Microsoft 365 & Google Workspace Security.
Your email and cloud workspace is where most attacks start and most data lives. We harden Microsoft 365 or Google Workspace to a defensible baseline, then prove it.
Overview
Business email compromise and cloud account takeover are among the most common and costly incidents for mid-market companies, and the default tenant configuration is rarely enough. We assess your Microsoft 365 or Google Workspace tenant against the CIS Benchmarks and vendor security baselines, then harden identity, mail flow, external sharing, data-loss prevention, and audit logging in a change-controlled way, validating each change so productivity is not broken.
What's included
- Tenant assessment against the CIS Microsoft 365 / Google Workspace Benchmarks
- Identity and conditional access: MFA enforcement, legacy-auth blocking, risk policies
- Email security: anti-phishing, anti-spoofing (SPF, DKIM, DMARC), safe links and attachments
- External sharing and data-loss-prevention (DLP) policy review and tuning
- Audit logging and alerting enabled and routed where they will be seen
- Privileged-admin review and break-glass account setup
- Post-change validation and a documented configuration baseline
What we harden
- Identity. MFA, conditional access, legacy authentication, and risky-sign-in policy.
- Email. SPF, DKIM, DMARC, anti-phishing, and impersonation protection.
- Data. External sharing, guest access, and data-loss-prevention rules.
- Visibility. Unified audit logging, alerting, and admin accountability.
What you get
- Hardening report. Tenant scored against the CIS Benchmark with prioritized findings.
- Configuration baseline. The target settings, documented so drift can be detected later.
- Change log. Every change made, why, and how it was validated.
- Monitoring plan. What to alert on and who responds, for email and identity events.
Common questions
Microsoft 365, Google Workspace, or both?
Either or both. We work in mixed environments and align each to its own CIS Benchmark and the same defensible outcome.
Will hardening break how our team works?
We make changes in a controlled sequence and validate each one. Where a control could affect users (for example conditional access), we pilot it first and communicate the change.
Does this help with SOC 2, HIPAA, or cyber insurance?
Yes. Identity, email, logging, and DLP controls map directly to SOC 2 and HIPAA requirements and to the questions cyber insurers ask, and the baseline is reusable as evidence.