The work
The first element is not optional — it closes the open doors and costs you no licence change. The rest is yours to choose. Everything starts selected because that is what we recommend, not to inflate the total; switch off whatever you do not want and the price falls immediately.
- What it means
- Two things. First, a second and third route into the administration of your own Microsoft 365, held independently, so you can never be locked out of it. Second, settings that are currently open by default rather than by choice — closing those, and getting your mail authenticated so that forged messages claiming to be from you are far more likely to be stopped.
- What you would notice
- Very little, day to day. Mail from outside gets a small marker so it is obvious at a glance. Sharing a document with someone outside asks who they are, instead of producing a link that works for anyone who has it. The two emergency accounts cost nothing to add — they are deliberately kept outside every access policy, which is both the point of them and the reason they need no licence. The working administrator account does sit inside those policies, so it carries one licence of its own, around €10 a month, included in the licence line rather than hidden.
- Why it stays in
- Not available to leave out — everything else assumes these doors are shut. Adding controls elsewhere while these stay open is fitting a better lock and leaving the window open.
Everything that can be fixed on your current licences — and less of it is a toggle than it looks.
Two emergency access accounts, held apart from any individual, tested and written up, with at least one credential under your own control rather than a supplier's — so administering this tenant never depends on one person. A long random passphrase, sealed, is the standard arrangement and costs nothing; hardware keys are offered further down as an option. Alongside them a separate administrator identity, used only for administration and never for daily work. The largest single risk reduction here.
Anti-phishing takes a moment to enable and judgement to tune. Set it hard and mail from a counterparty you actually trade with lands in quarantine; set it soft and it catches nothing. The tuning is the work, not the switch.
DMARC is the opposite of a switch. Moving from monitoring to enforcement means finding every system that sends mail as Materia — Outlook, the website's forms, anything issuing invoices or statements — confirming each is properly aligned, then tightening in stages while watching the reports come in. Rushed, legitimate mail starts being quarantined or rejected by receiving systems: an invoice that does not arrive, a confirmation that never lands. That is why this one runs four to six weeks past delivery instead of finishing on the day.
Alongside those: external sender tagging on, Anyone links closed, guest invitations restricted to administrators, outbound forwarding set explicitly instead of left to a vendor default and brought into line with the remote domain setting, and a written record of what changed and why.
- Emergency access accounts
- Anti-phishing tuned
- Sender tagging
- Sharing & guest limits
- Forwarding set explicitly
- DMARC to enforcement
- Written record
- What it means
- Today everyone signs in the same way from anywhere, and once signed in can download anything onto their own laptop. This replaces that with rules: who, from where, on which device, and what they can take away with them. It also switches on the scanning of links and attachments that your current licence does not include.
- What you would notice
- You would read documents in the browser rather than downloading them. On your phone, work mail sits behind a PIN and you cannot copy out of it into a personal app. Signing in stays much as it is now.
- If you leave it out
- Anything a person can see, they can copy onto a private machine — and it stays there after they leave.
A conditional access policy set replacing the present all-or-nothing arrangement, so access can depend on who, from where and on what. Safe Links, Safe Attachments and impersonation protection covering your directors and finance contacts by name. App protection on personal phones — PIN, encrypted company data, no copying into personal apps, and wipe of company data only, leaving personal photos and messages untouched. Documents readable in the browser but not downloadable to a personal laptop, and synchronisation limited to devices that meet policy. Rollout and instruction for all five people.
- Conditional access set
- Safe Links & Attachments
- Impersonation protection
- Phone app protection
- No download to personal laptops
- Sync limited to compliant devices
- Rollout & instruction
- What it means
- Microsoft keeps your data available, which is not the same as backing it up. Deleted items survive only a limited window. This keeps a separate copy somewhere else, and proves it can actually be restored.
- What you would notice
- Nothing at all, until the day it matters.
- If you leave it out
- A deletion noticed weeks later, or a ransomware incident, becomes permanent. And there is nothing to show an auditor who asks how you would recover.
Independent backup of mail and documents, held outside Microsoft, plus a restore test that is carried out and written up. With no company-owned devices, everything the business holds lives in one place — this is what makes losing it recoverable rather than final. No licence upgrade needed.
- Mail, documents, Teams
- Restore test on record
- EU data residency
- What it means
- The written half: policies, the procedure for adding and removing staff, what to do when an account is suspected of being compromised, and a prepared set of answers to the IT questions banks ask during due diligence.
- What you would notice
- A short set of documents you can hand over, instead of composing answers from scratch each time a bank or counterparty asks.
- If you leave it out
- The security work is real but invisible. Every questionnaire starts from zero, and there is nothing recording which risks you decided to accept.
The written half. IT and security policy, the access model, joiner and leaver procedures, an incident procedure for a suspected account compromise, and a risk register — plus prepared answers to the IT sections of bank due diligence questionnaires. Without this, the security work is real but invisible to the people asking about it. No licence upgrade needed.
- IT & security policy
- Access model
- Joiner / leaver procedure
- Incident procedure
- Risk register
- IT answers for due diligence
- What it means
- Marking which documents are confidential — SPAs, pricing, counterparty material — and enforcing it automatically, so that confidential material cannot quietly leave by email.
- What you would notice
- A label picker appears in Word and Outlook. Now and then a warning when something confidential is about to go outside the company.
- If you leave it out
- Nothing distinguishes a public brochure from a signed SPA, and nothing stops either of them being sent out — deliberately or by an autocompleted address.
Marks what is confidential and enforces it. Labels for SPAs, pricing models and counterparty data; rules that block or warn on unauthorised external sharing across the agreed Microsoft 365 channels, with legitimate exceptions recorded; a retention policy; and a structured document area suitable for use as a data room during due diligence.
- Confidentiality labels
- Outbound rules
- Retention policy
- Data room structure
Ongoing and pass-through
Quoted separately and never folded into the project fee, so you can see exactly what continues after delivery.
The increase over your current licences, not their full cost, and one licence for the separate administrator account. Switches on automatically when an element above requires it.
Five users. This is the storage the restores come from, so it is not a separate choice — it follows the backup element above.
Monthly configuration check, follow-up of alerts, quarterly access review, annual licence check. Office hours, next working day response, one hour of work included per month. Not a 24/7 service. Cancellable monthly.
Optional. The emergency accounts have to work when everything else has failed, which is why the standard alternative — a long random passphrase, sealed and held by a director — is perfectly defensible and costs nothing. Physical keys resist phishing better, but add a failure point of their own: lose the key, or lose access to whoever holds it, and you are worse off than before. Either way the credentials are sealed, tested and held apart from any one person.
Your selection
Included
Left out
What happens next
Approve this selection and the open doors close first — automatic forwarding, anti-phishing, sharing and guest limits, and the emergency access accounts. Delivery is three to four weeks, apart from mail authentication, which runs on another four to six weeks by design: moving faster risks blocking legitimate mail.
Send us your selection
Nothing here is a signature and nothing commits you — it tells us which elements to prepare the proposal for.
Your name, email and any note are stored with the selection so we can follow it up, and removed once the proposal is settled.
Payment
50% on approval, 50% on delivery, in line with previous engagements. VAT reverse-charged under Article 196.
Outside scope
Charged at €60 per hour, and only after written agreement. Nothing is started on assumption.
What this is not
Not a penetration test, not an audit, not a certification. The due diligence material covers the IT chapter only — not KYC, anti-money-laundering or sanctions screening. No deliverable guarantees that a specific bank will accept the environment.