Detect. Defend. Repeat.

Microsoft security expertise, working alongside your team.

Luna Cyber is a New Zealand consultancy specialising in Microsoft security. We find out where you actually stand, do the work to improve it, and stay available as your estate changes. Your team keeps ownership. We bring the depth they do not have in house.

Microsoft Partner, New Zealand owned Scoped and quoted up front Evidence from your tenant, not a questionnaire

How we work

Three ways to bring us in

Start wherever you actually need help. There is no compulsory first step, and nothing you have to buy into before we will talk about the problem in front of you.

What we cover

The whole Microsoft security stack

Five areas, and the seams between them. Most of the problems worth finding do not sit neatly inside one product, which is why we work across all of it rather than specialising in one.

Working together

A partner, not a supplier.

We are not interested in being the consultancy that arrives, produces a document and leaves you no better off than before. The point of bringing us in is that your organisation ends up genuinely more secure, and your team ends up knowing more than they did.

  • An extension of your team. We work alongside your IT people, in your channels, at your pace. They keep ownership of the estate. We add the depth they do not have on staff.
  • In it for the long term. We would rather know your environment for years than audit it once. The second engagement is always better than the first, because we already know how you are built.
  • You end up more capable. Every finding carries the reasoning, not just the fix. If your team can close it themselves next time, that is a good outcome, not lost revenue.
  • Straight talk. Fixed scope and no surprise invoices. We will tell you when something is not worth doing, and when you do not need us at all.
The three ways to work with Luna Cyber, each a valid starting point: Assess, a scoped review of a tenant, a product area, a design or a provider; Improve, a defined project with a fixed scope, fixed fee and end date; and Support, ongoing capacity and scheduled re-assessment. Engagements can lead into one another, but none of them is a required first step.
Start at whichever one matches the problem you have.

Our method

We look at what is configured, not at what someone remembers.

Most security reviews are built on interviews and self-assessment questionnaires. That measures what your team can recall on the day, which is not the same as what your tenant is actually doing. We read the configuration directly and work from that.

How an engagement runs, in three stages. Stage one, we agree the scope and the access: what is in scope, what is not, and read-only access approved by your administrator. Stage two, we read the configuration directly across Entra ID, Defender, Sentinel, Purview and Azure, verifying every permission before starting. Stage three, you get findings ranked by real risk, each carrying the evidence behind it, the reasoning and the fix, handed over in a working session with your team.
How an engagement runs, whatever the subject.

Independent assurance

Already paying someone to run your security?

Outsourcing security does not tell you whether the work is being done, and the reporting you receive comes from the same provider doing the configuring. We read your tenant independently and show you what is actually in place. We are a consultancy, not a managed service, so the review does not arrive with a proposal to take the contract over.

Tell us what you are dealing with.

A short conversation is usually enough for us to say whether we can help, what it would take, and roughly what it would cost. If the answer is that you do not need us, we will say so.