I will provide microsoft 365 security audit and consultation
3rd Line IT Support Engineer, Cybersecurity Specialist and Web Developer
About this Gig
Is Your Microsoft 365 Environment Really Secure?
Many businesses believe Microsoft automatically secures their environmentbut that's only part of the story.
Our Microsoft 365 Security Audit helps identify security gaps before attackers do.
We assess:
- Microsoft 365 Security Configuration
- Entra ID & Administrative Accounts
- Multi-Factor Authentication (MFA)
- Conditional Access Policies
- Email Security & Anti-Phishing Protection
- Endpoint Security Integration
- Backup & Recovery Readiness
- Remote Access Controls
- User Offboarding Processes
- Cyber Essentials Readiness
Audit failure is not an option. Whether you are chasing ISO 27001:2022, SOC 2 Type II, or the UKs Cyber Essentials Plus, your Microsoft 365 configuration is the primary evidence bank.
As a security engineer with 9+ years in aerospace-grade IT, I provide deep-tier auditing using the CIS Microsoft 365 Foundations v6.0.0 benchmark.
Following the assessment, you'll receive a professional report outlining identified risks, supporting evidence, and prioritised recommendations to strengthen your security posture.
Device:
Server/Hosting
Operating system:
Other
Also delivering:
Remote connection support
•
Documentation
FAQ
Can you help with the UK Cyber Essentials Plus (CE+) technical audit?
Yes. I perform a "Pre-Audit" scan that mirrors the official assessor's vulnerability tests. We fix CVSS 7.0+ vulnerabilities and automate your patching via Intune to ensure you pass the manual verification.
What is the benefit of the CIS v6.0.0 benchmark?
v6.0.0 is the most current standard (Late 2025). It includes critical new checks for AI/Copilot governance and Microsoft Fabric, ensuring your audit covers the latest tech stack risks.
Do you provide the ISMS documentation for ISO 27001?
Yes, in the Premium Package, I provide a full suite of M365-specific policy templates (Access Control, Encryption, Asset Management) required for the Information Security Management System (ISMS).
