Secure Workplace Assessment

Know exactly where you stand in 10 business days.

A read-only review of your identities, devices and Microsoft 365 or Google Workspace tenant. You get a scored report, your top 10 risks, a 90-day plan and a readout with your leadership. Fixed fee, agreed up front, and credited in full if you continue with us within 30 days.

What we review

The places breaches start and auditors look.

Identity

  • MFA coverage and phishing-resistant MFA
  • SSO coverage of your apps
  • Stale, orphaned and guest accounts
  • Admin sprawl and legacy sign-in
  • Conditional Access or Okta policy gaps

Tenant baseline

  • Microsoft 365 or Google Workspace checked against CISA ScubaGear
  • Microsoft Secure Score
  • Email authentication: SPF, DKIM, DMARC
  • External sharing and mail forwarding rules

Devices

  • MDM enrollment rate
  • Disk encryption
  • OS and patch currency
  • EDR coverage
  • Local admin rights

Compliance mapping

  • Your cyber insurance application controls
  • SOC 2 access and operations controls
  • Or SEC Reg S-P / FTC Safeguards Rule
  • SaaS backup coverage
Timeline

Ten business days from access to readout.

Day 1

Kickoff & access

A 30-minute call and read-only access. We never make changes during an assessment.

Days 2–7

Review

Automated scans plus hands-on review by a senior engineer.

Days 8–9

Report

Scored findings, top 10 risks and a 90-day plan with effort estimates.

Day 10

Readout

A 45-minute session with your leadership to walk through what we found.

What you get

A score for every area, and a plan to raise it.

Every area is scored 0 to 100. The plan has two columns: what to fix in the first 30 days, and what to keep fixed every month after. If you continue with us, that plan becomes your onboarding.

  • Scored report across identity, devices, workspace, threat and recovery
  • Top 10 risks in plain language
  • 90-day roadmap with effort estimates
  • 45-minute executive readout

Secure Workplace Scorecard

Example Co. · Month 3

Monitoring 24/7

Sample · illustrative data
92/100
↑ from 49 at assessment
Identity94
Devices91
Workspace89
Threat96
Recovery88
100%MFA coverage
98%Devices encrypted
100%EDR coverage
11 minMedian first response
This month At assessment
What we need from you

Read-only access and 30 minutes.

We sign a mutual NDA before we start. Access is removed as soon as the readout is done.

  • Read-only roles: Entra Global Reader and Security Reader, or Google read-only admin
  • Okta read-only admin, MDM auditor role and EDR console read access
  • A 30-minute interview with whoever runs IT today
  • A list of your critical apps
  • Your latest cyber insurance application or SOC 2 report, if you have one

Book your assessment.

Tell us about your company and we'll confirm scope, fee and a start date within one business day.