An engineer from our Shoreditch office reviews your Microsoft 365 posture, endpoints, phishing exposure and backups, then walks you through the findings in plain English. It costs nothing, there's no obligation, and if your setup is in good shape we'll say so.
Reviewed by engineers, not a scanning tool with a PDF export
Five areas, reviewed by people who do this for a living. Automated scans have their place, but most of what puts a small business at risk is configuration — and configuration needs a human to read it.
Who can log in, from where, and what's standing in the way. We check MFA coverage across every account, review your Conditional Access policies, and look for the over-privileged admin accounts and stale logins that attackers try first.
Every laptop and desktop we can see: is it encrypted, is it patched, and is it running real endpoint protection or just whatever shipped with it. One unpatched machine can undo everything else you've done, so we check this properly.
How your domain handles spoofing — SPF, DKIM and DMARC — what your filtering catches in practice, and how exposed your team is to the invoice-fraud emails that land in every business inbox.
Whether your Microsoft 365 data is genuinely backed up — deleted-item retention isn't a backup — and whether you could restore after ransomware or an account takeover. We look at what exists, how current it is, and whether it's ever been tested.
We map the findings against Cyber Essentials and NCSC guidance — the frameworks insurers and larger customers increasingly ask about. To be clear, this is guidance alignment, not a certification audit, and we'll tell you plainly how far off you are. New to the scheme? Start with our Cyber Essentials guide for small businesses.
What we found, why it matters, and what it would take to fix, written so you can read the whole thing in one sitting.
The two or three things to fix first come first. Everything else follows in order, so you're never guessing at priorities.
Some are settings you can change yourself the same afternoon — we'll point those out and tell you how. The rest come with an honest view of the effort involved.
You won't get a red dashboard designed to frighten you into a contract. And if you'd like a head start before we speak, our guide to Microsoft 365 security basics for small teams covers the settings we check most often.

Because the people doing the review run security every day. Our cyber security practice includes a 24/7 SOC built on Microsoft Sentinel, EDR/XDR on client endpoints, phishing simulations and incident response — so your audit is done by engineers who spend their working week on exactly these problems, from our office on Paul Street in Shoreditch.
The advice also comes with a track record. These are the results we publish for clients on managed security plans, typically within the first three to six months:
Three steps from first call to findings.
Call +44 20 7099 7753 or email us with "Free security audit" in the subject line. We'll book a short call to understand your setup — how many people, what you run, and anything already worrying you.
Our engineers work through the five areas above with whoever looks after your IT today. It doesn't interrupt your team's working day, and you don't need to prepare anything.
A plain-English walkthrough of what we found, ranked by risk, with a practical fix against each item. What you do with the list is entirely up to you.
No catch worth hiding. Some businesses that take the audit become clients — usually because they'd rather hand the fix list to us than work through it themselves. The rest take the findings away, do the work on their own, and end up better protected than they were. Both outcomes suit us fine.
The audit ends with one conversation about the findings, and after that it's your call. We won't chase you afterwards.
This audit is deliberately security-focused. If you want the wider picture — devices, licensing, support arrangements and your network too — book the free IT assessment instead.
Call us, or send an email with "Free security audit" in the subject and a sentence about your business. We'll take it from there.