Work securely with
Microsoft 365 and Azure.

Protect your data, fend off attackers and meet your compliance obligations – with information security consulting and managed services for the Microsoft cloud.

Detect.

An EDR agent on every device – Windows, macOS, Linux – and identity threat detection for Microsoft 365. Account takeovers, abused business mailboxes, unauthorised sign-ins: this is where they light up.

Decide.

Our partner SOC, specialised in security operations, analyses the situation – around the clock, outside your business hours too. A real attack, or a false alarm?

Contain.

Affected devices are isolated, compromised accounts locked, credentials reset. Afterwards you receive a short incident report with all relevant details.

How we work
Skip to the content ↓

How we
work.

Off-the-shelf solutions are often oversized and overpriced. So we take a close look at your individual environment and work out what exactly you need – and what you don't. Only our process is standard: five steps, proven many times over. The result is as individual as your business.

  1. 1

    Requirements

    In the first conversation we explain exactly how the process works step by step – and listen to what is going on at your company.

  2. 2

    Analysis

    Inventory of your current security posture: user management, email protection, stored data, threat detection.

  3. 3

    Architecture concept

    What you need – and what you don't. Guided by industry standards such as the CIS Benchmark for Microsoft 365.

  4. 4

    Implementation

    Best practices put in place: phishing-resistant MFA, hardened tenant configuration, protected email services and devices.

  5. 5

    Review / operations

    Continuous compliance checks, immediate action on deviations – or managed detection & response, every day.

What actually
lands on your desk.

We explain which security risks exist and how we remove them together in a way you really understand – so you know what you're buying. Three examples.

  1. Tenant audit · report excerptExample
    Recommendation 3 of 12High priority

    Multi-factor authentication is not phishing-resistant

    What this means for you
    An attacker with stolen credentials can intercept or trick an SMS or app confirmation. Accounts with access to financial data are affected.
    Recommendation
    Introduce phishing-resistant methods (e.g. hardware security keys), disable legacy authentication.
    Effort
    Manageable; we implement it for you on request.
  2. Managed Security Services · incident reportExample
    03:12Partner SOC

    Suspicious sign-in to Microsoft 365 – account locked, credentials reset.

    What happened
    Sign-in from a new device abroad, four minutes after a normal sign-in in Kassel.
    What we did
    Locked the account, ended sessions, reset credentials. 03:14.
    What you need to do
    Nothing tonight. We will align with you tomorrow morning and close the incident together.
  3. Managed services · monthly invoiceExample
    MonthlyTransparent

    Every line item traceable: what is protected and what was done – shown transparently every month.

    What is billed
    Only what is actually protected: seats, devices, identities and connected log sources.
    Services
    By actual time spent, rounded to whole hours – with an itemised statement of all work performed.
    Flexible
    Adjustable monthly, cancellable yearly. Add new devices or identities at any time.

Every report, every incident, every invoice follows the same logic: what happened, what we did, what you need to do. If the answer to the last one is "nothing", we say so.

Our services for small and
medium-sized companies.

Smaller companies often don't have the time to secure their Microsoft services themselves, and many IT providers lack specialised security expertise. That's where we come in.

Projects & consulting

Onboarding · Time & materials
  • Time & materials

    Flexible and transparent: we bill by actual time spent, rounded to whole hours. You only pay for work actually done – with an itemised statement, so you always know where progress and costs stand. Ideal when scope and requirements may change.

  • Microsoft tenant onboarding & baseline setup

    Security cannot be built on an unstable foundation. Before 24/7 monitoring starts, we bring your Microsoft 365 environment to a clean, secure state – so no hidden entry points from the past remain.

    • Tenant audit & cleanup – deep review of your Microsoft 365 and Entra ID configuration; security gaps, inactive accounts and outdated admin rights are cleaned up.
    • Security baseline – hardening to best practices, enforced MFA and strict conditional access policies.
    • Rollout & tool integration – Intune setup for Windows and macOS, deployment and integration of the Peak Data services.
    • Documentation & handover – the documented, hardened state is the starting line for the managed service.
  • Closing the gaps Microsoft leaves open

    Anyone using Microsoft 365 or Azure shares responsibility for security – the shared responsibility model. Backup, best practices, protection against phishing and ransomware: without these precautions the Microsoft cloud cannot be used securely.

