Security assessment: an illustrative scenario
Illustrative scenario. The company, people and figures here are fictional and were invented to show what an assessment produces. They are not a real client and are not a promise of results.
Cyber rating
64 / 100
Band: needs attention
Score by area
- Identity48
- Email70
- Devices66
- Data72
Fix first, ranked by risk and effort
- 1Require multi-factor authentication on all admin accountsRisk: HighEffort: Low
- 2Block legacy sign-in methods that bypass multi-factor authenticationRisk: HighEffort: Low
- 3Tighten anti-phishing and safe-links policiesRisk: MediumEffort: Low
- 4Remove 14 unused guest accountsRisk: MediumEffort: Low
- 5Review sign-in rules for shared mailboxesRisk: LowEffort: Low
The situation
A fictional 60-person professional services firm runs on Microsoft 365. A client’s security questionnaire and the firm’s cyber insurance renewal are both due within eight weeks. Nobody is sure how exposed the firm really is, and the IT supplier’s answer is “it’s fine”.
What the assessment looks at
A read-only review of configuration and exposure across identity, email, devices and data. Nothing is changed during the assessment. Findings are ranked by risk and by effort, so the firm can see what to do first.
What it might find
In this scenario, the summary page looks like the sample above. The largest gap is identity: some administrator accounts have no multi-factor authentication, and older sign-in methods still bypass it. Email protection is reasonable but could be tighter, and a set of forgotten guest accounts still has access.
The decision it enables
The five fixes are mostly configuration changes, not purchases. The owners can approve them in order, hand them to their existing IT supplier, and use the report as evidence for the client questionnaire and the insurer. They no longer have to take “it’s fine” on trust.
What could follow
The firm might ask for help making the changes and keeping them in place, which is what cost and security optimisation covers. Or it might do the work with its own supplier. The report belongs to the firm either way.