Evidence, not opinions.
Most Microsoft 365 assessments hand you a Secure Score screenshot and a spreadsheet. Mine produces a complete, evidence-backed assessment package — board summary, technical findings, compliance crosswalks, and a remediation roadmap — generated by a proprietary PowerShell engine that collects evidence directly from your tenant.
NIS2 is in force. “We think we’re secure” no longer counts.
Portugal’s Cybersecurity Legal Framework (Decree-Law 125/2025) took effect on 3 April 2026, transposing the EU NIS2 Directive and bringing an estimated 7,000–9,000 organisations into scope — most for the first time. It requires you to demonstrate your security posture with evidence, not assertion: risk-management measures, incident reporting on tight deadlines, supply-chain security, and personal, non-delegable accountability for the management body — with fines up to €10 million or 2% of worldwide turnover. That is exactly what this assessment produces: a reproducible, framework-mapped evidence base you can put in front of a regulator, an auditor, or your board.
Mapped to NIS2 Art. 21(2), ISO/IEC 27001:2022 and CIS.
Technical readiness — not legal advice.
One assessment, every audience.
The same evidence, rendered for the people who need to act on it — from the board to the engineer. Delivered as HTML and Word, with CSV and JSON evidence.
Executive Board Summary
Risk posture, top exposures, and investment priorities — in business language.
Executive Report
Prioritised findings, risk themes, and a phased remediation roadmap.
Technical Findings
Every finding with severity, evidence, Zero Trust pillar, remediation and required licence.
Identity Governance & CA
Privileged access, governance gaps, and Conditional Access optimisation.
Crosswalk & NIS2 Readiness
Technical-readiness mapping to NIS2 Art.21(2), ISO 27001, CIS, CISA SCuBA and EIDSCA — readiness, not a legal compliance verdict.
Attack Surface Exposure
External and configuration exposure across the tenant.
Licence Optimisation & Sizing
Licence waste, right-sizing, and managed-services scope.
Zero Trust & Azure
CISA five-pillar Zero Trust maturity, plus Azure infrastructure assessment.
A methodology you can defend to an auditor.
Evidence-backed
Thousands of items collected directly from your tenant. Every finding traces to evidence, not guesswork.
Coverage-aware
“Not Assessed” is never reported as Pass, Fail, or Zero. If something can’t be collected, the report says so and caps confidence.
No false clean bill of healthFramework-aligned
Rules mapped to CIS, CISA SCuBA, EIDSCA, ORCA and Maester.
Secure by design
App + certificate authentication. Read-only. No stored credentials.
Built for delivery
Every finding carries its remediation and the exact licence it requires — so the roadmap is actionable.
From scoping call to board-ready in days.
Scoping call (30 min)
we agree scope (M365, Azure, or both) and confirm access.
Read-only access
you grant delegated, read-only app + certificate access. No stored credentials; nothing is written to your tenant.
Evidence collection
the engine runs 228 curated checks, collecting thousands of configuration items directly from your tenant. Anything it can’t reach is recorded as “not assessed” — never guessed.
Validation & reporting
I review every finding, map it to NIS2 / ISO 27001 / CIS, and write the board summary, technical findings and remediation roadmap.
Walkthrough
a findings call to talk through the report, priorities and next steps. Delivered in days.


