Microsoft 365 & Azure security - for the deadline ahead
Get through the security deadline that's coming - your cyber-insurance renewal, your audit, your AI rollout.
Fixed-price, guaranteed engagements for financial services and regulated teams, delivered before the deadline you're up against. A specialist, senior-led practice built on 15+ years inside Managed Service Providers and Cloud Solution Providers - hundreds of tenants across financial services and beyond - hardening Microsoft 365 and Microsoft Azure to the baseline regulated teams are judged on.
Free posture audit. Fixed-price Deadline Packs from £3,500 / $4,500.
Senior-led delivery · Fixed-scope engagements · No open-ended day rates
The flagship - for a renewal or audit
Everything the questionnaire asks for, hardened and evidenced before your date.
When your renewal or audit lands, telling your insurer that staff sign in with a second step - a code or an approval on their phone - is no longer an answer. They want proof it was switched on for every account, administrators included, and enforced on the day it mattered. A false attestation is now the leading reason cyber claims are rejected. The Cyber-Insurance Renewal Pack hardens your Microsoft 365 estate to the exact baseline your insurer checks, maps every control to the question it answers, and finishes before your date.
The Renewal Guarantee: every scoped control hardened and evidenced before your date, or we keep working free.
from £16,000 / $20,500 - weighed against a cyber premium already running into tens of thousands a year, and a denied claim that can be existential: a declined renewal, a premium shock, or being uninsured in the incident you insured against.
What's in the pack
- Identity, device, and data controls hardened to the baseline on your insurer's or auditor's questionnaire: a second sign-in step on every account, administrators included; admin rights held by as few people as possible; sign-in rules that block a risky login before it succeeds; company devices managed and protected; and backups proven by an actual restore
- An evidence pack mapping each control to the exact question it answers, ready to submit - exported settings, coverage reports, and dated screenshots showing the control was on and covering everyone, rather than an assurance the insurer has to take on trust
- Microsoft Secure Score uplift with a prioritised, risk-ranked remediation plan - Microsoft's own measure of how well your tenant is configured, moved by fixing what carries the most risk first, with anything deliberately left recorded and explained
- A short board-ready summary of what was already safe, what was fixed, and what to monitor - written in plain English for the people who sign the policy, not the people who configure the tenant
Track record: we have taken regulated finance teams from the low Secure Score ranges (around 40%) to over 90%.
The flagship - for switching on AI
Turn AI on this quarter - without it surfacing data nobody meant to share.
Any AI you point at Microsoft 365 - Copilot, ChatGPT, Claude, or an internal agent - works with the permissions each user already has. So on day one it can surface files, mailboxes, and sites that have been quietly over-shared for years, all at once. The AI Readiness Pack finds and closes that exposure to a verified threshold, sets the AI's access scope deliberately, and gets you to a safe switch-on.
The Switch-On Guarantee: oversharing remediated and verified, or we keep working free.
from £15,000 / $19,200 - set against an AI licence you are already paying for every month and cannot safely switch on, and a single leak of salary, board, or client data through it.
What's in the pack
- An oversharing sweep for organisation-wide links, 'Everyone except external users' access, and stale permissions from people who moved or left
- Microsoft Purview sensitivity labels and Data Loss Prevention (DLP) applied to sensitive content to an agreed threshold
- Identity gaps closed - a Conditional Access baseline and privileged-role review ahead of rollout
- The AI's access scope set deliberately - Microsoft Copilot tenant controls where in use, and the connectors or grounding data any ChatGPT, Claude, or internal agent is allowed to reach
- A written, tenant-specific AI usage policy naming which assistants are sanctioned for which data
- A verification pass confirming the oversharing threshold is met before switch-on
Start here
See where you stand before you spend
See where you stand before you commit to anything. Every step names the result it will deliver up front, and the paid ones are free if they do not deliver it. Any fee you do pay credits against the work it leads to.
Free Posture Audit
See exactly where your security stands, at no cost.
Free
A no-cost audit of your Microsoft 365 or Microsoft Azure estate against the baselines that matter to you - see exactly where you stand before you spend anything, and keep the report either way.
You keep the report either way - no cost, no obligation.
Cyber-Insurance Precheck
Know which insurer questions you would fail, before you answer.
from £2,000 / $2,600
Send us your insurer's questionnaire. We map every question to your live Microsoft 365 posture and tell you - control by control - exactly where you'd fail, before you sign an attestation you can't back up.
