← Microsoft 365 audit scope

Secure Score & Compliance Baselines

9 checks · 2 sub-categories

A list of settings is not an audit. Every finding we raise is scored for real-world risk, tied to its effect on your Microsoft Secure Score, and mapped to the recognised baselines your insurer, your board or your accreditor will ask about — so the report doubles as evidence, not just a to-do list.

Scoring and prioritisation

  • Current Microsoft Secure Score and trend

    Your score, the comparison against similar-sized organisations, and which recommendations actually move it.

  • Risk-prioritised findings

    Each finding is rated on likelihood and impact for a business your size — not Microsoft's generic points value.

  • Effort and licence cost per remediation

    So you can start with the fixes that are free and take ten minutes.

Framework mapping

  • ACSC Essential Eight

    Findings mapped to the applicable Essential Eight mitigation strategies and the maturity level your current configuration supports.

    • Essential Eight
  • CIS Microsoft 365 Foundations Benchmark

    Control-by-control mapping against the CIS benchmark used by security-focused providers worldwide.

    • CIS Microsoft 365 Benchmark
  • CISA SCuBA and EIDSCA baselines

    The US government cloud baselines and Entra ID Security Config Analyzer test families, both of which cover controls CIS does not.

  • Privacy Act and the Notifiable Data Breaches scheme

    Where your configuration affects your ability to detect, assess and report an eligible data breach within the required timeframe.

    • Privacy Act 1988
    • NDB scheme
  • Cyber insurance questionnaire alignment

    Documented answers to the control questions insurers ask at renewal, so you're not attesting to something you can't evidence.

  • NIST CSF 2.0 function mapping

    For businesses reporting to a parent company or enterprise customer that works in NIST terms.

Want to know where you actually stand?

Every one of these checks is run as part of a single point-in-time audit, delivered as a plain-English, risk-prioritised report.