Request onboarding

Managed services

Around the clock · Monthly
  • Managed Secure Microsoft 365 Tenant

    Microsoft 365 is the digital heart of your company – and Microsoft changes the platform constantly. We take over the control centre: continuous tenant hardening along the Microsoft Secure Score, global identity management in Entra ID, central policies against uncontrolled data leakage, solid reports for audits and cyber insurance – and we assess Microsoft announcements for their security relevance to you before they land.

    Backend focus: no licences, no active threat hunting, no third-party protection. First-level user support, hardware and industry software stay with your IT team or IT service provider.

  • Secure Modern Workplace

    Our all-round package per seat – one interlocking, continuously managed ecosystem instead of isolated tools: 24/7 threat hunting by the SOC, a lived zero-trust architecture without permanent admin rights, immutable backup with regular recovery testing, and automatically compliant email signatures on every device.

    All licences included: Microsoft 365 Business Premium and Intune Endpoint Privilege Management, plus the tooling for 24/7 SOC monitoring, immutable backup for Microsoft 365 & Entra ID with recovery testing, enterprise password management and central signature management – including Windows and macOS device management via Intune.

  • Managed EDR

    A classic virus scanner is no longer enough. We continuously monitor all activity on your Windows, macOS and Linux devices – in the office and in the home office. The AI-assisted SOC analyses anomalies around the clock, intervenes proactively, fully cleans infected systems and restores the secure state.

  • Managed ITDR

    Real attacks today usually start with a login, not a virus. We monitor identities and mailboxes in Microsoft 365 permanently, detect unauthorised sign-ins, hijacked sessions and manipulated mailbox rules – and resolve incidents proactively instead of leaving you alone with alerts.

  • Managed SIEM

    Optional add-on: security events from different sources, stored securely for one year and reviewed regularly – AI-assisted SOC operations with real humans, at a predictable price.

Try it for 14 days

Our portfolio covers all six functions of the NIST Cybersecurity Framework 2.0: Govern Identify Protect Detect Respond Recover

We are happy to discuss the specific products in person – as a matter of principle, we do not publish details of our customers' security architecture.

Why our customers
sleep easier.

Security is a matter of trust. So hear directly from our customers how we secured their environments with flexible, individual services.

  • „Very good, professional contact from the scoping stage onwards, and a high level of transparency. The service made it very clear where the challenges lay and which critical points we should address. The whole process was transparent, very well structured and professionally executed.“

    Heike Fischer
    Managing Director, AuPairWorld GmbH
  • „When I set up as an independent auditor, it was clear from the start that the IT infrastructure had to meet the highest requirements for security and compliance. Not at some point, but right from the start. The result is a coherent solution that brings security, compliance and usability to the point.“

    The full story: security and compliance for an auditor

    When I set up as an independent auditor, it was clear from the start that the IT infrastructure had to meet the highest requirements for security and compliance. Not at some point, but right from the start. Together with Peak Data we built a Microsoft 365 environment designed for exactly that: zero-trust principles, modern authentication mechanisms, encrypted data access and central policy control. Everything is integrated from the beginning.

    What convinced me most was the structured, practical approach. Instead of mere technical setup, the whole environment was planned so that it not only meets regulatory requirements but is also efficient to use day to day. Modern, phishing-resistant authentication methods were used from the start — simple to use, strong in effect. The setup was complemented by smart functions such as central signature management, which ensures professionalism and consistency in external communication.

    The result is a coherent solution that brings security, compliance and usability to the point and simply convinces. — Matthias Peil, independent auditor

    Matthias Peil
    Independent auditor
  • „We have had Microsoft 365 for about a year and had no idea about the many settings – it was new territory for us. Now we have more security and the certainty that all the settings we didn't even know about are configured securely.“

    Christian Wiegand
    Managing Director, Photonic Codes GmbH

These companies rely on our expertise

  • AuPairWorld
  • Photonic Codes
  • Zindl Beratungsgesellschaft

Honest advice,
as equals.

2020 – the world is upside down. Working from home becomes the norm, and suddenly digital processes and the move to the cloud have to happen fast. Friends who run companies – people who know us as cloud experts – start asking for advice, and we come to an important realisation: hardly anyone is aware that Microsoft's default settings don't protect you sufficiently. Out of this grows our mission: protecting small and medium-sized companies that work in the cloud.