At least three findings that change how you'd answer, or it's free.
AI Oversharing Report
See what AI would expose, before you switch it on.
from £2,500 / $3,200
Rolling out AI on Microsoft 365 - Copilot, ChatGPT, Claude, or an internal agent? Grant read access and we show you, site by site, exactly what it would surface to the wrong people the day you switch it on, before you switch it on.
At least three exposures you didn't know about, or it's free.
Deadline Packs
Fixed-price engagements, timed to the date you're up against
When there's a date you can't move - an insurance renewal, a Cyber Essentials deadline, a VPN you've been told to retire - you don't want a day rate and an open-ended project. You want a defined outcome, a fixed price, and a guarantee it lands before the deadline. Find the situation you're in.
You have a renewal or audit coming
The Cyber-Insurance Renewal Pack is the complete answer to a dated questionnaire or audit - every control hardened and evidenced before your date. If just one control presses hardest, take that piece on its own: Cyber Essentials certification, or a tested-backup ransomware recovery.
Cyber Essentials Certification Pack
Get certified first time, without a failed assessment and a resit.
from £3,500 / $4,500
Get Cyber Essentials or Cyber Essentials Plus certified on the first attempt - the v3.3 controls mapped to your Microsoft 365 estate, hardened and evidenced, or we fix the gaps free.
The First-Attempt Guarantee: a scoped control fails? We fix it and support your resubmission free.
Cyber-Insurance Renewal Pack
Pass your insurer's questionnaire without a scramble or a refusal.
from £16,000 / $20,500
Walk into your cyber-insurance renewal with every control the questionnaire asks for - hardened, evidenced when it mattered, and guaranteed before your date.
The Renewal Guarantee: every scoped control hardened and evidenced before your date, or we keep working free.
Ransomware Recovery Pack
Know you could actually recover, because it has been rehearsed.
from £7,000 / $9,000
Prove you could recover from ransomware - immutable, restore-tested backups of both your Microsoft 365 and Microsoft Azure data, with a recovery you have actually rehearsed, not just configured.
The Recovery Guarantee: a full restore of your Microsoft 365 and Azure data demonstrated and evidenced, or we keep working free.
You're switching on AI
Switching on Microsoft Copilot, ChatGPT, or Claude over your Microsoft 365 data is a security project first. Three steps, in order: see what AI would expose today, close it, then build on it safely.
- See it
AI Oversharing Report
from £2,500 / $3,200
A fixed-price report showing, site by site, exactly what AI would surface across your Microsoft 365 the day you switch it on.
- Close it
AI Readiness Pack
from £15,000 / $19,200
The fixed-scope sprint that remediates oversharing to a verified threshold and gets you to a safe switch-on - the Switch-On Guarantee, or we keep working free.
- Build on it
AI Automation & Secure AI Adoption
from £6,000 / $7,700
Once AI is safe to use, purpose-built automation and governed AI tools you own outright, deployed into your own tenant.
You're modernising access
Retire legacy VPN for Zero Trust access, or put contractors on managed desktops inside your own tenant - delivered to an agreed date.
Secure Remote Access Pack
Retire the VPN, and give people safe access to internal systems.
from £8,500 / $10,900
Replace legacy VPN with Microsoft Entra Global Secure Access - per-application Zero Trust access, with every connection checked against identity and device health.
The Deadline Guarantee: VPN retired on the agreed date, or the final payment is waived.
Secure Managed Desktops Pack
Let contractors work on your systems without trusting their laptops.
from £9,000 / $11,500
Give contractors and staff on personal devices a secure, managed desktop inside your own tenant - Azure Virtual Desktop or a Windows 365 Cloud PC.
The Deadline Guarantee: every in-scope user on a secure, managed desktop by the agreed date, or we keep working free.
Services
The capabilities behind the packs
Ongoing hardening, platform foundations, automation, and senior security leadership - the senior-led capabilities the packs draw on, available as a plan, a build, or a retainer rather than a dated pack. Each is a defined outcome, never open-ended day rates.
Products
Products & self-hosted solutions
Standalone tools and complete solutions built on the same Microsoft cloud expertise - run as a service, or deployed self-hosted into your own tenant.
Tidy Names
Every domain you own, across every registrar, in one dashboard - with expiry alerts, DNS visibility, and email security checks.
