I will audit and harden your microsoft 365 security
Information Security Engineer
About this Gig
Your M365 tenant ships configured for convenience not security.
Legacy auth enabled, audit logging incomplete, external sharing wide open. These are the gaps attackers exploit.
I find and fix them before they do.
I'm an SC-200 certified analyst at a national CERT (CSIRT), handling real incidents across government and critical infrastructure. I bring that same rigor to your tenant.
What You Get:
⯈ Secure Score deep-dive with prioritized actions
⯈ MFA & Conditional Access gap analysis
⯈ Email auth verdict SPF, DKIM, DMARC pass/fail
⯈ Defender, DLP & external sharing review
⯈ Admin role sprawl check
⯈ Professional PDF report with remediation roadmap
Why It Matters: 43% of cyberattacks target small businesses 14% of cyber insurance claims denied for non-compliance A misconfigured tenant can void your coverage
Ideal for SMBs, startups prepping for SOC 2/ISO 27001, IT managers inheriting a tenant, or MSPs needing white-label audits.
Certs: SC-200 | SentinelOne ×3 | Fortinet FCA | CISA ICS300 Background: 3+ yrs SOC, VAPT, SIEM (QRadar, ELK), EDR, IR. BSc Cyber Security (Plymouth).
Message me before ordering to confirm scope.
Operating system:
Windows
•
Linux
•
Unix
•
Vmware
•
BSD
FAQ
Do I need to give you admin access?
For the Basic and Standard packages, I can work with read-only admin access or shared Secure Score exports. For Premium (remediation), I'll need Security Administrator or equivalent access, which we'll arrange securely.
What Microsoft 365 licenses do you support?
All plans including Business Basic, Business Standard, Business Premium, E3, and E5. I'll note which recommendations require specific license tiers in the report.
Will this help with my cyber insurance application?
Yes. The report is specifically designed to demonstrate security posture to insurers. It covers the controls most cyber insurance questionnaires ask about: MFA, email authentication, admin access controls, and audit logging.
Can you help with compliance frameworks like SOC 2 or ISO 27001?
The audit maps directly to controls required by SOC 2, ISO 27001, NIST 800-53, and HIPAA. The report includes framework mapping where applicable.
How is this different from Microsoft Secure Score recommendations?
Secure Score gives you a number and a generic list. I give you context which recommendations actually matter for YOUR environment, which ones to skip because they'd break workflows, and the order to implement them in. Plus email auth, DLP, and admin role analysis that Secure Score doesn't covered.
Do you sign NDAs?
Yes, happy to sign yours or provide a mutual NDA before we begin.
What's your timezone?
I'm based in Asia (UTC+5:30) but I respond within a few hours regardless of time-zone. All deliverables are asynchronous. no mandatory live calls unless you want the Premium video walkthrough.