Hope
Shared passwords, personal laptops, MFA on nothing. A questionnaire answered with optimism.
Is MFA on everywhere. Is there a password manager. Are devices protected. Does your email prove it's you. Has the team been trained. Most organizations can say yes to two. Protected Workplace does all five, properly, in six weeks, and keeps them true, with a report you can hand to the insurer.
Built for organizations that have outgrown "someone will sort it."
Pairs with Backups. Together they are the security pair almost every organization is missing.
Yes to all five. Report attached, dated this quarter. Premium held.
Most organizations we meet have cyber insurance.
Half couldn't prove what they signed.
Works with what you already run.
Business Premium or Workspace does most of this when it's actually configured.
1Password and awareness training fill the rest.
Almost every breach in an organization your size starts with a password, a phish or an unmanaged laptop. The fixes are not exotic. They are the five things every insurer asks about, done properly and kept true, with evidence. That's the whole module.
Five yeses
you can prove.
Pairs with Backups: the two things that make a bad day survivable.
Buying the licences is the easy part. Having all five switched on, for everyone, and proven, is what's missing.
Shared passwords, personal laptops, MFA on nothing. A questionnaire answered with optimism.
Business Premium or Workspace paid for. MFA on email only. Some laptops managed. A password manager two people use.
MFA enforced everywhere. One password manager, everyone. Every device encrypted and wipeable. Email authenticated. Team practised. Quarterly report.
We configure the five basics across every account and device, run practical awareness training, and produce the report that answers the insurer.
MFA enforced for every account by policy, not by asking. One password manager for everyone, shared vaults replacing the shared doc. Every laptop and phone enrolled, encrypted and wipeable, with the unknown ones found. Email authentication (SPF, DKIM, DMARC) set to enforce so nobody can send as you. Endpoint protection on, monitored.
A 60-minute session built on your organization's real scenarios: the spoofed CEO invoice, the fake Teams login, the vendor who changed bank details. Then a monthly simulated phish so the lesson stays fresh. Click rates tracked by team, not by name, and the people who report phishes get thanked.
A one-page security posture report every quarter: the five basics, their status, the evidence, what changed. Written to answer the insurer's questionnaire line by line. Monthly checks that nothing drifted: new devices, new accounts, exceptions. Access reviewed when people leave.
Measured, not promised. Every one of these is checked with you before we call it done.
MFA enforced, one password manager, every device encrypted and wipeable, email authenticated, endpoint protection on. For everyone, by policy.
Training on your real scenarios, a monthly simulated phish, click rates tracked by team. The lesson stays fresh because it keeps being tested.
One page, every quarter: status, evidence, what changed. Written to answer the questionnaire line by line, so the 'yes' is true.
Protected Workplace stops most bad days from starting. Backups makes the ones that start survivable. Most organizations need both and have neither.
Security that depends on people remembering doesn't hold. These rules make it hold, agreed in week one.
MFA, encryption and the password manager are set by policy. Nobody can opt out by being busy.
If it touches organization data, it's enrolled. Unknown devices lose access until they are.
Access removed, devices wiped or returned, logged. No ex-employee with a live login.
If it isn't in the report with a date, it isn't done.
The prompts, the agents, the rules, the templates, the data and the accounts. Everything is set up in your tenant, in your name. Leave any time and take all of it; nothing GoodOps builds is a reason to stay.
Three questions: which of the five basics are actually on for everyone, what did you tell your insurer, and what's already in your Microsoft or Google plan unused? Every tool lands in one of four states. That list is the plan.
Business Premium or Workspace includes device management and protection nobody configured. We switch it on.
e.g. Intune, Defender for Business, Workspace endpoint managementMFA on email only; a password manager two people use. We make it everyone, by policy.
e.g. Partial MFA, shared password docAn antivirus, a VPN and a trial of something. We replace them with the five basics.
e.g. Legacy antivirus, consumer VPN, trialsA tested backup or a managed provider you trust. We include it in the report.
e.g. Managed backup, existing MDM done rightGoodOps answers its own insurer from the same quarterly report. We'll show you ours.
You approve before we move to the next step. We start with one team or one cycle, prove it, then roll it out to everyone.
MFA enforced, password manager rolled out, devices enrolled and encrypted, email authentication set. Unknown devices found.
60-minute session on your real scenarios. First simulated phish. Click rates by team. Exits process built.
First quarterly posture report, written to the insurer's questionnaire. Exceptions closed. Owner's guide handed over.
Runs on your GoodOps retainer. Monthly drift checks and phish test; quarterly report; access review on every exit.
Then Protected Workplace runs on your GoodOps fractional retainer. Configuration, rollout and the first report are the module. Licences you already pay for do most of the work.
Software: Microsoft 365 Business Premium or Workspace Business covers devices and endpoint. 1Password CAD 8–12 and awareness training CAD 3–8 per person per month.
The things owners ask us on the first call.
Antivirus is one fifth of one of the five. Most incidents in organizations your size start with a password, a phish or an unmanaged laptop, none of which antivirus addresses. The five basics do.
Because you signed a questionnaire. If a claim is investigated and the 'yes' wasn't true, it can be denied. The quarterly report makes every yes provable with a date.
For a week. Then it's a tap. We roll it out with the training so people understand why, and the password manager removes more friction than MFA adds.
Managed lightly: the work apps are protected and wipeable, the personal side is untouched. Or we provide a work profile. Either way, no organization data on an unknown device.
No; that's the Backups module, and they pair. Protected Workplace stops most bad days from starting. Backups makes the ones that start survivable.
The 30-minute mini-diagnostic is free. From it you get a fixed price for the six-week rollout, typically CAD 8,000–15,000 depending on headcount and devices. Once live, it runs on your GoodOps retainer, including the monthly checks and the quarterly report.
Book the 30-minute mini-diagnostic. We'll check which of the five basics are really on, what you told your insurer, and give you a four-state plan for every tool.
A conversation about your organization.
Not a demo of software.