Contact us
Speak to our team of Microsoft Security specialists today.
Information provided within this form will be handled in accordance with our privacy statement.
Strengthening the foundation for future-ready cyber security with Data#3 and Microsoft.
The highlight was the fact that we finished on time and within budget. This rarely happens. It is hard to budget time, money, and foresee challenges and work through them. Also, the simplicity and ease of working with Data#3 and Microsoft really stood out.
Spokesperson - Cyber Security Specialist, Healthcare Organisation.
To safeguard sensitive information against increasingly sophisticated threats, a healthcare organisation* sought to empower further innovation while strengthening its use of Microsoft identity and security technologies.
Building on their prior partnership with Data#3, and as Microsoft’s largest Australian partner, the organisation knew Data#3 had the expertise and local support required to help them get the most from their technology investment.
*Organisation name removed for security purposes.
Operating for more than 100 years, the healthcare organisation provided specialised services supporting healthcare professionals. This trusted position means the organisation handles sensitive data, and the business takes that responsibility seriously. Investing in continued improvement to data security is seen as vital to dealing with ever-evolving cyber threats.
In FY 2024–25, the Australian Cyber Security Centre (ACSC) made more than 1,700 notifications to entities about potentially malicious cyber activity¹, an 83 per cent increase on the previous financial year. Against this backdrop of an ever-changing cyber security landscape, the healthcare organisation’s Cyber Security Specialist (spokesperson) said that it continually seeks to improve its security posture.
“Our regulatory requirements lay out the absolute minimum standard of cyber security we have to meet. Beyond that, we need to align with ISO 27001. We are always making sure we are keeping up to date with industry practices,” spokesperson said.
While industry compliance and organisational risk were sizeable considerations, there was an even more compelling aspect of the organisations work that drove them to reach beyond legislated requirements.
“Our data and the information we handle is mostly health sensitive because we are a medical defence organisation. We protect medical professionals with insurance and when people make a claim, if lawyers are involved, we need all the files around that claim, which means that we are handling patient information. It is quite sensitive information, so we handle it with sensitivity and care,” spokesperson explained.
Significant changes to the IT environment should always be evaluated for their cyber security implications, and a recent transition to the cloud was no exception. As always, the in-house team undertook a thorough risk assessment which revealed that ultimately, the transition brought tangible opportunity to strengthen defences.
“We were moving from mostly on-premises to cloud infrastructure, which has better tools to limit privileged access and improve identity access management. With on-premises, this was a bit more challenging for us to uplift in general, and to keep up with the times and ensure compliance.”
In the previous on-premises environment, visibility was “a real challenge” and identity management could be cumbersome. It was especially challenging to detect credential misuse and insider threat, placing additional burden on IT staff. The transition to cloud was something that the organisation saw as a welcome opportunity to make real gains.
“We started by making a plan internally, and I was able to dedicate most of my time to it. Additionally, there was no solution already in place, we were not replacing anything else, which made it more straightforward,” spokesperson said.
The transition to cloud brought with it a wealth of Microsoft security tools that offered the visibility and flexibility the healthcare organisation needed. The organisation also required a partner that could help it meet not only the necessary compliance requirements, but also the high standards the organisation set for itself.
Data#3 supplied the cloud infrastructure and was responsible for integrating existing infrastructure platforms and solutions, making the company a natural fit for the engagement. The spokesperson noted that Data#3’s existing knowledge of the environment, built through previous work together, was a key advantage.
Data#3 delivered an integrated identity and security uplift, combining Defender for Identity, Entra ID Password Protection, enhanced Conditional Access policies, and Privileged Identity Management (PIM). The solution addressed on-premises and cloud identity gaps and strengthened privileged identity access controls.
The process was designed to include the organisation’s in-house team every step of the way, incorporating the team’s deep knowledge of the organisation’s unique environment and business imperatives to ensure the solution aligned with its vision.
The organisation articulated its requirements and desired outcomes, and Data#3 developed a proposal that aligned.
The project included detailed discussions around infrastructure requirements, storage platforms, servers, endpoints, and existing infrastructure that could be leveraged as part of the solution. Formal workshops with the Data#3 team helped the organisation understand the technology implications, implementation process, and ongoing management responsibilities.
This structured process was a vital element of the project, ensuring roles and responsibilities were clear and expectations were understood on all sides.
“Flexibility was important, so if we got halfway through one implementation and it was not heading where we needed, we could discuss it and pivot,” spokesperson added.
With the solution in place, delivered on time and within budget, the outcome is a more manageable environment that provides far greater control and visibility than was possible in the previous on-premises environment.
A key benefit has been the implementation of Microsoft Defender for Identity, which provides identity-based alerts for suspicious activities. The enhanced detection capability gives the organisation greater visibility over user activity and supports the work of its Security Operations Centre (SOC) team.
The solution also enables the organisation to replace static privileged access with time-based privileged access. As a result, if an account is compromised, elevated access does not continue beyond the approved timeframe, providing an additional layer of defence to help mitigate identity-based attacks.
