Cloud security assessment
M365 Security Assessment
Microsoft 365 carries your identities, your email and most of your documents, and one compromised account can reach all three. We check how your tenant is configured, find where it is exposed, and put the fixes in priority order, so one phished account stays a small incident.
Book a discovery callOne tenant holds the whole company
Microsoft secures the service itself. How it is configured, and who can reach what, is on you.
Most tenant incidents trace back to a setting someone got wrong. Half the company still has admin rights from back when there were six of you. An app someone connected years ago can still read everything. Neither shows up in daily use, and either one is enough to turn a single mistake into a company-wide exposure.
This assessment catches them while they are still cheap to fix, and tells you which of them matter for your business.
What we look at
We review your tenant against industry-recognised best practices, including Microsoft's own security guidance, across the areas where Microsoft 365 risk concentrates.
Identity and access management
Nearly every tenant compromise starts at a sign-in. Who can get in, and what they can reach once in, decides whether a stolen password opens one mailbox or the whole tenant.
Email security
Phishing needs only one inbox to work. How much of it reaches your people, and what a single click can set off, depends on your mail setup.
Teams and SharePoint
Files in Microsoft 365 are built to be shared, which is also how they leak. We look at where your files can end up.
Data protection
Some of what your company holds must never leave it. Does your tenant know which data that is, and would anything stop it getting out?
Logging and visibility
When an account is compromised, the first question is what it reached. Either your logs answer that, or you guess.
Threat detection
An intrusion grows more expensive every day it goes unseen. We look at whether one would be noticed while it is still small.
What you walk away with
Where your tenant stands, finding by finding. Each one carries a risk rank and the effort to fix it. We also flag any Microsoft protections you already pay for that are not switched on. A report written for your board and your engineers at the same time. When investors run technical due diligence, security is on the list, and this report is what you hand them.
And if you want our help fixing what we find, we will be happy to give it.
The shape of a finding
A forgotten app with access to everything
- What it is
- An app approved years ago still has tenant-wide access to mail and files.
- Why it matters
- A breach at that vendor reaches your data without ever touching your tenant.
- The fix
- Review what apps can reach, revoke what is stale, and gate new consent.
- Fix within
- 14 days
An illustration of how we structure a finding. The data is generic.
Want a maturity rating across your whole security programme? The Custos Secure Baseline scores your security maturity and maps the way to the standard enterprise security reviews expect.
See the baselineCustos was founded by Liran Aknin, who has run security operations and hardened cloud environments in production. The work is delivered to that standard.
Who you work withSee where your Microsoft 365 security stands
A 30-minute discovery call to scope the review around what matters most for your tenant.
Book a discovery call