Blue North Cyber

Cybersecurity audits & assessments

Your cloud was
set up once.
Nobody checked it since.

Independent security audits of Microsoft 365, Google Workspace, AWS, and your website — measured against published CIS benchmarks, not opinion.

Benchmark run
Illustrative

CIS Microsoft 365 Foundations

  • 1.1.1Admin accounts are separate and unlicensedPass
  • 1.2.1MFA enforced for all usersFail

    4 accounts exempt via a legacy exclusion group

  • 5.2.2Legacy authentication is blockedFail

    IMAP and POP still permitted tenant-wide

  • 6.2.1External mail forwarding is disabledPass
  • 3.1.1Unified audit log is enabledChecking
2 findings so farEvidence captured

What gets checked

  • Microsoft 365

    CIS M365 Foundations

    Conditional access, legacy auth, admin roles, mail flow, sharing defaults.

  • Google Workspace

    CIS Workspace Foundations

    2-step verification, OAuth app access, Drive sharing, admin roles.

  • AWS

    CIS AWS Foundations

    IAM and root access, CloudTrail, public S3, open security groups.

  • Your website

    OWASP · CIS Controls v8

    TLS, security headers, DNS, SPF/DKIM/DMARC, exposed admin panels.

How it works

  1. 01

    Scope

    Agree the environments and the boundaries in writing. Fixed fee from here.

  2. 02

    Assess

    Read-only access. Every setting checked against its benchmark.

  3. 03

    Report

    What's wrong, what it means, and what to fix first — then a call on it.

What you get

  • Executive summary, written for someone who isn't in security
  • Findings register with the benchmark reference and evidence behind each one
  • Remediation roadmap, ordered by what actually reduces risk
See the engagements

Find out where you actually stand.

One short call covers which tenants you run and what you need. If it isn't a fit, you'll be told.

Fixed scope, fixed fee · Quoted after a short call