Security & Compliance

Know where you stand, then stay there.

A one-off Assessment scores your Microsoft 365 environment and hands you a fix-it roadmap. Managed Compliance keeps you there after, with a living record you can hand to an insurer, a regulator, or a tender.

What we check · the Assessment

Four pillars. Nothing assumed.

01 · IDENTITY & ACCESS

Who can get in

  • MFA enforcement across all accounts, including admins
  • Conditional Access policy coverage
  • Privileged account exposure
  • Legacy authentication still enabled
02 · DATA PROTECTION

Where data leaks

  • Sharing & permission sprawl in SharePoint, OneDrive, Teams
  • Data Loss Prevention coverage
  • Retention alignment with POPIA / GDPR
  • External sharing exposure
03 · DEVICE & ENDPOINT

What connects

  • Intune enrolment coverage & policy gaps
  • Unmanaged devices with tenant access
  • Patch & update compliance
04 · COMPLIANCE POSTURE

What you can prove

  • Existing documentation, or the absence of it
  • Audit trail availability
  • Alignment against POPIA / GDPR / industry rules
  • Cyber-insurance baseline requirements
The deliverable

An assessment you can hold, not a conversation.

Every engagement leaves you with five things, not a verbal summary.

STEP 01 · SCORED REPORT

Plain-English exposure score

Across your whole Microsoft 365 environment, by pillar.

STEP 02 · ROADMAP

Fixes ranked by risk and effort

So you know what to do first, not just what's wrong.

STEP 03 · REGISTER

The record insurers and clients ask to see

A living compliance register, not a one-time PDF.

STEP 04 · EVIDENCE

Documented proof your posture changed

Before-and-after evidence for every remediated finding.

STEP 05 · SUMMARY

One page your board can actually read

An executive summary in plain language, not jargon.

5–15
Business days to a scored report
0
Downtime. Nothing installed on your users
Quote
Scoped to your tenant on a short discovery call
How Managed Compliance works

Three steps. No jargon.

STEP 01

Assess & score

We assess your tenant's technical and organisational security measures against POPIA, GDPR, and insurance baselines. Scored report in 5–15 business days from complete access and evidence.

STEP 02

Remediate & prove

We fix what we found and document every change as evidence, with a written independence note wherever we implemented the control ourselves.

STEP 03

Monitor & report

Ongoing Managed Compliance: monthly reporting, a living register, and scheduled re-assessment.

A 40-user firm assumed their setup was fine. The assessment found no Conditional Access, no MFA on three admin accounts, and no compliance register. Eight weeks later the roadmap findings were remediated, evidenced as at the re-assessment date.

ILLUSTRATIVE ENGAGEMENT · DETAILS ANONYMISED

Need your computers and devices covered too?

Managed IT covers monitoring, patching, backup and help desk, with Microsoft 365 governance built in at the higher tiers.

See Managed IT

Ready to see where you stand?

See Pricing & Calculator