Evidence First · NCSC Aligned · Automated Testing · London & Home Counties

Client Onboarding &
Security Baseline

We start every engagement by understanding your environment as it actually is, not as it should be. Every client gets a Cyber Essentials assessment. Microsoft 365 clients also get a Zero Trust review and automated tenant testing, so the picture is built from evidence rather than opinion.

Facts Before Fixes

Security improvements only work when they're based on evidence. Guesswork leads to unnecessary tools, complexity and cost, and it often misses the actual risks.

🔍

Evidence-Based

We assess what is actually configured in your environment, not what should be there or what similar organisations have. Your baseline is specific to you.

🎯

Risk-Focused

We prioritise issues that materially reduce the likelihood and impact of common cyber attacks, not compliance theatre or vendor-preferred solutions.

🏗️

Built for Real Environments

Microsoft 365, Google Workspace, your own servers or a mixture of all three. Our onboarding focuses on what is actually deployed across identity, devices, cloud services and network access.

What We Assess Depends on What You Run

Every new client gets a Cyber Essentials assessment, because it is the UK baseline and it applies to any environment. Where a business runs on Microsoft 365 we go considerably further, because the tooling exists to test that platform properly and it would be a waste not to use it.

Microsoft 365 environments

Three assessments

If your business runs on Microsoft 365, we combine three complementary views of your environment. Each one catches things the others do not.

  • Cyber Essentials (current NCSC standard). The five technical controls that define the UK baseline, assessed against the version in force at the time.
  • Microsoft Zero Trust assessment. A configuration-based review across the six Zero Trust pillars, covering how identity, devices, apps, data, infrastructure and network are actually set up.
  • Maester. Automated testing of your Microsoft 365 tenant against hundreds of published security tests, producing evidence rather than opinion.
Google Workspace, on-premises & hybrid

Cyber Essentials assessment

For every other environment we assess against the current Cyber Essentials standard. It is platform independent by design, which is exactly why the NCSC built it that way.

  • The same five controls. Firewalls, secure configuration, access control, malware protection and security update management, applied to whatever you actually run.
  • The same honest output. A gap analysis marking each control as met, partial or a blocker, with evidence and a prioritised remediation order.
  • No pretending. Zero Trust assessment tooling and Maester are Microsoft specific. We will not invent a Google Workspace or on-premises equivalent in order to appear more thorough.

Jargon Explained: Maester

Maester is an open source test automation framework for Microsoft 365 security. Rather than someone eyeballing your settings and forming an opinion, it runs hundreds of individual tests against your tenant through the Microsoft Graph API and reports which pass and which fail, each with a link to the exact setting that needs changing.

It bundles several recognised baselines into one report, including the CIS Microsoft 365 Foundations Benchmark, the US CISA SCuBA baselines, the Entra ID Security Config Analyzer (EIDSCA) and the Office 365 Recommended Configuration Analyzer (ORCA), alongside its own community-curated tests.

Two things matter about it for you. It is free and open source, so you are not paying us to licence a tool. And because it is automated, it can be run again in six months to prove nothing has quietly drifted. See maester.dev.

How Onboarding Works

One clear picture of where you are, what gaps exist and what to do next. Step one applies to every client. Steps two and three apply where you run Microsoft 365.

1
Every environment

Cyber Essentials Gap Analysis

We assess your environment against the five Cyber Essentials controls in the standard currently in force. This produces a structured gap analysis that is honest about where you stand, and it applies whether you run Microsoft 365, Google Workspace, your own servers or a mixture.

We identify which controls already meet the standard, which are partially implemented, and which present certification blockers or material risk, all before any remediation work begins.

What the gap analysis identifies:

  • Controls already meeting Cyber Essentials v3.3 requirements
  • Partial controls requiring additional configuration or documentation
  • Hard blockers that would prevent certification without remediation
  • Priority order for remediation, by risk rather than by complexity
2
Microsoft 365 environments only

Microsoft Zero Trust Assessment

Using Microsoft's Zero Trust framework, we assess your environment across the six core pillars, giving a complete, configuration-based view of your current security posture.

The assessment is non-intrusive. We review policies, access controls, and security posture without disrupting your live systems or requiring downtime.