The ability to manage identity on a granular level is one of many measures that work together to reduce opportunities for malicious actors. Permissions are managed through access policies that restrict access based on location and user role. For example, selected overseas vendors are granted legitimate privileged access to systems, while all other access attempts from outside Australia are blocked. This approach helps reduce the organisation’s overall attack surface.
From the outset, the organisation sought to increase confidence in its overall security posture and, with the help of Data#3’s security expertise, this goal has been achieved. According to the spokesperson, this outcome was further supported by developing in-house skills across the Microsoft security toolset.
Knowledge transfer formed an important part of the project, with workshops and shadowing sessions allowing the Data#3 team to demonstrate their approach and equip their in-house team with the skills and confidence to manage the environment independently.
By reducing risks associated with privileged access and weak passwords, the organisation has lowered the likelihood of costly breaches and compliance issues. Given the average cost of a data breach in Australia has now reached a staggering $4.26 million², this is no small matter.
Importantly, these gains have been achieved without disrupting users. The Conditional Access framework not only strengthens protection but does so in a way that maintains a smooth and consistent user experience, balancing security with usability.
Across the organisation, much of the project’s value operates behind the scenes. While largely invisible to end users, the solution provides stronger governance around privileged access and a more secure approach to managing and supporting users.
While the project was completed and ready to be managed in-house, they continue to value the assurance that trusted advice is readily available when needed.
“Even though we don’t have a managed services agreement in place with Data#3, if something pops up related to the project, even though it is finished, we contact the team, and they are happy to help and provide direction,” spokesperson said.
The in-house team is accustomed to working with vendors across different locations and time zones. That said, there are clear advantages to partnering with a provider that has invested in a meaningful local presence beyond account management alone.
Effective communication played a critical role in the project’s success, with the ability to work on-site helping to simplify collaboration and decision-making throughout the engagement.
The Data#3 team were approachable, transparent, and responsive, providing regular reporting in line with the organisation’s preferred cadence. Ongoing communication through Microsoft Teams ensured discussions were never limited to scheduled meetings, allowing questions, issues, and ideas to be addressed as they arose. This continuous engagement helped maintain a clear understanding of project progress and next steps.
The in-house team particularly valued this consistency of communication and the confidence that support would remain available, even when challenges emerged during the project.
As with any technology initiative, some issues arose during implementation. However, these were resolved quickly through ongoing collaboration via Microsoft Teams. When opportunities allowed, Data#3 also shared its expertise, helping the organisation’s in-house team develop a deeper understanding of the technologies and systems being implemented.
Communication proved to be one of the most valuable aspects of the engagement. Technical concepts were explained in a way that was easy to follow, ensuring stakeholders understood what was happening and when. While the Data#3 team demonstrated strong technical expertise, they also took the time to ensure the organisation’s in-house team understood what was occurring within its environment rather than simply moving on to the next task.
This willingness to share knowledge was particularly important, helping their team feel confident they could manage the environment independently once the project was handed over, while still knowing expert support was available if needed.
Ultimately, what stood out most was having access to a team that made a complex technical undertaking feel straightforward.
“The highlight was the fact that we finished on time and within budget. This rarely happens. It is hard to budget time, money, and foresee challenges and work through them. Also, the simplicity and ease of working with Data#3 and Microsoft really stood out,” spokesperson concluded.
Secure the data behind every decision As organisations move faster with AI, data integrity has become...
Strengthening the foundation for future-ready cyber security with Data#3 and Microsoft.
When the topic of data integrity is raised in boardroom discussions, it’s usually framed as a...
There’s a question I ask organisations early in every data security engagement: can you tell me, right...
Nearly every organisation I work with is either implementing AI, planning to, or being asked to explain...
In partnership with Microsoft, Data#3 has developed a K-12 Security Blueprint and whitepaper for school...
Transitioning from legacy to modern cloud foundation for innovation.
Australian Catholic University shapes the future of learning with Microsoft Azure.
November 13, 2025; Brisbane, Australia: Leading Australian technology services and solutions provider,...
Technology is advancing at an unprecedented pace, fundamentally transforming the way we work. Leading...
Many SMEs think they’re too small to be targeted, until they are. Cyber attackers exploit...
When evaluating Software as a Service (SaaS) applications, organisations increasingly prioritise security...
In cyber security, change is constant, but some challenges remain stubbornly familiar. Do you remember...
International Safety Systems switches to modern, secure Microsoft Azure environment Download Customer...
In government, simply having a zero-trust plan doesn’t guarantee success. The challenge? Complex IT...
Understanding Microsoft’s Information Barriers, Enhancing security and compliance In today’s...
Take a closer look at Cisco’s rise in cyber security
Discover how HPE Aruba Networking’s Security Service Edge gives users the confidence to deliver Zero...
Discover how HPE Aruba Networking’s recent acquisition of Axis Security is allowing them to deliver...
In an era where technological advancements outpace our imagination, keeping up can be as daunting as it...
Speak to our team of Microsoft Security specialists today.
Information provided within this form will be handled in accordance with our privacy statement.