Cybersecurity audits & assessments
Your cloud was
set up once.
Nobody checked it since.
Independent security audits of Microsoft 365, Google Workspace, AWS, and your website — measured against published CIS benchmarks, not opinion.
CIS Microsoft 365 Foundations
- 1.1.1Admin accounts are separate and unlicensedPass
- 1.2.1MFA enforced for all usersFail
4 accounts exempt via a legacy exclusion group
- 5.2.2Legacy authentication is blockedFail
IMAP and POP still permitted tenant-wide
- 6.2.1External mail forwarding is disabledPass
- 3.1.1Unified audit log is enabledChecking
What gets checked
Microsoft 365
CIS M365 Foundations
Conditional access, legacy auth, admin roles, mail flow, sharing defaults.
Google Workspace
CIS Workspace Foundations
2-step verification, OAuth app access, Drive sharing, admin roles.
AWS
CIS AWS Foundations
IAM and root access, CloudTrail, public S3, open security groups.
Your website
OWASP · CIS Controls v8
TLS, security headers, DNS, SPF/DKIM/DMARC, exposed admin panels.
How it works
- 01
Scope
Agree the environments and the boundaries in writing. Fixed fee from here.
- 02
Assess
Read-only access. Every setting checked against its benchmark.
- 03
Report
What's wrong, what it means, and what to fix first — then a call on it.
What you get
- Executive summary, written for someone who isn't in security
- Findings register with the benchmark reference and evidence behind each one
- Remediation roadmap, ordered by what actually reduces risk
Find out where you actually stand.
One short call covers which tenants you run and what you need. If it isn't a fit, you'll be told.
Fixed scope, fixed fee · Quoted after a short call