👋 Hello there! It's me...

Phil Marsh

And I’m a Cyber Security Solutions Architect

I am a Cyber Security Solutions Architect working within a UK law firm, specialising in securing complex, highly regulated environments I focus on translating advanced Microsoft security capabilities into practical, resilient controls that actually work in the real world.

Phil Marsh

About

A quick snapshot of what I do and how I work.

Security • Infrastructure • Leadership
▥

Security & IT

Infrastructure, Security, Engineering & Leadership

10+ yrs
⌖

Based in

United Kingdom

Remote / hybrid friendly

Hi there! I'm Philip Marsh, I'm a cyber security solutions architect at a UK law firm, focused on helping organisations strengthen their defences, detect threats earlier, and make better use of modern security tooling. My work spans enterprise security operations, Microsoft security technologies, Microsoft Sentinel, threat detection engineering, KQL, automation, and practical security improvements that make a measurable difference.

Through this blog, I aim to share practical guidance, technical walkthroughs, lessons learned, and opinion pieces for cyber security professionals working in real-world environments. My writing is aimed at cutting through noise and turning complex security topics into clear, actionable content, especially for teams working with Microsoft security platforms, enterprise detection, and day-to-day operational security challenges.

My Career Timeline

Specialist, Cyber Security Solutions Architect

Implementing a "secure by design" approach within a top 100 law firm in the UK. Part of the wider IT leadership team, I help to ensure that all new and existing IT project implementations follow security best practises and meet the changing regulatory requirements for secure systems.

Associate

Recognised for my IT leadership and consistent high quality deliverables, I was promoted to the role of Associate within a UK lawfirm, still undertaking my Cyber Security Lead role.

Cyber Security Lead

Completely designed, created and implemented a security posture at a large UK Law Firm, working with partners to implement a 24/7 "follow-the-sun" SOC backed by a leading UK MSSP. I also oversaw Cyber Projects to revamp EDR and Identity protections within the firm, onboarding Crowdstrike (and later Defender for Endpoint) as well as implementing a secure Conditional Access design backed by Intune Compliance policies across the entire organisation.

IT Helpdesk Analyst

Working in a fast-paced law firm, I learned a substantial amount that helped me later in my career, from infrastructure to security.


Disclaimer

The content on this blog is provided for general informational and educational purposes only and is supplied “as-is” without any warranties or guarantees. While I aim to ensure the information is accurate and useful, I make no representations that any guidance, scripts, queries, configurations, or solutions will be suitable for every environment or use case.

You should fully review, test, and validate any solution in a safe, non-production environment before applying it to live systems. Some approaches may require modification to suit your organisation’s specific technical, operational, legal, or security requirements. Use of any content from this blog is at your own risk.

If you notice content that is incorrect or has errors, please feel free to reach out to me

Support the blog

If you want to support my blog, and help bring this content to more users, please consider donating to me at [Link coming soon].