OFFICIAL: SENSITIVE — Monthly Security Report — February 2026
← Back to Portal
Monthly Security Report

Meridian Defence Systems Pty Ltd

Managed Security Report — February 2026
Period: 1–28 Feb 2026 Classification: OFFICIAL: SENSITIVE Prepared by: Netier Security Operations Report ID: MDS-MSR-2026-02
86%
Overall Security Posture
92%
MDR Coverage
88%
Patch Compliance
82%
Secure Score
95%
Device Compliance
78%
ThreatLocker
01

Executive Summary

Strong Security Posture Maintained
Meridian Defence Systems maintained an 86% overall security posture throughout February 2026, a 3-point improvement from January. Zero security incidents required escalation to the ACSC, and all DISP compliance obligations were met. The managed detection and response platform processed over 1.2 million events with a 99.7% automated resolution rate, demonstrating mature and effective security operations across all 180 endpoints.
1.2M
Events Processed
↑ 8% from Jan
0
Security Incidents
No escalations
14
Vulnerabilities Closed
↑ 3 from Jan
88%
48hr Patch Rate
↑ 5% from Jan

Monthly Highlights

Achievements

  • Sophos MDR detected and blocked a targeted phishing campaign (14 recipients, 0 compromised)
  • ThreatLocker Secured Mode enabled on 97% of endpoints
  • Microsoft Secure Score increased from 79% to 82%
  • All critical patches deployed within 48 hours for the 3rd consecutive month

Areas for Improvement

  • 3 devices missing ThreatLocker agent (new deployments pending)
  • 6 stale Intune devices (>90 days since last check-in)
  • 2 users without MFA enforcement (contractor accounts)
  • Adobe Reader CVE-2026-0142 pending on 12 workstations
02

Sophos MDR

1,247,832
Events Processed
↑ 8.2% from Jan
99.7%
Auto-Resolved
Industry avg: 94%
3,744
Escalations
↓ 12% from Jan
0
Active Cases
All resolved

Threat Detection Breakdown

CategoryCountBlockedStatus
Malware / PUA847847100%
Phishing / BEC42342199.5%
Suspicious Process15614995.5%
Network Anomaly8989100%
Credential Abuse3434100%
Policy Violation1818100%

6-Month Event Trend

980K
Sep
1.05M
Oct
1.12M
Nov
1.18M
Dec
1.15M
Jan
1.25M
Feb

Phishing Campaign Detail: Operation “Invoice Override”

Targeted Phishing Campaign Detected — 12 Feb 2026
Sophos MDR identified a coordinated spear-phishing campaign targeting Meridian’s finance team. Emails impersonated a known defence subcontractor with a malicious PDF attachment containing a credential harvester. The campaign was fully contained within 4 minutes of the first delivery.
14
Recipients
3
Clicked Link
0
Compromised
4 min
Time to Contain

Repeat Offenders (Clicked in Multiple Campaigns)

UserDepartmentCampaigns ClickedTraining Status
j.morrison@meridiandefence.com.auFinance2 of 6Enrolled
s.chen@meridiandefence.com.auProjects2 of 6Completed

Security Awareness Training Completion

91%

164 / 180 employees completed February training module: “Identifying AI-Generated Phishing Emails”

03

Vulnerability Management

8
New This Month
↑ 2 from Jan
14
Closed This Month
↑ 3 from Jan
6
Currently Open
↓ 6 from Jan
3.2d
Avg Time to Close
↓ 1.1d from Jan

Open Vulnerabilities by Severity

6
Open
Critical: 1
High: 2
Medium: 2
Low: 1

6-Month Vulnerability Trend

18
Sep
15
Oct
14
Nov
12
Dec
12
Jan
6
Feb
Downward trend (improving)

Critical & High Vulnerabilities

CVESeverityProductAffectedTicketStatus
CVE-2026-0142CriticalAdobe Reader DC12 devicesINC-4521In Progress
CVE-2026-21391HighWindows Print Spooler8 devicesINC-4518In Progress
CVE-2026-0987HighMicrosoft Edge3 devicesINC-4525Scheduled
CVE-2025-48721CriticalSolarWinds Orion1 serverINC-4412Closed
CVE-2026-0028HighVMware vCenter2 serversINC-4415Closed
04

Essential Eight — Patching Compliance

48-Hour Critical Patch Target: Met
All critical and high-severity patches for internet-facing services were deployed within 48 hours of release, meeting Essential Eight Maturity Level 2 requirements for the third consecutive month.

Servers

94% patched within 48h

Workstations

88% patched within 48h

Network Devices

100% patched within 48h

Applications

82% patched within 48h

OS Patching Status

OSDevicesCurrentBehindRate
Windows 11 24H2142138497.2%
Windows Server 20221817194.4%
Windows Server 2019660100%
macOS 15.31412285.7%

Agent Coverage Gaps

DeviceMissing AgentStatus
MDS-KIOSK-03NinjaOne RMMPending deploy
MDS-LAB-THIN-01Sophos EndpointScheduled
MDS-CONF-DISPLAYNinjaOne RMMLow priority
05

ThreatLocker

177
Managed Devices
+3 from Jan
97%
Secured Mode
↑ 2% from Jan
342
Requests This Month
↓ 15% from Jan
18
Denied & Reviewed
All legitimate blocks

Device Count Alignment

PlatformCountvs ThreatLockerDelta
Sophos Endpoint179177-2
NinjaOne RMM178177-1
Intune MDM180177-3

