← Signal to Noise
Episode 6/Deep Dive/24 August 2026/12:25

Introducing our Latest Release of Security Features

Announcing our latest batch of MIDAS security features

Watch
Listen

Discover the latest upgrades to our Midas security service.

Good security is a journey, not a destination. Today, Dave talks with Chris, our senior security analyst at Nova Blue, about the evolution of our MIDAS security service and the ongoing work that ensures our clients stay ahead of threats.

## Continuous Improvement in Security

Chris has been with Nova Blue for nearly five years, and his role has evolved alongside our managed security service. The core of our approach is continuous improvement, a concept that underpins every update and feature we implement. As Chris points out:

"Security is never finished...the threats change because the security features change because people's ways of working change."

This philosophy drives our team to remain proactive, focusing on hardening secure environments and mitigating risks before they become incidents.

## The MIDAS Service Evolution

The MIDAS service is designed to adapt to the ever-changing threat landscape. Chris explains that his team actively researches new developments, both within Microsoft environments and the broader security landscape, to enhance our offerings. This ensures our clients benefit from the latest advancements in security:

"It's not a one-stop thing; it's an ever-growing process."

## Key Features of the Latest Release

As we prepare to roll out the latest updates, Chris highlights some key areas of focus:

- User Identity Protection: Enhancements to how we secure user identities.

- Device Hardening: A complete overhaul of our macOS and iOS offerings to ensure robust protection.

- Email Threat Protection: Improved measures to safeguard against email-based threats.

These updates reflect our commitment to not just advising on security measures but actively implementing them in our clients' environments.

"This is not just a list of to-dos; it’s about what we are going to do and what we have done."

## The Journey Ahead

As we continue to grow and adapt, Chris emphasizes the importance of staying informed and responsive to changes. Our security programs must evolve, ensuring we are always prepared to meet new challenges head-on.

Transcript

Machine-generated from the recording, so expect the odd mis-hearing. 2,380 words.

Dave: Good afternoon. So first of all, sorry we've not had any videos for a little while, but summer holidays and all that. And you may notice the eagle-eyed amongst you that I am not joined today by Steve. I'm joined by Chris, who is another one of our awesome team. I'm super excited to have Chris here today to talk about some of the work he's been doing with our security service. So first of all, Chris, do want to just introduce yourself a little bit?

Chris: Yeah, thanks Dave. so I'm the senior security analyst at Nova Blue. I've been on the Nova Blue team for nearly five years now. my my primary role is helping to run the managed security service across all our tiers, essential complete and premium. each day it's been focusing on instant handling, baseline progression. And security reporting.

Dave: Yeah, thanks. So what Chris isn't saying that he was actually the very first member of the managed service team joined over blue joined Steve back in the day and really built the service alongside Steve and Les the other founder. I describe it as kind of lovingly brick by brick built in the early days. But the reason that Chris is on today is because we're getting to a point now where actually, you know, it's not so much about brick by brick hand building anymore. It's about repeatable processes, about scale. As we grow, bring in more clients, more people to work with. We're building our own maturity, but we're also building our provision as well. One of the key features of our security service is continuous improvement. You'll have heard us before on these videos talk about MIDAS, that's our core managed security service. Just as a reminder, effectively it does two things. One of those things is, proactive, very much focus on building secure environments, on hardening, on closing down threat vectors before those threats even manifest themselves, and really focusing on reducing the likelihood or the probability of a cyber incident happening. And that's what we're to be focusing on later today. And then the other component is monitoring, detecting, responding when something does go wrong. But the reason we brought Chris in today is he's going to tell us a bit about the work that he and the team have been doing on our next iteration of features for that MIDAS service. But before we dive into that, Chris, I mean, I've described MIDAS in our, I guess, our kind external facing, very slightly marketing language. But from your point of view, what does it mean to work on MIDAS every day? And what are the sort of things that you're doing just to bring that to life?

