Skip to content

Cloud security assessment

M365 Security Assessment

Microsoft 365 carries your identities, your email and most of your documents, and one compromised account can reach all three. We check how your tenant is configured, find where it is exposed, and put the fixes in priority order, so one phished account stays a small incident.

Book a discovery call

One tenant holds the whole company

Microsoft secures the service itself. How it is configured, and who can reach what, is on you.

Most tenant incidents trace back to a setting someone got wrong. Half the company still has admin rights from back when there were six of you. An app someone connected years ago can still read everything. Neither shows up in daily use, and either one is enough to turn a single mistake into a company-wide exposure.

This assessment catches them while they are still cheap to fix, and tells you which of them matter for your business.

What we look at

We review your tenant against industry-recognised best practices, including Microsoft's own security guidance, across the areas where Microsoft 365 risk concentrates.

Identity and access management

Nearly every tenant compromise starts at a sign-in. Who can get in, and what they can reach once in, decides whether a stolen password opens one mailbox or the whole tenant.

Email security

Phishing needs only one inbox to work. How much of it reaches your people, and what a single click can set off, depends on your mail setup.

Teams and SharePoint

Files in Microsoft 365 are built to be shared, which is also how they leak. We look at where your files can end up.

Data protection

Some of what your company holds must never leave it. Does your tenant know which data that is, and would anything stop it getting out?

Logging and visibility

When an account is compromised, the first question is what it reached. Either your logs answer that, or you guess.

Threat detection

An intrusion grows more expensive every day it goes unseen. We look at whether one would be noticed while it is still small.

What you walk away with

Where your tenant stands, finding by finding. Each one carries a risk rank and the effort to fix it. We also flag any Microsoft protections you already pay for that are not switched on. A report written for your board and your engineers at the same time. When investors run technical due diligence, security is on the list, and this report is what you hand them.

And if you want our help fixing what we find, we will be happy to give it.

The shape of a finding

High Priority 1

A forgotten app with access to everything

What it is
An app approved years ago still has tenant-wide access to mail and files.
Why it matters
A breach at that vendor reaches your data without ever touching your tenant.
The fix
Review what apps can reach, revoke what is stale, and gate new consent.
Fix within
14 days

An illustration of how we structure a finding. The data is generic.

Want a maturity rating across your whole security programme? The Custos Secure Baseline scores your security maturity and maps the way to the standard enterprise security reviews expect.

See the baseline

Custos was founded by Liran Aknin, who has run security operations and hardened cloud environments in production. The work is delivered to that standard.

Who you work with

See where your Microsoft 365 security stands

A 30-minute discovery call to scope the review around what matters most for your tenant.

Book a discovery call