Skip to content

Services

MIR · Managed Identity Resilience MCR · Managed Cloud Resilience MER · Managed Email Resilience MBR · Managed Brand Resilience MAR · Managed AI Resilience

Company

Resources Company Contact Get my Exposure Score →
MIRCore offering IDENTITY → ACCESS → EXPOSURE → RESILIENCE

Every identity is a door. We show you which ones are unlocked — and close them.

Your directory already contains the paths an attacker would walk. MIR finds them, ranks them by what closing them does to your score, and closes them.

90 secondsNo signup to startRead-only, no agents

90%EXPOSURE CUT IN 90 DAYS
0AGENTS ON DCs
MonthlyRE-SCORED

The problem

Identity is where breaches start, and where visibility ends.

Most organisations can tell you how many accounts they have. Very few can name the three chains that lead from a standard user to Domain Admin.

// the account nobody remembers

A service account created six years ago for a project that ended

Still enabled. Still privileged. No sign-in for 412 days, on no one’s review list, and holding a delegation set by someone who has since left. It generates no alerts because it does nothing — until it does.

// three hops, zero alerts

Escalation built entirely from legitimate permissions

A nested group membership, a delegation, then Domain Admin. Every step is authorised, so nothing looks abnormal to your SIEM. The path was always there; someone finally walked it.

// the hybrid seam

Two directories, one trust, no single view

Sync between on-prem AD and Entra ID creates privilege relationships that neither directory’s native tooling maps end to end. Post-acquisition estates multiply the problem.

The programme

What MIR actually does

One continuous loop across both directories — not four dashboards.

01 · Discover

Map the full identity attack surface

Read-only discovery across on-premises Active Directory and Entra ID, mapped to MITRE ATT&CK.

  • Stale and dormant enabled accounts
  • Shadow admins via nested group membership
  • Kerberoastable service accounts and SPN exposure
  • Constrained and unconstrained delegation
  • Weak Kerberos and legacy authentication configuration
  • Leaked and reused credential matches
  • Conditional access and MFA coverage gaps
  • Human and non-human identity inventory
02 · Prioritise

Rank by attack path, not by CVSS

Findings are assembled into paths and ranked by what closing them does to your exposure score.

  • Full privilege-escalation path mapping
  • Ranked top-three fixes per cycle
  • Modelled exposure reduction per fix
  • Board-readable risk language alongside technical detail
03 · Remediate

Close it, reversibly

Guided or fully managed closure, change-controlled and backed up before any change is applied.

  • Guided or managed remediation options
  • Backup and rollback before every change
  • Verified on rescan, not on assertion
  • Change-control aligned to your process
04 · Prove

Re-score and report

The same measurement runs monthly so improvement is evidence rather than assertion.

  • Monthly exposure re-score
  • Attributable score delta per closure
  • Quarterly board and audit pack
  • Evidence set for cyber insurance and ISO 27001 / Essential Eight

At a glance

What’s included

The commercial and technical shape of the programme, before you talk to anyone.

Directory coverageHybrid AD + Entra ID, multi-forest and post-acquisition estates
DeploymentRead-only. No agents on domain controllers, no schema changes
BaselineBreach Likelihood Assessment — attack paths mapped within days
CadenceContinuous discovery, monthly re-score, quarterly executive report
RemediationGuided or fully managed, with backup and rollback
FrameworksMapped to NIST CSF, ISO 27001 Annex A and ACSC Essential Eight
Guarantee90% reduction in measured identity exposure score in 90 days — see terms

Who MIR fits

This is a good fit if…

  • 1,500–10,000 users, hybrid Microsoft estate
  • Security team of 1–10 carrying identity alongside everything else
  • Recent audit, insurance renewal or board question about identity risk
  • Post-acquisition estate with inherited directories nobody fully owns

If none of these describe you, MIR probably is not your priority — and we would rather tell you that than sell it. Run the free assessment on a different surface and see where your score is actually worst.

Objections

The fair questions

No. Collection is read-only and API-based. Nothing is installed on domain controllers and no schema changes are made. This is deliberate — it is what makes a first assessment a low-friction decision rather than a change-board item.

Defender for Identity detects known attack behaviours in real time and does that well. MIR measures the conditions that make those attacks possible — stale privilege, delegation, sprawl — and closes them. Detection tells you about the fire; exposure management removes the fuel. Most of our clients run both.

Probably the same top findings, plus everything created in the three months since. A pen test is a point-in-time sample; your directory changes weekly. The difference is continuity and closure, not detection skill.

Start with MIR

Find out where you stand on identity — in 90 seconds.

Eight questions, a score, and your top three exposure factors. If you want the real number, the full assessment reads your actual environment: read-only, no agents, 48 hours to a report.

90 secondsNo signup to startNo agents, read-onlyNo obligation

Get my Exposure Score — free →