Chris: Yeah, of course. so a lot of what we're doing each day is researching and seeing what's new within the Microsoft environment or the threat landscape, generally speaking, and how we can bring those things in and incorporate them into the MIDAS service. It's not a one-stop thing, it's a ever-growing process. So we're always seeing what's new and how we can incorporate that in, learn about it, and translate that into real actions we can bring to our customers to further harden their environments, whether that's identity Protection, device protection, email-based, anything like that. So all those things get bought into our backlog and we review those as a team, test them, progress them, learn about them, and evolve them into the next release of the MIDAS baseline. So every six months we release a new edition of our baseline, and that covers new actions across. MIDAS services, whether that's essential, complete and premium, also micro as well. these items are split into six phases. Phase zero being the pre-start, normally things like audits that we'll rerun every six months. Maybe it's to check for stale identities that haven't been used in the last three months or so. maybe it's checking GDAP relationships you might not have, checking PIM rolls and assignments. Those things that could get forgotten about we'll make sure they reviewed and the right actions taken to reduce the potential exposure there. Moving on to phases one through to six, these are more into the nitty-gritty. So we've got phase one, which is all about user identity, phase two is more about email threat protections and conditional access. Phase three is all about device security. Four is about BYOD and data protection from a mobile standpoint. Five is your identity and guest access and external sharing. And then phase six is all about purview and data protection within your SharePoint and what that looks like outside of your business as well.

Dave: That's a super cool overview So I think there are two things that come out of that for me that are really part of our kind of core tenet and way of working. So the first thing is, and you alluded to it, but just really drawing out, this isn't stuff that we are advising people to do. This is stuff that we, I say we, I mean, you and the team are actually doing. You're in there with your hands on the keyboard, logged into somebody else's Microsoft 365 environment and implementing those things. on their behalf, yes, with their support and there's a business change process that goes with that, but it's not just a list of to-dos. It's a, here's the things that we are going to do and then here's the things that we have done. And then the second thing, I think, just to pick up on is that idea of continuous improvement, that this is not a one and done. Security is never finished because... Well, lots of reasons. The threats change because the security features change because people's ways of working change. And a security program that is designed as a kind of one-stop shop is out of date the second that piece of work finishes. that I think is really important tenet of MIDAS, is, you know, it's a continuous improvement. And it sounds like from what you're saying that you're spending far more of your time. doing that proactive continuous improvement, then you are, for example, looking at load of alerts or responding to incidents.

Chris: Yeah, that would be fair to say. Yeah, there's there's like you said as well, it's ever growing, there's always something new. that there's never it's never done, it's never complete. as soon as one thing was researched and refined, by the time we've documented all Microsoft brought out a new feature that's made something else redundant. So we're always having to check our notes and make sure we're up to date with the latest guidance. but yes, it's it's always it's always growing.

Dave: No, that's cool. So on that point that of growing and you briefly mentioned it and the main reason we were going to chat today. So you have just finished this last six months worth of work. It's about to be released to clients imminently So all our current clients will get comments on that if they've not already had it by the time they see this video. do you want to talk through a high level, what are some of the key things? So what are the things that have changed in the last six months and what are some of key features?

Chris: So one of the big features we're really proud of is the overhaul to iOS and Mac OS in our baseline. Before it was very it was strong before, but Intune had was limited in terms of its features, whereas now that's all been upgraded. So we've been able to take advantage of these new areas and we've overhauled our compliance, onboarding processes, device policies for device hardening, including browsers, OS level. local admin privileges, FireVolt, and anything else that Intune currently offer, that's now all included within our 26H2 release. Same with iOS, the same features where applicable can apply as well. So that's things like compliance, device onboarding, enrolment profiles, all of that's now available and included in the latest release. So any customer with macOS and iOS in their environment, they can now take full advantage of these Dave: Yeah, cool, that sounds like a really good improvement, because I know that that's been one of the challenges in the past where those differences in architecture have meant it's been a bit more manual process. But it sounds like this allows you to strengthen security across Apple devices in a much more slick and swept up way.

Chris: Yeah, totally. the process a lot more seamless for the user as well, integrates with their managed Apple ID, makes use of Platform SSO, to access their Entra account via a passkey embedded in the MacBook itself, giving them that phishing resistant method of logging in, which is something else we'll also talk about in this release as part of conditional access. It's it's a better user experience, it's more secure and it's much easier to manage.

