Cloud Security Assessment

See your whole cloud estate, and know what to fix first.


Microsoft 365 and Azure hand you hundreds of configurable controls, graded one at a time by a portal that has never met your business. We review the estate as one system and give you back a ranked list of what to change, in the order it should be changed.

Why it is hard to answer

Most organisations have a partial view of their own cloud configuration.

Microsoft 365 and Azure ship with a broad set of configurable controls, and they are switched on over years by different people solving different problems. Each control is graded on its own, in a portal that has no view of the others and no opinion about your business. The result is rarely one large gap, and far more often a spread of settings that are half done, stuck in pilot, or paid for and never switched on.

Nobody can draw the estate

Tenants, subscriptions, SaaS applications bought outside IT and resources left behind by projects that finished years ago. Every audit starts with someone reconstructing the picture from memory.

A score with no verdict

The number moves on its own as Microsoft adds new mitigations, and every control counts the same whether or not it matters to you. Two organisations on the same percentage can be in completely different shape.

Controls you already pay for, switched off

Capability included in the licence tier that nobody had time to configure, sitting dormant while a business case goes in for a tool that would do the same job.

Policies still in pilot

Conditional access and data loss prevention policies written, applied to a test group, left in report-only mode, and counted as finished by everyone who is not looking at the portal.

Changes that might break something

Tightening a setting can lock out a director on a Friday afternoon or break a service account nobody documented. Inside the organisation, the risk of the fix is far more visible than the risk it removes.

One person responsible for it all

In most midmarket teams a single person understands the whole configuration, and there is nobody positioned to catch it when they are wrong.

What we typically find

The findings are often unexpected.


Most organisations expect an assessment to find missing protection. More often it finds protection that was bought, licensed and never finished.

30–50%

of Microsoft security capability is not fully deployed or configured, in the environments we assess.

1 in 3

licensed controls are running in audit or report-only mode, recording what they would have blocked rather than blocking it.

Under 10%

of the organisations we assess can show a return on what they already spend on security tooling.

Drawn from Microsoft cloud security assessments delivered by Talanos.

How the assessment runs

Six steps from a half-hour call to a roadmap you can work through.

Nothing is installed and nothing is changed. The assessment runs on read-only access to your own administration portals, and the sequence below is designed so that findings are checked with you before any recommendation is finalised.

  1. 01

    Scoping

    A call to agree which environments are in scope, what your licence position is and what you already suspect is wrong. Nothing to prepare beforehand.

    30 minutes
  2. 02

    Access provisioning

    Security Reader and Global Reader roles are assigned to dedicated accounts, which can read your configuration and change none of it.

    Read-only
  3. 03

    Control assessment

    More than 300 individually configurable controls are reviewed across twelve service areas, through the same Microsoft administration portals your team uses.

    300+ controls
  4. 04

    Analysis and scoring

    Each service area is scored as it stands and against where it should be, so the report shows the distance to close instead of a pass mark. This is also the stage that establishes which controls depend on each other, and which findings carry real risk.

    Current vs target
  5. 05

    Report and roadmap

    An executive summary, the full control reference, and a prioritised roadmap scoped to the licence you already hold, so the first items on it cost you nothing but time.

    Prioritised
  6. 06

    Review session

    The findings are presented to your IT and security team, with a follow-up session included for the questions that arrive once people have read it.

    Plus follow-up

Typically four weeks from the scoping call to the roadmap, with around two weeks of that after read-only access has been provisioned. No lengthy statement of work and no multi-month engagement.

What gets assessed

Every place a setting can be wrong.

Identity

Entra ID configuration, MFA enforcement and the methods allowed, conditional access policies and what state they are in, privileged role assignments, stale and disabled accounts, identity lifecycle policies, and Defender for Identity sensor coverage.

Email security

Anti-phishing configuration, Safe Links and Safe Attachments scope, shared mailboxes with direct login enabled, DKIM, mailbox intelligence, spam confidence thresholds and safety tips.

Teams

External access and cross-tenant trust, anonymous meeting joins, who can create private channels, meeting invitation branding, and which domains people can invite.

SharePoint and OneDrive

External sharing policy and whether anyone is alerted when it is used, sync from unmanaged devices, idle session sign-out, and guest access controls.

