A structured, fixed-scope audit of your Microsoft 365 or Google Workspace environment—delivered as a written findings report with prioritized remediation guidance your team can act on immediately.
Who this is for
Never had an independent audit
Renewing cyber insurance this year
Recovering from a security incident
Second opinion on your MSP's work
Most SMBs don't have a written record of what their cloud environment actually looks like—what's configured, what isn't, and where the gaps are. That's not negligence, it's just the reality of how these platforms get deployed: quickly, under pressure, and without a security baseline in mind.
The Security Assessment changes that. In three to five business days, you get a clear, written picture of your current security posture—not a dashboard screenshot or a vendor sales report, but an independent audit written by someone who understands both the platform and the threat landscape facing SMBs.
The findings report is yours to keep and act on, regardless of whether you engage us further.
The assessment covers every major security control surface in your Microsoft 365 or Google Workspace environment, benchmarked against CIS and CISA SMB guidance.
Every Security Assessment delivers a structured written document—a plain-language report your leadership team can read and your IT team can implement.
You complete a short intake form and grant our team read-only admin access to your tenant, using the minimum permissions required.
We audit your tenant across all control domains, documenting findings as we go, not after the fact.
You receive the written findings report, and we schedule the findings walkthrough call—typically 60 minutes.
The report is yours. Use it as a remediation roadmap internally, or engage us to implement the fixes—either is valid.
Flat project pricing scoped to your environment size. No hourly billing, no surprise overages. Pricing shared after a 20-minute scoping call.
While this isn't a formal certification audit, the findings and documentation you receive directly support these common compliance and underwriting requirements.
Most insurers now require MFA enforcement, email authentication, and documented security controls before binding or renewing a policy. Your findings report provides exactly the evidence underwriters ask for.
If you sell into the defense supply chain, CMMC compliance is often contractually required. This assessment identifies gaps against the access control and audit logging domains CMMC evaluates.
Preparing to sell to enterprise customers that require a SOC 2 report? This assessment is a practical first step—identifying access control and monitoring gaps before a formal audit begins.
Healthcare-adjacent organizations need documented technical safeguards for PHI. This assessment reviews access controls, audit logging, and data protection configurations relevant to the HIPAA Security Rule.
This assessment supports your compliance preparation but does not constitute formal certification. Certain frameworks (SOC 2, HIPAA) require independent third-party audits for official attestation.
Why Olson Tech
Fixed price
not billed by the hour
You work directly with the person doing it
Benchmarked against CIS/CISA
not a private scoring model
No managed-services upsell attached
Delivered in days
not a procurement cycle