What we assess across six Zero Trust pillars:

  • Identity: authentication, MFA, conditional access, privileged accounts
  • Devices: compliance policies, device management, endpoint protection
  • Applications: access controls, Shadow IT, approved app policies
  • Data: classification, protection policies, data loss prevention
  • Infrastructure: server hardening, patch status, configuration baselines
  • Network: perimeter controls, segmentation, remote access
3
Microsoft 365 environments only

Automated Tenant Testing with Maester

The Zero Trust assessment tells us how your environment is designed. Maester tells us how it is actually behaving right now, by running hundreds of individual security tests against your Microsoft 365 tenant and reporting exactly which pass and which fail.

This is the part that turns judgement into evidence. Every failed test comes with a direct link to the setting that needs changing, so remediation is specific rather than general. Because the tests are automated and repeatable, we can run them again later and prove your posture has not drifted.

What the automated testing covers:

  • Entra ID identity and conditional access configuration, via the EIDSCA baseline
  • The CIS Microsoft 365 Foundations Benchmark
  • The US CISA SCuBA secure configuration baselines
  • Exchange Online configuration, via ORCA
  • Community-curated best practice tests maintained by the Maester project

Maester is free, open source and community driven. We use it because it produces better evidence than a manual review, not because anyone pays us to.

A Framework Built for Modern Environments

Traditional perimeter security assumes that everything inside the network is safe. Zero Trust removes that assumption. It requires explicit verification for every access request, regardless of location or device.

Microsoft's Zero Trust framework is the natural starting point for organisations running on Microsoft 365 and Azure. The NCSC has confirmed that Cyber Essentials is compatible with Zero Trust architecture, and the assessment findings map well onto the five CE controls. This assessment applies to Microsoft 365 environments. For other platforms, the Cyber Essentials assessment stands on its own.

This dual-framework approach means your onboarding produces two clear outputs from a single assessment: a modern security posture view, and a practical compliance picture against the UK government standard.

🆔

Identity

Verify every user. Always. MFA, conditional access, and privileged identity management.

💻

Devices

Ensure every device meets compliance requirements before granting access to data or services.

📱

Applications

Control access to apps and discover shadow IT. Only approved apps, properly governed.

📂

Data

Know where your data is, classify it, and apply appropriate protection policies.

🌐

Network & Infrastructure

Segment networks, control remote access, and harden servers against common attack vectors.

ℹ️

About Microsoft's Zero Trust Framework

Microsoft's Zero Trust approach is publicly documented and aligned to NIST and NCSC guidance. It provides a practical structure for assessing Microsoft 365 and Azure environments against modern security principles. For more, see Microsoft's Zero Trust documentation and the NCSC's Zero Trust architecture guidance.

Clear Outputs. Practical Next Steps.

At the end of onboarding, you have a documented picture of your current posture, what needs to change and in what order, without the jargon.

🧪

Automated Test Report

For Microsoft 365 clients, an interactive Maester report showing every security test run against your tenant, which passed, which failed, and the exact setting to change for each one.

📊

Security Baseline Report

A documented view of your current security posture across Microsoft services: identity, devices, applications, data and network.

🔍

Cyber Essentials Gap Analysis

A structured comparison against all five CE controls, with each control clearly marked as met, partial or a blocker, with evidence.

📋

Prioritised Remediation Plan

Risk-based recommendations in order of impact, not vendor preference or what is easiest to sell. Each item is explained in plain language.

🗺️

A Clear Path to Certification

If Cyber Essentials is your goal, you leave onboarding knowing exactly what needs to happen, how long it will take, and what we'll do together to get there.

Onboarding Is the Beginning, Not the End

A one-time baseline tells you where you are. Ongoing support keeps you there, and keeps you certified.

🔧

Hands-On Remediation

We don't just identify gaps and hand you a to-do list. We fix them: configuring controls, rolling out MFA, hardening devices and managing patches on your behalf.

🔄

Continuous Monitoring

Security posture changes every time a user joins, a device is added, or a policy is updated. We monitor continuously so your controls stay aligned to Cyber Essentials requirements.

📅

Annual Renewal Support

With ongoing support in place, your annual Cyber Essentials renewal becomes a formality, not a scramble to discover gaps you didn't know existed.

Start With Clarity

Begin With a Baseline

Whether you're preparing for Cyber Essentials certification or want a clearer picture of your Microsoft security posture, we start with evidence, not assumptions. And we don't sell tools.

Contact Us 📅 Book a Short Call About Cyber Essentials Virtual CISO