Detect. Defend. Repeat.
Luna Cyber is a New Zealand consultancy specialising in Microsoft security. We find out where you actually stand, do the work to improve it, and stay available as your estate changes. Your team keeps ownership. We bring the depth they do not have in house.
How we work
Start wherever you actually need help. There is no compulsory first step, and nothing you have to buy into before we will talk about the problem in front of you.
Find out where you stand. A scoped review of your tenant, a single product area, a design you are about to build, or the provider you already pay to run your security.
What an assessment covers → DefendGet the work done. A defined piece of engineering with a fixed scope, a fixed fee and an end date. Hardening, deployments, migrations, or clearing a backlog nobody has had time for.
How projects run → RepeatKeep the depth on tap. Ongoing capacity for your team, scheduled re-assessment, and engineers who already know how your estate is put together.
What ongoing support looks like →What we cover
Five areas, and the seams between them. Most of the problems worth finding do not sit neatly inside one product, which is why we work across all of it rather than specialising in one.
Entra ID, Conditional Access, privileged access, authentication methods, guest access and app consent. The perimeter that actually matters.
Learn more → DetectionDefender across endpoint, identity and Office 365, and Microsoft Sentinel: coverage, tuning, detection quality and what your ingestion is costing you.
Learn more → DataPurview labels, DLP and retention, plus Intune, device compliance and endpoint hardening. Protecting the data itself, and the devices it lands on.
Learn more → CloudDefender for Cloud, Azure Policy, RBAC and subscription design, and the exposure that comes with infrastructure nobody has reviewed in a while.
Learn more → CopilotCopilot does not create oversharing. It surfaces the oversharing you already had, instantly and to everyone who asks. Readiness, governance and agent identity.
Learn more →Working together
We are not interested in being the consultancy that arrives, produces a document and leaves you no better off than before. The point of bringing us in is that your organisation ends up genuinely more secure, and your team ends up knowing more than they did.
Our method
Most security reviews are built on interviews and self-assessment questionnaires. That measures what your team can recall on the day, which is not the same as what your tenant is actually doing. We read the configuration directly and work from that.
Independent assurance
Outsourcing security does not tell you whether the work is being done, and the reporting you receive comes from the same provider doing the configuring. We read your tenant independently and show you what is actually in place. We are a consultancy, not a managed service, so the review does not arrive with a proposal to take the contract over.
A short conversation is usually enough for us to say whether we can help, what it would take, and roughly what it would cost. If the answer is that you do not need us, we will say so.