NO CHARGE, NO OBLIGATION

Get your free security and AI readiness benchmark

We review your Microsoft 365 against Cyber Essentials and Microsoft's own security baselines, and show you what a Copilot rollout would expose. You get the report whether or not you take it any further.

What you get

A short written report covering seven things.

Identity and access

How multi-factor authentication is configured, whether old sign-in methods are still enabled, how many people have full administrator rights, and whether your conditional access policies are enforced or still in report-only mode.

Devices and Data

For managed devices, we report encryption, patch currency, and anything running past Microsoft's support date, along with how your SharePoint and OneDrive sharing is set. Where they are not managed, we count them and say so because if nothing is managing a laptop, nobody can tell you whether it is encrypted or patched, including you. That gap is usually the most useful thing in the report.

Cyber Essentials alignment

Where you sit against the five controls, including the two that became automatic failures in April 2026: multi-factor authentication on cloud services and security updates within fourteen days. How much of this we can see depends on whether your devices are managed, rather than on which control it is, and the report is explicit about which parts it could not reach.

What you are paying for

For every licence you hold, how many seats are assigned, and which of them are on leavers, blocked accounts and shared mailboxes. Free licences are marked as free, so the figure you are looking at is the one you could actually stop paying.

Signs of a compromised mailbox

A check of every mailbox for the rules an attacker leaves behind after taking one over, quietly hiding or forwarding mail about invoices and payments. It is an indicator check rather than a full investigation, and we are careful to say which.

AI exposure

Which third-party and AI tools your staff have connected to your Microsoft 365, and what a Copilot rollout would surface.

Applications with standing access

Separate from what your staff have connected, the applications with permissions across your whole tenant can reach every mailbox or file without anyone signing in. Most are legitimate. The report asks whether anyone can still say what each one is for, and the dates it gives make that a short conversation.

Then a prioritised list of what to fix, in plain language, with an indication of which items we would handle as part of managed support and which would be a piece of project work.

How it works

Nothing is installed. We ask you to grant read-only access to your Microsoft 365 tenant. Withdrawing it is two steps whenever you choose disable the read-only account, and remove the approval in your Microsoft admin centre.

Nothing runs on your computers either. No agent, no script for your staff, nothing for anyone to install every check reads what your machines already report to Microsoft. One of your administrators approves the read-only access once, from a link we send, and that is the whole of what we need from you.

It takes about fifteen minutes of your time for one approval and a read-only account, and under half an hour of ours to run. You will have the report within a week.

Who it's for

Businesses of roughly ten to fifty people running Microsoft 365. It is genuinely free, and there is no obligation, even if you already have an IT provider and simply want a second opinion on how your systems are set up.

“Responses to calls logged via the help desk are always prompt, with issues dealt with quickly and efficiently. An ideal solution for a smaller business that doesn’t require a full-time, in-house IT support service.”
— Dewberry Redpoint — client since 2020