Secure Score baseline
We read your current score in the Microsoft Defender portal, break it down by Identity, Devices, Apps, and Data, and benchmark it against organisations of similar size.
Microsoft Secure Score already measures your tenant against dozens of controls across identity, devices, apps, and data. Most SMBs have never read it. We baseline it, benchmark it against businesses your size, and hand you a roadmap that works the few actions that move the needle - MFA, legacy auth, admin roles - before the long tail.
Ready to scope Secure Score for your business?
Every inclusion below is documented, delivered, and renewable under our standard agreement. No surprise scope. No silent exclusions.
We read your current score in the Microsoft Defender portal, break it down by Identity, Devices, Apps, and Data, and benchmark it against organisations of similar size.
A prioritised list led by the actions worth the most points for the least effort - MFA for all users, MFA for admins, blocking legacy authentication - then the long tail, ranked by impact.
Entra ID configuration reviewed against the controls Secure Score measures: admin role sprawl, MFA coverage, conditional access, banned passwords, and security defaults.
Where unmanaged devices and unconfigured Defender or Intune policies are dragging your score down, and what enrolling them buys you.
After remediation we re-baseline (changes take 24 to 48 hours to post) and give you a before-and-after you can show a board or an insurer.
Knowing where a service stops matters as much as knowing what it covers. Here’s what sits outside this engagement - so there are no awkward surprises later.
Microsoft publishes no 'right' Secure Score, and we won't invent one. We work the high-impact actions relevant to your business; the number follows. Chasing 100% means actioning controls you may not need.
Some improvement actions need a specific Microsoft 365 or Defender licence. We flag which, and the cost, but the licence itself is billed at cost, not bundled.
Secure Score measures your Microsoft tenant. A framework gap analysis against Essential Eight or CIS is broader, and is a separate, deeper engagement - see those pages.
Every engagement runs the same four steps. You always know which one we’re in and what comes next.
We connect to your Microsoft 365 tenant and read the current Secure Score across all four categories, with the comparison benchmark for businesses your size.
We rank every improvement action by points, effort, and user impact - and tell you honestly which ones are noise for a business like yours.
We action the high-impact items with your sign-off, or hand the list to your team, tracking each through the Defender portal's status workflow.
We re-baseline after the changes post, and report the uplift with a documented before-and-after.
Copilot Cowork is now generally available, and it is billed in a way that catches people out: a fixed seat plus a metered usage charge that can dwarf it. Here is how the pricing works, what it can cost, and every lever to cap the spend.
Read articleCompliance · 9 min readAuditors and insurers increasingly want both CIS Controls v8 and the Essential Eight. They overlap, but they aren't the same shape. Here's the control-by-control mapping we use - and the four CIS controls the Essential Eight quietly leaves you exposed on.
Read articleHow-to · 11 min readMicrosoft 365 Copilot is the most expensive per-user add-on a business will add this year. Most rollouts fail on the prep, not the technology. Here's the sequence we use to make sure it actually pays for itself.
Read articleVulnerability scans, Microsoft 365 audits, security posture reviews, and dark web exposure checks. Know where you stand before an attacker does - with a remediation plan you can actually act on.
Learn moreYour maturity against all eight ACSC mitigation strategies, scored to your target level, with a roadmap to close the gaps. The Australian baseline that primes, contracts, and cyber insurers increasingly ask you to prove.
Learn moreRoadmap, remediation, and ongoing attestation against the CIS Critical Security Controls and the Australian Essential Eight. Frameworks that actually get implemented, not just referenced.
Learn moreTell us what your current setup looks like. We’ll send back a quote, a transition plan, and a firm date you’d be onboarded - within 48 hours.