Today Peak Data is a team of Microsoft cloud security experts with the certifications to match. We don't throw complicated jargon around: we explain which security risks you face and how we'll fix them together, in a way you can actually understand. Security is a big responsibility – and we take it very seriously. That doesn't mean we always have to be serious.

Current certifications on the team

  • ISC2 CISSP
  • CompTIA Security+
  • Microsoft Certified: Security Operations Analyst Associate
  • Microsoft Certified: Azure Security Engineer Associate
  • Microsoft Certified: Azure Solutions Architect Expert

Pricing.
Predictable and transparent.

You only pay for what is actually protected – per seat, device or identity. And for services, only for work actually done.

ServiceBillingTermIncluded
Time & materialsBy actual time spent, rounded to whole hoursAs neededItemised statement of all work performed
Tenant onboarding & baseline setupProject price, quote after the first conversationOne-offAudit & cleanup, security baseline, rollout, documentation & handover
Managed Secure Microsoft 365 TenantMonthly, quote after the first conversationOngoingTenant hardening, identity & policy management, audit reports, roadmap assessment
Secure Modern WorkplaceMonthly, per seat – licences includedOngoingM365 Business Premium & Intune EPM, SOC monitoring, immutable backup, password management, signature management
Managed EDRMonthly, per protected deviceAdjustable monthly, cancellable yearlyReal-time detection & response, isolation, incident report
Managed ITDRMonthly, per licensed identityAdjustable monthly, cancellable yearlyProtection for Microsoft 365, Entra ID and hybrid identities
Managed SIEMMonthly, per connected log sourceAdjustable monthly, cancellable yearlyLog storage for one year, continuously updated detection rules

You can trial Managed EDR, ITDR and SIEM for 14 days – on request including a pentest arranged with us. We quote concrete prices in the first conversation.

Frequently asked
questions.

Who monitors the systems around the clock?

24/7 monitoring is provided by our SOC partner, specialised in security operations and SOC 2 Type II certified. That way threats are detected and handled at any time – including outside your business hours.

Which standards do you work to?

Our approach follows the NIST Cybersecurity Framework 2.0 and the CIS Benchmark for Microsoft 365. The portfolio covers all six CSF functions: Govern and Identify through the Managed Secure Microsoft 365 Tenant, the tenant audit and our consulting; Protect through the security baseline and Secure Modern Workplace; Detect and Respond through managed EDR, ITDR and SIEM with the 24/7 SOC; Recover through immutable backup with regular recovery testing.

Who has access to the log data?

Access is limited to us, our security operations partner and the contacts you authorise. Data is transmitted encrypted and stored securely – GDPR-compliant, of course.

Where is the data stored – and is there a data processing agreement?

Telemetry and log data are transmitted encrypted and stored in our SOC partner's cloud infrastructure, SIEM logs for one year. Our partner is SOC 2 Type II certified and GDPR-compliant. For all managed services we sign a data processing agreement under Art. 28 GDPR with you; our partner is included as a sub-processor. We are happy to share the underlying documents – including the specific products in use – with you before we start.

What happens in an emergency?

When a threat is detected, our analysts react immediately. The affected system or account is isolated, analysed and cleaned. Afterwards you receive a short incident report with all relevant details.

Can I trial the service before deciding?

Yes. A 14-day trial is available for Managed EDR, Managed ITDR and Managed SIEM. During that time you see the full feature set in action and, by arrangement with us, can run pentests.

How can I cancel or adjust the service?

You stay flexible. The service can be adjusted monthly and cancelled yearly. New endpoints, identities or SIEM sources can be added or removed at any time.

Does Managed ITDR cover other systems too?

Managed ITDR is designed specifically for the Microsoft cloud and covers Microsoft 365 / Entra ID and hybrid identities. Other cloud or on-premises systems are not part of the service.

Didn't find your question? Let's talk about it.

Did something just happen?

Call us – we'll take a look together, right away.

Your local time right now is .

Phone+49 15678 533450Call now

Let's
talk.

A virtual coffee chat? The contact form? Email or phone? We're here for you – Fuldatal (Kassel district), Germany.

Pascal Plaga

Pascal Plaga
Managing Director – the person you'll talk to

hello@peak-data.de+49 15678 533450

  1. We get back to you personally within one business day – no autoresponder.
  2. We talk about your situation and explain how our process works step by step.
  3. You receive an honest assessment of what you need – and what you don't.
Or book a slot directly

What you enter here is used only to reply to you. This site sets no tracking cookies.