Advisory Services · Security Assessment

Know exactly where your environment is exposed.

A structured, fixed-scope audit of your Microsoft 365 or Google Workspace environment—delivered as a written findings report with prioritized remediation guidance your team can act on immediately.

Who this is for

Never had an independent audit

Renewing cyber insurance this year

Recovering from a security incident

Second opinion on your MSP's work

Why This Matters

You can't fix what you can't see.

Most SMBs don't have a written record of what their cloud environment actually looks like—what's configured, what isn't, and where the gaps are. That's not negligence, it's just the reality of how these platforms get deployed: quickly, under pressure, and without a security baseline in mind.

The Security Assessment changes that. In three to five business days, you get a clear, written picture of your current security posture—not a dashboard screenshot or a vendor sales report, but an independent audit written by someone who understands both the platform and the threat landscape facing SMBs.

The findings report is yours to keep and act on, regardless of whether you engage us further.

What We Audit

Seven control domains. One clear report.

The assessment covers every major security control surface in your Microsoft 365 or Google Workspace environment, benchmarked against CIS and CISA SMB guidance.

Identity & Access Management
Admin accounts, MFA coverage, conditional access, privileged roles
Email Security & Authentication
DMARC, DKIM, SPF configuration and enforcement status
Device & Endpoint Posture
MDM enrollment, compliance policies, personal vs. managed device access
Data Sharing & External Access
Sharing defaults, guest access controls, third-party app permissions
Audit Logging & Monitoring
Log retention, alert policies, sign-in risk monitoring, anomaly detection
Anti-Phishing & Threat Policies
Defender settings, impersonation protection, safe links, quarantine policies
Admin Role & Privilege Review
Global admin exposure, role assignments, service account hygiene
What You Receive

A written report your team can act on.

Every Security Assessment delivers a structured written document—a plain-language report your leadership team can read and your IT team can implement.

Executive summary—current risk posture in plain language, suitable for leadership or board review
Detailed findings by control domain—what's configured correctly, misconfigured, or missing
Prioritized remediation list—findings ranked by risk severity with actionable fix guidance
Benchmark comparison—your configuration against CIS and CISA SMB security baseline
60-minute findings walkthrough call—we review every finding with your team
30-day follow-up—optional check-in to review remediation progress, at no extra charge
How It Works

Fixed scope. Fast turnaround. No surprises.

01

Intake & Access (Day 1)

You complete a short intake form and grant our team read-only admin access to your tenant, using the minimum permissions required.

02

Configuration Audit (Days 1–7)

We audit your tenant across all control domains, documenting findings as we go, not after the fact.

03

Report Delivery (Day 7-9)

You receive the written findings report, and we schedule the findings walkthrough call—typically 60 minutes.

04

Your Call (After Delivery)

The report is yours. Use it as a remediation roadmap internally, or engage us to implement the fixes—either is valid.

Engagement Model
Fixed-Fee

Flat project pricing scoped to your environment size. No hourly billing, no surprise overages. Pricing shared after a 20-minute scoping call.

3–5 business day turnaround
Read-only tenant access only
Covers M365 or Google Workspace
Findings walkthrough call included
Schedule a Scoping Call →
Compliance Alignment

Documentation your auditors and underwriters will ask for.

While this isn't a formal certification audit, the findings and documentation you receive directly support these common compliance and underwriting requirements.

Cyber Insurance

Most insurers now require MFA enforcement, email authentication, and documented security controls before binding or renewing a policy. Your findings report provides exactly the evidence underwriters ask for.

CMMC

If you sell into the defense supply chain, CMMC compliance is often contractually required. This assessment identifies gaps against the access control and audit logging domains CMMC evaluates.

SOC 2

Preparing to sell to enterprise customers that require a SOC 2 report? This assessment is a practical first step—identifying access control and monitoring gaps before a formal audit begins.

HIPAA

Healthcare-adjacent organizations need documented technical safeguards for PHI. This assessment reviews access controls, audit logging, and data protection configurations relevant to the HIPAA Security Rule.

This assessment supports your compliance preparation but does not constitute formal certification. Certain frameworks (SOC 2, HIPAA) require independent third-party audits for official attestation.

Why Olson Tech

What separates us.

Fixed price

not billed by the hour

You work directly with the person doing it

Benchmarked against CIS/CISA

not a private scoring model

No managed-services upsell attached

Delivered in days

not a procurement cycle

Get a clear picture of your risk—in under a week.

Start with a free 20-minute scoping call. We'll confirm the assessment is the right fit and give you a fixed price before any work begins.