Fixed-price entry point
Your security posture measured against the CIS benchmark, at a fixed price and with no further obligation. Read-only — we don't change anything, we measure. The report is yours: implement the recommendations yourself, with your existing partner, or with us.
Your Microsoft 365 environment measured against the CIS benchmark — control by control, with a coverage score.
What's behind the number: which gaps are genuinely risky, and which just cost points.
Sorted by impact and effort. Quick wins first, projects clearly scoped.
One hour walking through the results — pitched for leadership and the board.
01
30 minutes: scope, access, scheduling. That's all we need from you.
02
Read-only access to your tenant. No changes, no disruption for your users.
03
Report plus a one-hour walkthrough. After that, you know where you stand and what comes first.
What the report looks like
Every finding names the risk, the priority, and the concrete action — no audit jargon somebody has to translate first.
Extract: findings & actions
Illustrative example — no client data
Legacy Authentication
Still active for several protocols — bypasses MFA entirely
→ Disable immediately, document any exceptions
Break-Glass Accounts
No dedicated emergency account with phishing-resistant sign-in
→ Two accounts with FIDO2 keys, excluded from Conditional Access
MFA Coverage
Full coverage for admins, gaps among standard users
→ Registration campaign, then enforce via Conditional Access
Update Rings (Intune)
Patches reach every device at once — no pilot ring
→ Staggered rings: Pilot → Broad → Critical
Guest Accounts
External access with no expiry date or review process
→ Quarterly access reviews, automate the lifecycle
What you get
Critical issues across identity, devices, collaboration, and infrastructure become visible — prioritised by impact and effort.
You'll see what's due this quarter, what should be budgeted for later, and which quick wins free up productivity right away.
A clear narrative plus a technical appendix you can hand straight to leadership, auditors, and partners.
Deep dives
Beyond the CIS review: pick a stream for a deep dive, or bundle several into a coordinated programme. Led by senior engineers who've delivered transformations inside Swiss organisations — most assessments ship in four weeks or less.
Device baselines, Intune readiness, update compliance, and end-user experience metrics.
Azure governance, landing zones, cost control, and automation maturity.
Entra ID configuration, Conditional Access, lifecycle automation, and privileged access workflows.
Secure Score, incident response readiness, backup strategy, and policy alignment with Swiss requirements.