Dave: So on that, pass keys are very much the flavor of the month at the moment. but I think in this release, there's some improvements specifically around pass keys.

Chris: That's right, yep. Microsoft have updated their registration campaign within Entra, whereas before you could only use the standard Microsoft app OTP offering, you can now enroll users into Passkey straight away. So this process is very similar to what users would have already seen before. We can now upon next login help users go through the process and enroll their passkey on their mobile phones, whether that's a personal or work device. And once that's enrolled. We can then back that up with our conditional access policies to require all users using pass keys across any device.

Dave: Yeah, so I mean, that's great example. I think of how we can take a security feature. We can then effectively wrap it in a business process and then work with the client to help them implement that because I know that some of the nervousness around, OK, how do I actually implement this pass key thing I've heard of? What does it look like? What does it mean? But I do think being able. to roll this out as part of our baselines will really help organizations get to grips with this.

Chris: Yep, absolutely. Along with that we have user guides ready to go as well. So we can pass those out to all staff to use in their own time to complete that process.

Dave: Great. And should just pause, you mentioned a combination of letters and numbers, said 26H2. So just want to explain that Chris: yeah.

Dave: numbering, because we didn't explain that at front.

Chris: Yeah, of course. So twenty six H two, that's the year and then which half of the year. So twenty six H one or H two. So the next release will be twenty seven H one, which will be roughly March next year. And then it's every six months from there.

Dave: got it, which is basically similar to Windows versioning, isn't it? Yeah. And I think that, you Chris: Windows, yeah. Similar, yeah.

Dave: know, that again, aligns with the philosophy, doesn't it? Treating security releases like software releases so that that happens both kind of in cycle, but also out of cycle when something important happens. I think that's a good philosophy.

Chris: Yep, it allows enough enough time for new features that come out. we can make sure we've fully reviewed those ready for the next release so they're minimizing potential user impact when they're implemented. but it that doesn't mean we can't make emergency changes in between as well. So if something else comes up in between those that we need to make a quick hotfix for, we can also apply that to.

Dave: Yeah, I think that's a really important point. And again, that's kind of at heart of the services. As I said earlier, know, lots of things change all the time. Threats change, new threat actors emerge, particularly these days with AI powered threat actors. Things are moving so quickly that, you know, we're not going to sit in a six month cycle. So what else is there then in 26H2 or anything else you wanted to highlight?

Chris: Yeah, I guess just firstly in this release, there's just over fifty new items which I think is our biggest release yet since going through this six month scheme. and you just touched on it there, AI is one of those hot topics as well. So we've we've started to use the tools within Microsoft to sort of track AI behaviors and agents within your environment. So right now it's quite surface level, admittedly, but it's just checking what's in your environment and do you recognize these agents. and what they have access to. At least from an audit perspective, you can then check those and take the appropriate action on them. We'll grow this in future baseline releases too.

Dave: Well, I don't want take too much more of your time because you've got a lot of controls to go and implement, but is there anything Chris: Ha.

Dave: else that you wanted to highlight?

Chris: Yeah, I think this is a quite a feature complete release of the MIDAS baseline. So you're getting a mix of identity improvements, device hardening, data governance improvements. and it's across all the tiers as well, Essentials Complete and Premium. So wherever you are, you're getting something new in this release.

Dave: Awesome. Well, that was a really useful insight into, I guess, how our service is structured, but more importantly, into what you've been working on for 26H2. So hopefully people have got a bit more of an insight now into what MIDAS is, bit about the philosophy, what it matters. But more importantly, we've heard from the awesome Chris on the work he and the team we've been doing. So we'll get you back on shortly to chat about some more stuff.

Chris: Thanks, Dave.

Dave: Awesome, speak soon. Take care.

Chris: Take care.

Cyber SecurityMicrosoft 365Company News
TALK TO A HUMAN

If any of this sounds like your organisation, a 30-minute assessment call will tell you where you actually stand - no obligation, no sales script.

Book an assessment