Assessments & Audits

How secure is your Microsoft environment, really?

Most environments have grown organically over the years — nobody quite knows anymore what's configured and what's left exposed. A Worxspace assessment replaces the gut feeling with evidence: measured, prioritised, actionable.

Fixed-price entry point

CIS Review for SMEs — CHF 2,500

Your security posture measured against the CIS benchmark, at a fixed price and with no further obligation. Read-only — we don't change anything, we measure. The report is yours: implement the recommendations yourself, with your existing partner, or with us.

CIS L1 Coverage Report

Your Microsoft 365 environment measured against the CIS benchmark — control by control, with a coverage score.

Secure Score Analysis

What's behind the number: which gaps are genuinely risky, and which just cost points.

Prioritised Action Roadmap

Sorted by impact and effort. Quick wins first, projects clearly scoped.

Executive Readout

One hour walking through the results — pitched for leadership and the board.

How it works

01

Kick-off

30 minutes: scope, access, scheduling. That's all we need from you.

02

Review

Read-only access to your tenant. No changes, no disruption for your users.

03

Readout

Report plus a one-hour walkthrough. After that, you know where you stand and what comes first.

Fixed price CHF 2,500 · Read-only access · The report and roadmap are yours

What the report looks like

Findings you can actually act on.

Every finding names the risk, the priority, and the concrete action — no audit jargon somebody has to translate first.

Extract: findings & actions

Illustrative example — no client data

Legacy Authentication

Still active for several protocols — bypasses MFA entirely

Disable immediately, document any exceptions

P1

Break-Glass Accounts

No dedicated emergency account with phishing-resistant sign-in

Two accounts with FIDO2 keys, excluded from Conditional Access

P1

MFA Coverage

Full coverage for admins, gaps among standard users

Registration campaign, then enforce via Conditional Access

P2

Update Rings (Intune)

Patches reach every device at once — no pilot ring

Staggered rings: Pilot → Broad → Critical

P2

Guest Accounts

External access with no expiry date or review process

Quarterly access reviews, automate the lifecycle

P3

What you get

Evidence, not guesswork.

Actionable Risk Profile

Critical issues across identity, devices, collaboration, and infrastructure become visible — prioritised by impact and effort.

Roadmap & Investment Plan

You'll see what's due this quarter, what should be budgeted for later, and which quick wins free up productivity right away.

Executive-Ready Report

A clear narrative plus a technical appendix you can hand straight to leadership, auditors, and partners.

Deep dives

More depth, where you need it.

Beyond the CIS review: pick a stream for a deep dive, or bundle several into a coordinated programme. Led by senior engineers who've delivered transformations inside Swiss organisations — most assessments ship in four weeks or less.

Modern Workplace

Device baselines, Intune readiness, update compliance, and end-user experience metrics.

Cloud Foundations

Azure governance, landing zones, cost control, and automation maturity.

Identity & Access

Entra ID configuration, Conditional Access, lifecycle automation, and privileged access workflows.

Security Posture

Secure Score, incident response readiness, backup strategy, and policy alignment with Swiss requirements.

Do you know where your environment stands?

30 minutes with an engineer — not a sales call. You'll speak directly with the people who'd actually run your environment.

Next stepWorxspace ManagedAfter the review: an operating model that fixes the findings for good — CIS baseline included.