation Support
  • ISO 27001 Preparation & Technical Measures
  • GDPR Evidence & Technical Protection Measures
  • BaFin- & HIPAA-compliant Data Protection Architecture
  • Microsoft Purview Compliance Manager
  • Supplier Risk Assessment & Documentation
Request Consultation

AI Advisory & Adoption

AI Advisory & Adoption

Strategy consulting and secure implementation for organisations that want to deploy AI tools – without losing control of their data. From readiness analysis to production operations.

  • AI Readiness Assessment & Strategy Consulting
  • Copilot for M365 – Governance, DLP & Secure Rollout
  • Azure OpenAI & Custom AI Implementation
  • AI Risk Analysis & EU AI Act Compliance
  • Data Governance for AI Projects (Zero Trust)
  • AI Security Training, Auditing & Awareness
Speaker Experience Speaker at CloudIdentitySummit 2024 & 2025. Certified: AB-900 (Copilot & Agent Administration), Copilot for Security Ninja, Applied Skills M365 Copilot.
Request Consultation

Cloud & Workplace

Cloud & Workplace

Microsoft 365 migrations, tenant hardening and Exchange Online operations – carried out according to BSI baseline protection with transparent documentation. Also hybrid environments (On-Premises + Azure) and Infrastructure as Code with Terraform.

  • M365 Migration & Tenant Hardening (BSI Baseline)
  • Exchange Online & Teams Governance
  • Hybrid Migrations (On-Premises → Azure / M365)
  • Azure Landing Zone & Terraform IaC
  • Microsoft Intune MDM (Windows, iOS, Android)
  • Azure Virtual Desktop (AVD / PAW)
Request Consultation

Cloud Sovereignty · Delos

Cloud Sovereignty in the DACH Region

Sovereign cloud infrastructure for regulated industries and critical infrastructure operators – based on Delos Cloud with Microsoft. As a Managed Service Provider (MSP) we plan, migrate and operate sovereign Microsoft environments compliant with BSI C5 and GDPR. Your data stays within the DACH region.

  • Delos Cloud Strategy & Migration Projects (Microsoft)
  • Data Sovereignty & EU Data Boundary – data stays in Germany
  • BSI C5 Attestation & ISO 27001 Preparation
  • Managed Service Provider (MSP) for sovereign DACH environments
  • KRITIS- and BaFin-compliant cloud architecture
  • Tenant Segregation & Air-Gapped Configurations
Delos Cloud Sovereign cloud infrastructure from Microsoft with Delos – BSI Grundschutz-compliant, operated in Germany. Certified to BSI C5 and ISO 27001. Note: Delos Cloud is available exclusively to public sector organisations (federal, state, and municipal authorities) and is currently not available to private-sector companies.
Request Consultation

Frequently Asked Questions

Answers on Zero Trust, Microsoft Purview, NIS2 and how we work.

What is Zero Trust and how does it work?

Zero Trust is a security model that trusts no user or device by default – regardless of location. Every access request is verified, authenticated and limited to minimum permissions. Implementation uses Microsoft Entra ID (identity), Intune (device compliance) and Defender for Endpoint (endpoint security) – aligned with NIST SP 800-207.

How does a Zero Trust Maturity Assessment work?

The assessment has three phases: inventory (analysis of current configuration), gap analysis (identifying weaknesses and risk-based prioritisation) and roadmap (concrete implementation plan with quick wins). Duration: typically 2–4 weeks. Output is a written report with clear next steps.

What is Microsoft Purview and why do I need it?

Microsoft Purview is the integrated data protection and compliance platform in Microsoft 365. It automatically classifies, labels and protects sensitive data via Sensitivity Labels, DLP policies, eDiscovery and Insider Risk Management. For organisations with GDPR, NIS2 or ISO 27001 obligations, Purview is often the most efficient solution because it requires no separate tools.

Which industries and company sizes does Novesso serve?

Novesso advises companies from around 50 employees in regulated industries: Healthcare (HIPAA, GDPR), Banking & Finance (BaFin, DORA), Energy & Critical Infrastructure (NIS2), Public Sector (BSI Baseline) and mid-market in the DACH region. Project scope and engagement depth are agreed individually.

Can't find the right topic?

Let's talk. First consultation free – I'll analyse your situation and tell you honestly whether and how I can help.