How we work
Assess, Improve, Support. They are not stages you have to move through in order, and none of them is a prerequisite for the others. Pick the one that matches the problem you have.
An assessment answers a question you cannot answer from the inside: what is actually configured, and where does that leave you. We read the configuration directly, work out what it means in practice, and hand back something your team can act on.
The subject is up to you. It might be the whole estate, or one product area you have doubts about, or a design you are about to commit to, or the provider you already pay to run your security.
Findings ranked by real risk rather than by how many controls failed, each carrying the evidence behind it, the reasoning, and the fix that closes it. A report you can put in front of a board or an insurer, and a working session with your team to go through it properly rather than emailing a PDF and disappearing.
Found: Legacy authentication still permitted, bypassing MFA entirely for a third of accounts.
Fixed: Conditional Access policy blocking legacy auth, phased in over two weeks, with a short exception list for the service accounts that genuinely needed it.
This is the kind of gap a questionnaire never surfaces. Nobody remembers a protocol setting from three IT managers ago, so we read the sign-in logs instead of asking.
At some point somebody has to do the work. An Improve engagement is a defined piece of engineering with a scope we agree in advance, a fee we quote before we start, and a date it finishes. No open-ended time and materials, and no retainer required.
It does not have to follow an assessment. Plenty of clients already know what needs doing and simply do not have the hours or the specific expertise on staff.
Found: Sensitivity labels had existed for three years and had never been applied to a single document.
Fixed: Label taxonomy rebuilt around how the business actually classifies work, auto-labelling piloted in Finance, then rolled out tenant-wide over four weeks.
A defined project with a real finish line was the right shape here. There was no need for an ongoing relationship to close it.
Estates do not hold still. New starters, new licences, new integrations, and new Microsoft features arriving every month whether you asked for them or not. Support keeps senior Microsoft security expertise available to your team without you having to hire it.
This is deliberately not a managed service. We are not taking your monitoring contract or putting an agent on everything. Your team stays in charge; we are the people they call when something is outside what they have done before.
Found: A re-assessment six weeks after an initial fix caught a newly onboarded app registration holding tenant-wide mail read access, granted without review.
Fixed: Consent revoked the same day, and an app governance process put in place so the next one cannot be granted silently.
This is the argument for staying involved. A point-in-time assessment catches what is wrong that week. Security posture is a moving target.
Independent assurance
Most organisations that outsource security have no way to check the work. The reporting comes from the same provider doing the configuring, and a monthly service summary is not evidence. We read your tenant directly and show you the difference between what your provider says is in place and what is actually there.
Common questions
No. If you already know what needs doing, we can go straight to doing it. An assessment is useful when the question is genuinely open, and a waste of your money when it is not.
For an assessment, read-only. A dedicated application identity, never a personal login, with the minimum Microsoft Graph, Azure RBAC and, where relevant, Exchange Online permissions the work requires. Nothing is enabled until an administrator in your organisation approves it, and we check every permission before we start so you can see exactly what we can reach. Work that changes things uses separate access, scoped to the job and approved on its own terms.
An assessment is usually a few working days from access being granted to a report in your hands, depending on the size of the estate. Project timelines depend entirely on the work, and we give you a date before you commit rather than after.
Often more so. Outsourcing security to a provider does not tell you whether the work is being done, and the reporting you receive comes from the same people doing the configuring. We read your tenant independently and show you what is actually in place. We are not pitching to replace your provider, and the review does not arrive with a proposal to take over the contract.
Recognised security benchmarks for what can be scored, and Microsoft's own best-practice guidance for the products themselves. The same evidence is cross-mapped to NIST CSF, ASD Essential 8 and ISO 27001, so you can speak to whichever framework your board, client or insurer cares about without commissioning a second piece of work.
Regularly, and it usually goes well. We are specialists rather than a general IT provider, so we are not competing with them for the rest of your IT. Where we are reviewing a provider's work rather than working alongside them, we will tell you that up front.
Describe the problem and we will tell you which of the three actually fits, including when the answer is that you do not need us yet.