This is the Trace Id: 173559a3b11a2c43eaeee4eb09556238
July 02, 2024

House of HR enhances security across its diverse organization with the Microsoft 365 E5 bundle

House of HR is a pan-European company specializing in Human Resources services including staffing, consultancy and recruitment. Headquartered in Belgium, it has around 5,000 employees located in over 800 branches. The company has an aggressive growth policy that includes the widespread acquisition of small to mid-sized organizations, which however retain a high degree of autonomy. Ensuring an excellent standard of security for all parts of the organization – and the data of the millions of candidates they process each year – is a challenge that the team has addressed with several Microsoft solutions such as the Microsoft 365 E5 bundle. Including security solutions Microsoft Defender, Microsoft Purview and Microsoft Sentinel, the new stack has successfully raised security KPIs and maturity levels across the entire company.

House of HR

“We’re a big, fast-growing company, and unlike most of our competition we are highly decentralized. We grow organically but also through acquisition, and the companies we’ve purchased are also growing fast. Obviously, the big challenge for my team is to ensure the security of all those entities, and the personal details of the millions of candidates we collectively deal with each year.”

Tom Verlinden, Digital Director and CISO at the House of HR is at the forefront of tackling that challenge. He expands on the central demand of his team’s approach to security, commenting: “Trust has to be the most important factor of any security solution, and that trust comes from the quality and the stability of that solution.

“That’s exactly what we’ve experienced: from the first day we had the full suite of Microsoft tools.”

The security challenge of decentralization

House of HR is a pan-European company specializing in HR services, particularly in staffing, consultancy, and recruitment. Headquartered in Belgium, it operates through various brands across different sectors, including IT, engineering, healthcare, and more. The company’s chief aim is to match skilled professionals with suitable job opportunities. It is growing quickly, and much of that growth is the result of acquisition.

“We refer to the companies we buy as PowerHouses,” explains Karel Hillewaere, Security Manager for House of HR. “These PowerHouses, particularly the smaller ones, might not have reached an ideal level of maturity regarding their security posture. Given the opportunity to share services with the wider organization, that maturity grows enormously,” comments Verlinden.

“For us, maintaining those organizations’ freedom to act autonomously and pursue their own trajectories is essential to our growth and development overall. But clearly, we have to make sure that their security systems are uniformly excellent. Ensuring we have a centralized security stack which works within a decentralized network of PowerHouses is a key aspect to our security strategy.”

“We also have to deal with identity,” adds Hillewaere. “We have around 15,000 users located over 800 branches all around Europe. Making sure all their devices are managed is essential. And the third essential element for us is setting up and maintaining a zero-trust environment.

A factor which made implementation of all three so much easier and efficient was House of HR’s commitment to the cloud, Verlinden adds. “It’s one of our strategic pillars, mostly because as a rapidly growing company we need excellent scalability that is just not possible with an on-premises environment,” he says.

“The other factor in our favor is a strong working relationship with both our partner, The Collective Consulting, and Microsoft, who supplied the technology and services to make the new security stack such a success.

“The Collective Consulting is a specialized firm whose expertise has helped House of HR prioritize features and resolve roadblocks in the deployment process.”

Security starts with identity

“If you cannot manage your identities properly, you cannot offer any real security at all. Five years ago, we took the first steps and created a new Active Directory linked to Microsoft Azure AD, which ensured that all our identities are centralized,” explains Verlinden.

The company had already developed a relationship with Microsoft with the rollout of Azure, and House of HR had also deployed the Microsoft 365 Suite to enhance its collaboration capabilities.

“We like to call ourselves Microsoft believers,” comments Hillewaere. “Everything we are doing around security operations and security governance is utilizing a lot of Microsoft tools.”

Commenting on the issue of device identity, Verlinden remarks: “As we grew as a company and Security Centralization became increasingly important, we saw that Microsoft was developing Intune, and its advantages, so we embraced that solution.”

Given the previous deployment of Microsoft 365 Suite and the company’s desire for enhanced, centralized security, the adoption of the E5 stack was a logical next step. Featuring powerful apps, including Microsoft Defender, Microsoft Purview and Microsoft Sentinel, the Microsoft 365 E5 bundle was the company’s first choice for an in-depth security solution.

