Our Security Principles
Security isn't one product you buy and forget about, it's a handful of ideas applied consistently across everything we manage. Here's what those ideas are, and how they show up in what we actually run.
Least Privilege
Access should be limited to exactly what's needed, nothing broader "just in case." The more access that exists, the more there is for an attacker to find and use if something goes wrong.
- We manage your Microsoft 365 tenant through delegated admin access, not by holding onto your global admin credentials (see How Microsoft 365 Works with Triumphant).
- MFA is required for everyone, regardless of role or seniority. Privilege doesn't exempt an account from verification, if anything, a higher-privilege account is a bigger target.
Defense in Depth
No single control is trusted to catch everything on its own. Layers overlap on purpose, so if one fails or gets bypassed, another is still standing between an attacker and your data.
- A managed firewall watching the network edge (see Our Networking Standards)
- Huntress watching every endpoint for what the firewall can't see (see What Is Huntress?)
- MFA and passkeys protecting accounts even if a password leaks
- Automated patching closing known vulnerabilities before they're used against you
- Security awareness training addressing the layer no piece of software can fully cover, people
Any one of these failing on its own shouldn't mean the whole network is exposed.
Assume Breach
However good the layers above are, we plan as if something will eventually get through, a convincing phishing email, a zero-day, a bad click on an otherwise ordinary Tuesday. Once that's the assumption, the priority shifts from pure prevention to fast detection and containment.
- Huntress can automatically isolate a compromised device from the network the moment it spots something real, before it spreads.
- Backups are stored with write-locks enabled, so even an attacker with valid admin credentials can't delete your way out of a clean recovery (see Where Backups Are Stored & How They're Protected).
- There's a clear, calm process for what to do the moment something feels wrong (see I Think I Clicked Something Bad, Now What?), because the speed of reporting matters as much as the tools behind it.
- If the worst actually happens, there's a defined recovery path, not improvisation (see What Happens During a Ransomware Incident).
The Stack These Principles Built
Everything above is the reasoning. Here's where to go for the specifics:
- What Is Huntress? (MDR/EDR Explained)
- Setting Up MFA on Microsoft 365
- Setting Up a Passkey for Microsoft 365
- Why We Require a Password Manager (Keeper)
- How Backups Work and Where Backups Are Stored & How They're Protected
- How Automated Patching Works
- How to Spot a Phishing Email
- What Happens During a Ransomware Incident
- Our Networking Standards
What You Should Do
- Don't ask us to disable or bypass MFA for convenience, on any account, for any reason. It's the single control we're least willing to compromise on.
- Don't request access broader than your role actually needs. If something feels limiting, tell us what you're trying to accomplish, there's often a narrower way to grant it.
- Report anything that feels off immediately, even if you're not sure it's anything. Every principle above depends on us hearing about a problem early.
Need Help?
If you run into any issues, reach out to the Triumphant support team:
- Email: [email protected]
- Phone: (404) 387-0435