• microsoft O365 security optimisation

You bought Microsoft O365 so you wouldn’t have to stress about IT security. So why are you still shockingly vulnerable?

Right now, your team runs on Microsoft. It’s powerful, familiar, and holds the keys to your entire business—your emails, client financials, and proprietary files. But out-of-the-box, default Microsoft 365 isn’t safe.

Don’t pay for a safety deposit box and leave the combination at 0-0-0-0

Accounts lacking basic MFA
0

Accounts without MFA, are 6 times more likely to be hacked.

Average cost of an data breach
0
  • the goal

Invisible doors closed. Absolute peace of mind.

For the cost of a minor operational expense, you can insulate your business from the worst impacts of a cyber incident.

We’ll give you a clear, flat-rate quote to audit your environment, lock the digital doors, enforce seamless logins, and establish a working disaster recovery plan. Our methods don’t make it difficult for your team. Your people get to keep working in the way they prefer—just safely.

  • DANGEROUS ASSUMPTIONS

You know security is important. Here’s why it hasn’t been fixed yet.

“Surely Microsoft handles this for us?”

No. Under Microsoft’s “Shared Responsibility” model, they keep the servers turned on. But enforcing passwords, locking out hackers, and backing up data is entirely your legal responsibility.

“Passwords and MFA slow us down.”

You’re worried that adding Multi-Factor Authentication means your staff will be locked out of their emails. What you need is Vaultwarden. Your team will love it!

“We already back up to OneDrive”

Those aren’t backups; they are sync tools. If ransomware hits a laptop, or an employee deletes a folder, changes sync to the cloud. Microsoft deletes your recycle bin after 93 days. It’s gone forever.

“We’re too small for hackers to care.”

AI bots run automated scripts looking for unlocked doors. Small businesses are the #1 target because hackers know you don’t have an internal IT security team.

  • the RISKS

You can’t afford to do nothing, but you probably don’t need new software.

If you handle sensitive data, leaving these Microsoft defaults on is considered negligent by most cyber-insurance providers. Most IT companies will try to sell you expensive, 3rd-party cybersecurity software. But the secret is to optimize what you already have.

Microsoft’s default setup

  • The risks of O365 default
  • User generated rules that bypass security.
  • Anonymous file sharing in OneDrive and SharePoint
  • Allowing “Sign in with Microsoft” on apps and websites
  • Microsoft allows old email protocols (like POP3 and IMAP)
  • Allowing guest access in Teams & SharePoint
  • Silenced or unmonitored Administrator Alerts

What it SHOULD be

  • What we assess and upgrade
  • Block general users from auto-forwarding to external accounts
  • Restrict use to company computers and approved workstations
  • Make use of Conditional Access rules by geography and IP address
  • Disable outdated and unused protocols
  • Harden Windows Defender and enforce Screen Timeouts.
  • Put written SOPs and procedures and policies in place

We optimize your existing Microsoft tenant, provide appropriate security and disaster recovery policies, and can implement password managers and tools to protect your data.

  • The GOAL

Here’s what GOOD security looks like

Your staff doesn’t have to learn new processes or change where they save their files. We just build a fortress around them.

We align your business with the Canadian Centre for Cyber Security (CCCS) Baseline Controls, implementing enterprise-grade restrictions that are invisible to your staff but impenetrable to hackers.

1. Conditional Access Control: by location and identity

Geographic Fencing: We lock your Microsoft 365 access strictly to Canada and the countries where you operate. If a hacker tries to log in from anywhere else, the system blocks them instantly.

Attack Surface Reduction: Hackers exploit forgotten tools. We restrict access to the services your team actually uses.

Windows Endpoint Hardening: We ensure the Windows local firewalls are locked, automatic patching enforced, and Defender antivirus set up correctly.

2. Verification with Two-Factor Authentication

A common hacker trick is stealing a password and secretly adding their own phone as the Two-Factor Authentication (MFA) device. We block this. New MFA devices can only be added when securely chaperoned and verified

3. Zero-Trust Device Control (Windows & Mobile)

Approved Computers Only: We restrict browser access to company-owned computers. No risk from an infected home PC.

Mobile Data Ring-Fencing: Employees can only access company data using approved, secure Microsoft apps. We can wipe the company datafrom lost personal phones???

4. Corporate Password Vault (Optional Add-On)

No more “spreadsheet of passwords”. Safely sharing the company credit card, the FedEx login, or the social media passwords.

Private Password Management: We can deploy Vaultwarden, a highly secure, open-source password manager. It is hosted privately on your own server. It secures your shared company passwords and credit cards, making them easily accessible to the right staff with a single click. 

5. Disaster Readiness & Documentation
  • The Cyber Incident Response Plan: We write and provide a step-by-step emergency playbook.
  • A Documented Disaster Recovery Plan: We physically map out your backup architecture. You get a clear, executive-level document proving exactly how your data is backed up, where it lives in Canada, and how fast it can be restored.
  • AI Policy and AI Usage Guidelines
  • A Network Usage Policy to inform every employee, and provide legal recourse.

Let’s be clear…

No-one can stop your staff from clicking bad links.

Human error will always happen. But our lockdown limits the “blast radius.” If an employee gets tricked, the hacker gets stopped at the MFA prompt, or is restricted from deleting company-wide files.

We don’t replace your IT provider or team

We can work alongside your existing internal and external IT teams, purely as Microsoft Security and Backup specialists.

We don’t sell software

Your team loves Entra, Defender, Outlook, Excel, and Teams. We are just securing the house you already live in. We will recommend secure and stable open-source options if new functionality is needed.

The BOTTOM Line

Securing your Microsoft tenant costs a fraction of a single ransomware incident.

Our solutions are priced to make financial sense for small teams.

  • Strategic Assessment
  • Implementation of Best-Practice Security Policies and settings
  • Optional password manager including company credit cards.
  • Optional ongoing support and improvements