TO

About

Tristan van Onselen

Chief Security Officer · Defender Sensei

I'm a Chief Security Officer who spends most of my time inside the Microsoft security stack — Sentinel, Defender XDR, Entra ID, Purview — and I write here to share what actually works in production environments that don't have a 50-person SOC.

What I focus on

  • Zero Trust architecture for small and mid-market organizations
  • Microsoft Sentinel deployment, tuning and cost optimization
  • Defender XDR onboarding and incident response runbooks
  • Entra ID conditional access and identity hardening
  • NIS2, ISO 27001 and pragmatic compliance mappings

Why DefenderSensei

Most security content is written for the Fortune 500 — by vendors who want to sell you something. I'm not selling anything here. The mission is simple: make enterprise-grade cybersecurity practices accessible to organizations that don't have enterprise budgets.

If a 30-person engineering team can run the same Zero Trust posture as a Fortune 500 — and they can, with what's already in their Microsoft 365 license — then sharing how is worth doing.