Know exactly where you stand in 10 business days.
A read-only review of your identities, devices and Microsoft 365 or Google Workspace tenant. You get a scored report, your top 10 risks, a 90-day plan and a readout with your leadership. Fixed fee, agreed up front, and credited in full if you continue with us within 30 days.
The places breaches start and auditors look.
Identity
- MFA coverage and phishing-resistant MFA
- SSO coverage of your apps
- Stale, orphaned and guest accounts
- Admin sprawl and legacy sign-in
- Conditional Access or Okta policy gaps
Tenant baseline
- Microsoft 365 or Google Workspace checked against CISA ScubaGear
- Microsoft Secure Score
- Email authentication: SPF, DKIM, DMARC
- External sharing and mail forwarding rules
Devices
- MDM enrollment rate
- Disk encryption
- OS and patch currency
- EDR coverage
- Local admin rights
Compliance mapping
- Your cyber insurance application controls
- SOC 2 access and operations controls
- Or SEC Reg S-P / FTC Safeguards Rule
- SaaS backup coverage
Ten business days from access to readout.
Kickoff & access
A 30-minute call and read-only access. We never make changes during an assessment.
Review
Automated scans plus hands-on review by a senior engineer.
Report
Scored findings, top 10 risks and a 90-day plan with effort estimates.
Readout
A 45-minute session with your leadership to walk through what we found.
A score for every area, and a plan to raise it.
Every area is scored 0 to 100. The plan has two columns: what to fix in the first 30 days, and what to keep fixed every month after. If you continue with us, that plan becomes your onboarding.
- Scored report across identity, devices, workspace, threat and recovery
- Top 10 risks in plain language
- 90-day roadmap with effort estimates
- 45-minute executive readout
Secure Workplace Scorecard
Example Co. · Month 3
Monitoring 24/7
Read-only access and 30 minutes.
We sign a mutual NDA before we start. Access is removed as soon as the readout is done.
- Read-only roles: Entra Global Reader and Security Reader, or Google read-only admin
- Okta read-only admin, MDM auditor role and EDR console read access
- A 30-minute interview with whoever runs IT today
- A list of your critical apps
- Your latest cyber insurance application or SOC 2 report, if you have one
Book your assessment.
Tell us about your company and we'll confirm scope, fee and a start date within one business day.