We start every engagement by understanding your environment as it actually is, not as it should be. Every client gets a Cyber Essentials assessment. Microsoft 365 clients also get a Zero Trust review and automated tenant testing, so the picture is built from evidence rather than opinion.
Security improvements only work when they're based on evidence. Guesswork leads to unnecessary tools, complexity and cost, and it often misses the actual risks.
We assess what is actually configured in your environment, not what should be there or what similar organisations have. Your baseline is specific to you.
We prioritise issues that materially reduce the likelihood and impact of common cyber attacks, not compliance theatre or vendor-preferred solutions.
Microsoft 365, Google Workspace, your own servers or a mixture of all three. Our onboarding focuses on what is actually deployed across identity, devices, cloud services and network access.
Every new client gets a Cyber Essentials assessment, because it is the UK baseline and it applies to any environment. Where a business runs on Microsoft 365 we go considerably further, because the tooling exists to test that platform properly and it would be a waste not to use it.
If your business runs on Microsoft 365, we combine three complementary views of your environment. Each one catches things the others do not.
For every other environment we assess against the current Cyber Essentials standard. It is platform independent by design, which is exactly why the NCSC built it that way.
Maester is an open source test automation framework for Microsoft 365 security. Rather than someone eyeballing your settings and forming an opinion, it runs hundreds of individual tests against your tenant through the Microsoft Graph API and reports which pass and which fail, each with a link to the exact setting that needs changing.
It bundles several recognised baselines into one report, including the CIS Microsoft 365 Foundations Benchmark, the US CISA SCuBA baselines, the Entra ID Security Config Analyzer (EIDSCA) and the Office 365 Recommended Configuration Analyzer (ORCA), alongside its own community-curated tests.
Two things matter about it for you. It is free and open source, so you are not paying us to licence a tool. And because it is automated, it can be run again in six months to prove nothing has quietly drifted. See maester.dev.
One clear picture of where you are, what gaps exist and what to do next. Step one applies to every client. Steps two and three apply where you run Microsoft 365.
We assess your environment against the five Cyber Essentials controls in the standard currently in force. This produces a structured gap analysis that is honest about where you stand, and it applies whether you run Microsoft 365, Google Workspace, your own servers or a mixture.
We identify which controls already meet the standard, which are partially implemented, and which present certification blockers or material risk, all before any remediation work begins.
Using Microsoft's Zero Trust framework, we assess your environment across the six core pillars, giving a complete, configuration-based view of your current security posture.
The assessment is non-intrusive. We review policies, access controls, and security posture without disrupting your live systems or requiring downtime.
The Zero Trust assessment tells us how your environment is designed. Maester tells us how it is actually behaving right now, by running hundreds of individual security tests against your Microsoft 365 tenant and reporting exactly which pass and which fail.
This is the part that turns judgement into evidence. Every failed test comes with a direct link to the setting that needs changing, so remediation is specific rather than general. Because the tests are automated and repeatable, we can run them again later and prove your posture has not drifted.
Maester is free, open source and community driven. We use it because it produces better evidence than a manual review, not because anyone pays us to.
Traditional perimeter security assumes that everything inside the network is safe. Zero Trust removes that assumption. It requires explicit verification for every access request, regardless of location or device.
Microsoft's Zero Trust framework is the natural starting point for organisations running on Microsoft 365 and Azure. The NCSC has confirmed that Cyber Essentials is compatible with Zero Trust architecture, and the assessment findings map well onto the five CE controls. This assessment applies to Microsoft 365 environments. For other platforms, the Cyber Essentials assessment stands on its own.
This dual-framework approach means your onboarding produces two clear outputs from a single assessment: a modern security posture view, and a practical compliance picture against the UK government standard.
Verify every user. Always. MFA, conditional access, and privileged identity management.
Ensure every device meets compliance requirements before granting access to data or services.
Control access to apps and discover shadow IT. Only approved apps, properly governed.
Know where your data is, classify it, and apply appropriate protection policies.
Segment networks, control remote access, and harden servers against common attack vectors.
Microsoft's Zero Trust approach is publicly documented and aligned to NIST and NCSC guidance. It provides a practical structure for assessing Microsoft 365 and Azure environments against modern security principles. For more, see Microsoft's Zero Trust documentation and the NCSC's Zero Trust architecture guidance.
At the end of onboarding, you have a documented picture of your current posture, what needs to change and in what order, without the jargon.
For Microsoft 365 clients, an interactive Maester report showing every security test run against your tenant, which passed, which failed, and the exact setting to change for each one.
A documented view of your current security posture across Microsoft services: identity, devices, applications, data and network.
A structured comparison against all five CE controls, with each control clearly marked as met, partial or a blocker, with evidence.
Risk-based recommendations in order of impact, not vendor preference or what is easiest to sell. Each item is explained in plain language.
If Cyber Essentials is your goal, you leave onboarding knowing exactly what needs to happen, how long it will take, and what we'll do together to get there.
A one-time baseline tells you where you are. Ongoing support keeps you there, and keeps you certified.
We don't just identify gaps and hand you a to-do list. We fix them: configuring controls, rolling out MFA, hardening devices and managing patches on your behalf.
Security posture changes every time a user joins, a device is added, or a policy is updated. We monitor continuously so your controls stay aligned to Cyber Essentials requirements.
With ongoing support in place, your annual Cyber Essentials renewal becomes a formality, not a scramble to discover gaps you didn't know existed.
Whether you're preparing for Cyber Essentials certification or want a clearer picture of your Microsoft security posture, we start with evidence, not assumptions. And we don't sell tools.
Contact Us 📅 Book a Short Call About Cyber Essentials Virtual CISO