Defender helps detect and respond rapidly to cyber-threats such as phishing, malware, and ransomware. Purview is designed to enhance the visibility of data and assets. It allows a company to secure and govern data across its estate while reducing risk and meeting compliance requirements. “In this context,” remarks Hillewaere, “we use it for data classification, to avoid data loss from mail, SharePoint, and so on.”

Deploying Sentinel allows organizations to uncover sophisticated threats and respond decisively with an intelligent, comprehensive security information and event management (SIEM) solution. In addition to a SIEM, the company has utilized Sentinel as a Security Orchestration, Automation, and Response (SOAR) solution. This allows the team to focus on tackling the more complex issues and mitigate against more sophisticated threats, while also ensuring the SOC benefits from advance warning of potential incidents.

Summarizing the company’s relationship with Microsoft, Verlinden remarks: “They provide pretty much everything we need. For us, Microsoft is a one-stop shop.”

Enhanced security leads to real-world results

Once the Microsoft 365 E5 security stack had been successfully deployed, the House of HR team saw almost immediate results. “Our endpoint KPIs have improved since the rollout, with incidents of phishing and other serious incidents lower,” confirms Hillewaere, adding: “The metrics we’ve got from Intune are also looking good.”

Microsoft Tooling is a key aspect of the SOC and now provides a high level of threat visibility. By using the services of The Collective Consulting, House of HR was able to use that visibility to stop attacks dead in their tracks. That visibility in the SOC has also helped the company build its roadmap to identify critical next steps.

But the security team did not want to rely solely on internal data to prove the effectiveness of the new set-up, and the increasing maturity of its security posture, including among those smaller PowerHouses that were a potential weak spot for the overall organization.

“Every year we have internal security audits, which give us more detail on process level scoring, and also CIS (Centre for Internet Security) assessments to measure our security controls. Overall, our level has increased to a score of 4.25 to 5,” he says. “While we’re yet to achieve our ultimate goal, it shows we are on the right track. And when it comes to the companies we acquire, we also did some tests. They tended to score between 1.5 and 2.5, but the day they moved to our central stack, they gained two to 2.5 points in maturity.”

The company has also underlined its credibility by achieving an ISO 270001 certification, which provides third-party evidence for effective management of an organization, including risk management, measurement and evaluation of performance, and decision-making processes. Of course, this also covers the organization’s approach to security.

“By certifying our services, including those of our powerhouses, we can prove to our customers that we are taking security seriously,” remarks Verlinden.

Security: a never-ending challenge

As House of HR emphasizes innovation and digitalization in its services, Microsoft's solutions encourage the adoption of a digital culture within the organization. This involves embracing new technologies and digital tools, fostering a culture of continuous adaptation to technological advancements.

“Yes, it’s a continuous evolution,” confirms Verlinden. “Five years ago, we started to concentrate on identity, then we looked at centralization. Then we looked at a more product level, and finally were more focused on the E5 tools and SIEM. “Being realistic, security is a never-ending story. That’s why at the company SOC (Security Operations Center), we always need to be vigilant for new types of threats. We have to identify the new threat factors, and then adapt.

“That can be from a change in technical control, a policy, or whatever, but it's continuously asking ourselves: what are our weaknesses, and how can we protect ourselves better? Whatever the answers, it’s good to know that we’ll have the support of Microsoft expertise and technology. And we are very much looking forward to exploring the opportunities that Microsoft Copilot for Security can offer us, in the future.”

“The other factor in our favor is a strong working relationship with both our partner, The Collective Consulting, and Microsoft, who supplied the technology and services to make the new security stack such a success.”

Karel Hillewaere, Security Manager, House of HR

Take the next step

Fuel innovation with Microsoft

A man wearing headphones and smiling

Talk to an expert about custom solutions

Let us help you create customized solutions and achieve your unique business goals.
A woman smiling and a pointing to a screen showing some statistics

Drive results with proven solutions

Achieve more with the products and solutions that helped our customers reach their goals.

Follow Microsoft