Threat detection and response

Alerting, signal correlation and attack surface reduction across endpoint, identity, email and cloud, and how much of an incident you would actually be able to reconstruct afterwards.

Information protection and data lifecycle

Sensitivity labels and whether they enforce anything, DLP policy scope and whether it is live or still reporting, and retention coverage across Teams, SharePoint, OneDrive and Exchange.

Devices and applications

Intune and Endpoint Manager, security baselines, compliance status and enrolment, plus enterprise applications and the OAuth permissions granted to them.

The difference

Changes worth making, in the order to make them.


Any portal can count controls. Working out which of them carry real risk in your environment, which depend on each other, and which are worth the disruption of switching on takes someone who has seen what happens when the judgement goes wrong.

The controls nobody counts

A setting that reads as compliant on its own can be undone by another one three portals away. The review covers the interactions, and the service areas that standard scoring leaves out entirely.

Findings from people who run a SOC

The consultants doing the review are security practitioners first. What gets flagged reflects how attackers behave in environments we monitor, rather than what a vendor checklist happens to list.

Recommendations that fit your licence

Every recommendation is scoped to the licence tier you already hold, so the roadmap starts with capability you have paid for and are not using, before it asks you to spend anything.

Nothing changes while we look

The assessment reads your configuration and writes nothing to it, so it needs no change window, no maintenance weekend and no rollback plan. It cannot break what it is looking at.

Every item on the roadmap arrives with the effort it takes and the disruption it carries, so you can decide what to do this month and what to schedule.

What you receive

Three documents and a conversation.


The assessment is a fixed piece of work with a defined output. There is no statement of work to negotiate and no multi-month engagement attached to it.

Independently assessed

ISO 27001
ISO 9001
Cyber Essentials Plus
CREST Security Operations
FSQS registered

Sample report

Read one before you commission one.

A complete assessment report from a real engagement, anonymised. The executive summary as the client received it, scoring for every service area, all 46 findings with severity ratings, and the remediation plan grouped by priority. The clearest answer to what you would be buying.

Read the sample report

PDF, 29 pages. No form to fill in.

  • The executive summary, as the client received it
  • Control counts and scoring for each service area
  • 46 findings, each with a severity rating and an action
  • The remediation plan, grouped by priority

Questions we are asked

Before you give anyone access to your tenant.

How is this different from our Microsoft Secure Score?

Secure Score grades a set of Microsoft's own recommendations, one at a time, and the number moves on its own as Microsoft adds new mitigations.

The assessment reviews more than 300 individually configurable controls across twelve service areas, including areas the score leaves out, and weighs the combined effect of how they are set against how your organisation actually works. You get a prioritised roadmap; the score gives you a percentage.

What access do you need, and can it break anything?

Two read-only roles, Security Reader and Global Reader, assigned to dedicated accounts. Nothing is installed and no configuration is touched, so there is no change window to arrange and nothing to roll back afterwards.

How much of our time does it take?

A half-hour scoping call at the start, the administrative work of assigning read-only roles, and a review session at the end. There is no questionnaire to complete and no preparation needed before the scoping call.

From that call to the finished roadmap is typically four weeks.

Will we have to buy more licences to act on the findings?

Not for most of them. The roadmap opens with capability you are already licensed for and have not switched on, which in most environments is where the majority of the improvement sits.

Where something does need a higher tier or a third-party tool, it is called out separately so you can price it on its own merits.

How is it priced?

As a fixed price, quoted after the scoping call once we know how many environments are in scope and how large the estate is. It is a paid piece of work with a defined output, not a day rate that runs until someone stops it.

The scoping call itself costs nothing and carries no obligation.

Do you assess AWS and Google Cloud?

Yes. Most assessments cover Microsoft 365 and Azure, because that is where midmarket estates tend to concentrate, but AWS and Google Cloud environments are assessed as well. Tell us what you run at the scoping call.

What happens once we have the roadmap?

Your decision, and not one you need to make up front. Some clients work through the roadmap with their own team and ask us to reassess afterwards to show the movement. Others hand the remediation to us. Where the answer is that somebody needs to be watching continuously rather than once a year, that is our cloud security operations service, and we can talk about it separately.

Ready to talk

Start with half an hour and no preparation.


The call covers which environments are in scope, what licences you have, and what you already suspect is wrong. By the end of it you will know whether an assessment would tell you anything you do not already know.

Book a scoping call