Security Assessments

Know where you stand.
Know what to do next.

Get an evidence-based review of your Microsoft and infrastructure security, with findings ranked by risk and specific actions to address them.

Baseline review · Prioritised findings · Improvement roadmap

Arrange a consultation
What We Review

Configuration, exposure
and recovery readiness.

We agree which systems to review and the access required before work begins.

01

Microsoft security configuration review

Review the identity, device, email and data controls protecting your Microsoft 365 environment. We assess the agreed settings against your objectives and the relevant Microsoft guidance.

  • Identity and administrative access
  • Device management and protection settings
  • Email, collaboration and information protection
  • Operational ownership and visibility
02

Security hardening review

Find insecure settings, unnecessary exposure and weaknesses in administrative access.

  • Secure configuration and unnecessary exposure
  • Privilege and access management
  • Update and vulnerability management processes
  • Testing, rollout and rollback considerations
03

Network and recovery readiness review

Review the architecture and operating arrangements supporting secure connectivity and recovery of critical services.

  • Azure network and firewall configuration
  • Network segmentation and administrative access
  • Backup coverage, recovery dependencies and runbooks
  • Recovery test evidence and outstanding actions
04

Cyber Essentials readiness

Review the proposed assessment scope and identify control or evidence gaps to address before a certification application.

  • Assessment scope and asset inventory
  • Readiness review against the applicable requirements
  • Remediation priorities and evidence preparation
  • An action list for outstanding requirements
Explore Cyber Essentials & Plus support
The Assessment Output

Findings you can act on.

What was reviewed

The agreed scope, evidence considered, configuration baseline and limitations.

What needs attention

Findings explained through risk, business impact and the priority for improvement.

What to do next

A remediation plan with priorities, dependencies and a recommended order of work.

Assessments are bounded by the agreed scope and available evidence. Readiness support does not guarantee certification; the relevant certification body makes that decision.

Before You Get Started

Your assessment questions, answered.

Do I need to know exactly what is wrong?

No. Tell us what is causing concern and describe the systems you use. We can help identify where a review would be most useful.

Will the assessment change my environment?

Review activities and access are agreed before the assessment. Configuration changes require separate approval, with testing and rollback planning.

Can Zelo help with the recommendations afterwards?

Yes. We can plan and implement remediation as a follow-on project, with the work and acceptance criteria agreed in advance.

Planning Your Engagement

An assessment with clear boundaries.

Scope, fees and acceptance criteria are agreed in writing before work begins.

Ready to strengthen
your security?

Speak with Zelo about your Microsoft environment, data protection priorities or recovery plans.

Arrange a consultation