3 devices pending ThreatLocker deployment: MDS-KIOSK-03, MDS-LAB-THIN-01, MDS-CONF-DISPLAY

Request Breakdown

342
Total
Approved: 182 (53%)
Auto-allowed: 120 (35%)
Denied: 40 (12%)

Elevation Audit — Admin Privilege Usage

UserElevationsApplicationJustificationRisk
m.taylor (IT Admin)47Various IT toolsApproved admin roleExpected
r.singh (DevOps)23Docker Desktop, VS CodeDevelopment workExpected
k.williams (Engineering)12MATLAB, CAD toolsEngineering softwareReview
d.nguyen (Finance)3Unknown .exeNo justificationInvestigate
06

Microsoft Intune

180
Managed Devices
+2 from Jan
95%
Compliant
↑ 1% from Jan
98%
Encrypted
↑ 2% from Jan
6
Stale Devices
↑ 2 from Jan

Device Breakdown by Type

180
Total
Windows: 142 (79%)
macOS: 14 (8%)
iOS/iPadOS: 18 (10%)
Android: 6 (3%)

Compliance & Encryption Status

CheckCompliantNon-CompliantRate
Device Compliance Policy171995%
BitLocker / FileVault176497.8%
Configuration Profiles174696.7%
Windows Autopilot138497.2%

Stale Devices (>90 Days Since Check-in)

DeviceUserLast Check-inAction
MDS-WS-MORRISON-OLDj.morrison18 Nov 2025Decommission pending
MDS-IPAD-CONF-02Shared22 Nov 2025Locate & wipe
MDS-WS-TEMP-CONTContractor30 Nov 2025Wipe ordered
MDS-ANDROID-POOL-04Pool device5 Dec 2025Investigate
MDS-MACBOOK-DESIGNk.patel12 Dec 2025On leave
MDS-IPHONE-SPARE-02Spare18 Dec 2025Return to stock
07

Microsoft 365 Tenant Security

192
Total Identities
180 users + 12 service
98.9%
MFA Enforced
2 users without
82%
Secure Score
↑ 3% from Jan
12
CA Policies
All enforced

Microsoft Secure Score

82% SECURE SCORE
Identity91%↑ 4%
Data78%↑ 2%
Device85%↑ 3%
Apps74%↑ 1%

MFA Gaps

UserTypeReasonAction
ext.contractor.01ContractorAwaiting hardware tokenExpedite
svc.legacy.scannerServiceLegacy app (no modern auth)Migration planned

Conditional Access Policies

PolicyScopeStatus
Require MFA for all usersAll usersEnforced
Block legacy authenticationAll usersEnforced
Require compliant deviceAll usersEnforced
Block high-risk sign-insAll usersEnforced
Require app protectionMobileEnforced
Named location restrictionsAdminsEnforced

Email Security per Domain

DomainSPFDKIMDMARC
meridiandefence.com.au-allSignedreject
meridian-ds.com.au-allSignedreject
mds-projects.com.au-allSignedquarantine
meridiandefence.io-allSignedreject

Forwarding Rules Audit

No External Forwarding Rules Detected
All 180 mailboxes were scanned for inbox rules that forward externally. Zero external forwarding rules found. Transport rules are configured to block automatic external forwarding.

Defender for Endpoint Health

ComponentHealthyWarningErrorRate
Sensor Health1763197.8%
Antivirus Signatures1782098.9%
Tamper Protection18000100%
Network Protection1744296.7%
Attack Surface Reduction16812093.3%
08

Appendices

A. Methodology

This report is compiled from automated data collection across the Meridian Defence Systems managed security stack. All metrics are sourced directly from vendor APIs and verified by Netier Security Operations analysts. The reporting period covers 1–28 February 2026.

Data SourceCollection MethodFrequency
Sophos CentralAPI — Events, Alerts, EndpointsReal-time + daily aggregation
Microsoft Defender for EndpointAPI — Machine actions, alertsReal-time + daily aggregation
Microsoft IntuneGraph API — Device complianceEvery 4 hours
Microsoft Secure ScoreGraph API — Security assessmentDaily
ThreatLockerAPI — Approvals, denials, elevationEvery 6 hours
NinjaOne RMMAPI — Patch status, agent healthEvery 4 hours
Vulnerability ScannerAuthenticated scans (Nessus)Weekly + on-demand

B. Glossary

TermDefinition
MDRManaged Detection and Response — 24/7 threat monitoring and incident response service
E8Essential Eight — ACSC-recommended baseline mitigation strategies for cyber security
DISPDefence Industry Security Program — Australian Government program for defence contractors
CA PolicyConditional Access — Azure AD policy that enforces access controls based on conditions
MFAMulti-Factor Authentication — requiring two or more verification factors
CVSSCommon Vulnerability Scoring System — industry standard for rating vulnerability severity
RMMRemote Monitoring and Management — tool for remote device administration
BECBusiness Email Compromise — targeted email fraud impersonating trusted parties

C. Distribution

RecipientRoleAccess Level
David HarringtonCEO, Meridian Defence SystemsFull report
Sarah ChenCTO, Meridian Defence SystemsFull report
Mark TaylorIT Manager, Meridian Defence SystemsFull report
Tom HoustonAccount Manager, NetierFull report
DISP Security OfficerFSO, Meridian Defence SystemsExecutive summary
OFFICIAL: SENSITIVE — Meridian Defence Systems Pty Ltd — February 2026