"Don't wait for a crisis to happen to use the kill switch," warned Prakash Venkata to UC Today.
It is a stark imperative from a man who has spent two decades fortifying the digital perimeter of one of the world's largest professional services networks. As a Partner in PwC’s cybersecurity practice and the firm’s Global Cyber Alliances lead, Venkata does not deal in hypotheticals. Rather, he operates in the visceral reality of supply chain vulnerabilities and nation-state actors.
For years, the philosophy governing enterprise IT and security was one of bespoke fortification. You build a unique castle, dig a custom moat, and assume your idiosyncratic architecture offers obscurity, if not security. That era is drawing to a close. PwC recently became the first professional services firm to pilot Microsoft’s Baseline Security Mode (BSM), a rigorous, standardized posture designed to eliminate the configuration drift that often plagues modern tenants.
The pilot was intended as a stress test of the tension between operational agility and existential security. "The challenge is that it’s not just one organization getting impacted when there is a vulnerability; the entire supply chain is affected," Venkata explained. By opening the hood of PwC’s complex, federated network to Microsoft’s engineering teams, Venkata and his colleagues have provided a roadmap for how enterprises can navigate the transition to a "secure-by-default" world without disrupting business operations.
- Resilience Engineering Lessons from James Kretchmar: Learning from the AWS 2025 Outage
- What the AWS Outage Tells Leaders About Risk, Resilience and Reality: When the Cloud Collapsed
The Professional Services Stress Test
PwC embodies the ultimate edge case for any standardized security framework. Unlike, for example, a manufacturing entity with a static perimeter, PwC is a mobile army of auditors, consultants, and tax professionals connecting from thousands of different networks, often embedded within client environments. If a security baseline can withstand scrutiny here, it can withstand scrutiny anywhere.
However, the initial deployment of the pilot immediately illuminated the "load-bearing" skeletons in the corporate closet; specifically, legacy protocols that refused to die.
The first casualty of the audit was the assumption of modernization. IT leaders often believe their environments are cleaner than they are, but BSM’s observability tools revealed the stubborn persistence of deprecated technologies. "One was the Exchange Web Services, which we all thought were deprecated and gone. We still noticed that being in our environment," Venkata admitted.
Technical debts are one thing, but these are fundamentally dormant vulnerabilities waiting for a threat actor to exploit them. The complexity of a global firm means that somewhere, in some territory, a legacy file-sharing protocol is still humming along because a specific client engagement ten years ago required it.
Venkata noted the difficulty of managing this shadow infrastructure: "We were using deprecated or non-compliant ones globally in some way or another, and we did not have visibility into it to observe, monitor, or take it out of the environment." The pilot forced Venkata and PwC to confront a complex reality. You cannot secure what you cannot see, and you cannot modernize what you mistakenly believe is already gone.
The Friction of Standardization With Microsoft Enterprise Security
Perhaps the most treacherous aspect of standardizing security postures is not technical, but cultural. In a federated organization, standardization often feels like an imposition; a loss of local control ceded to a central bureaucracy. When Venkata’s team moved to enforce these new baselines, they encountered significant friction from territories that viewed their custom configurations as essential to client delivery.
The pushback was rooted in the dangerous logical fallacy of survivorship bias. Local admins argued that their bespoke setups were safe simply because they had not yet suffered a catastrophe. "That communication was difficult because they said, 'We've been using it, we haven't been breached, so what does it mean if we turn it off completely?'" Venkata recalled. This is the classic CISO’s dilemma of trying to enforce hygiene without disrupting revenue.
The solution required a diplomatic pivot. Rather than wielding security as a blunt instrument, Venkata’s team had to frame the transition as a modernization of client service. The argument was about protecting the client’s sensitive data from emerging threats that local teams might not even be aware of.
"We can transition in such a way that the clients do not feel the impact while we monitor for security challenges," Venkata noted. By segregating sensitive data and empowering local admins to manage the transition within the new guardrails, PwC managed to enforce the baseline without severing the business relationship.