Hosted servicePre-launchLearn moreMicrosoft Entra Monitor
Continuous monitoring of Microsoft Entra secret and certificate expiries - and directory storage - before they cause an outage.
Self-hostedLimited releaseLearn more
Drawn from 15+ years of Microsoft cloud delivery across Managed Service Provider and Cloud Solution Provider estates - representative outcomes, not tied to any single client.
- 15+ years
- inside Managed Service Providers & Cloud Solution Providers (MSP/CSP)
- Hundreds
- of client tenants designed, secured, migrated, and supported
- ~90%
- Microsoft Secure Score achievable from low baselines
- Six-figure
- annual cloud savings from cost & licensing optimisation
How we work
A clear path, priced up front.
Most teams go straight from the free audit to a pack - take one step or the whole path, with no obligation to continue.
Audit
Free
no cost, no obligation
A no-cost Posture Audit of your Microsoft 365 or Microsoft Azure estate against recognised baselines, so you can see where you stand before spending anything.
Pack / Build
from £3,500 / $4,500
a Deadline Pack; larger builds from £20,000
A fixed-price, fixed-scope implementation - most often a dated Deadline Pack that closes the gaps against an external deadline.
Retain
from £3,500 / $4,500
per month
Continuous Evidence - a monthly retainer that keeps your posture aligned and your audit and insurance evidence current and submittable, not rebuilt from scratch each year.
Prefer the full sequence mapped first? An optional fixed-fee Roadmap does that, and is credited against any pack or build you book within 60 days - but most teams go straight from the free audit to a pack. See the full approach.
The practice
Our approach
Service-provider experience at the core: patterns proven across many tenants, applied with the seniority, agility, and security rigour of a specialist practice.
Forged in MSPs and CSPs
15+ years inside Managed Service Providers (MSPs) and Cloud Solution Providers (CSPs) - the good, the bad, and the ugly. We have seen which designs hold up under real support load and which quietly become someone else's problem.
Broad across technologies and sectors
Exposure to a wide spread of environments, industries, and regulatory pressures means we recognise your situation rather than meeting it for the first time - and we know which approach actually fits it.
Senior-led, hands-on, low overhead
Work is led directly by an Azure Solutions Architect Expert - no junior hand-offs, no unnecessary layers - while holding to Well-Architected and Cloud Adoption Framework rigour.
Security built in, not bolted on
Identity and Zero Trust thinking runs through every engagement, reflecting a security-specialist background.
Built to standardise and scale
Multi-tenant delivery habits carry over: infrastructure-as-code with Terraform, repeatable baselines, and custom tooling built per engagement rather than worked around - so a fix becomes a standard, not a one-off.
Outcome-based, fixed scope
Every offer is a defined outcome - a roadmap, a build, or a retainer - never open-ended day-rate burn.
AI-accelerated delivery
Better work, in less time, for less money
AI has genuinely changed what a small senior team can deliver, and we have rebuilt how we work around that rather than treating it as a novelty. The benefit belongs to you: work that is more thorough as well as faster, lower fixed fees, and more of the budget spent on judgement instead of legwork.
Less time between question and answer
Tenant configuration, sign-in logs, and policy exports are read and cross-referenced in minutes rather than over days of manual review. The analysis that used to justify a two-week discovery phase now sits inside the first week, so findings arrive while the context is still fresh.
Custom tooling stops being a luxury
A one-off script to reconcile licences, pull an evidence pack, or remediate several hundred mailboxes used to cost more to write than the manual work it replaced. That calculation has changed - purpose-built tooling is now often the cheaper way to get the work done.
More thorough, not only quicker
The time AI frees up is spent on the parts that need judgement: more design options weighed before committing, wider review of edge cases, and handover documentation that gets written properly rather than squeezed in at the end.
Consistency across tenants
Baselines, runbooks, and infrastructure-as-code are generated from one reviewed standard rather than retyped per environment. Drift between tenants comes from manual repetition, and there is less of that now.
Using AI on client work carries obligations, and we publish the ones we hold ourselves to - approved providers on paid commercial plans, what never reaches a model, and a named human accountable for every output. Read the AI policy
Get started
Find out where you stand, free
Most engagements start with a no-cost posture audit against the baselines that matter to you. If a fixed-fee roadmap is the right next step, we'll say so - and if it isn't, we'll say that too.