NIST CSF 2.0 · CIS Benchmarks · Essential Eight

Hardening to a standard, not to opinion.

Same assessment, written so every finding points at a named control. It goes straight into an insurance renewal or a client security questionnaire without anyone rewriting it.

Why the standard matters

A plain findings list says fourteen accounts have no MFA. A mapped finding says the same thing, then names the control it fails and attaches the evidence. Same work on our side. Very different on yours, because the second one can go to an insurer, a client's security team or your own board without being rewritten first.

Most small firms do not need a framework programme. They need their existing exposure described in language the person asking has to accept.

What it is worth to you

Three things tend to pay for this, and none of them are the report itself.

Deals you would otherwise lose. Enterprise clients and their insurers increasingly send a security questionnaire before signing. A mapped assessment answers most of it directly, with evidence, in a day rather than a fortnight of guessing. Firms lose work at that stage more often than they realise, and usually never find out why.

Licence spend you are already wasting. Every assessment includes a page on what you pay for and do not use. On a tenant of any size that often covers the fee on its own, and unlike the fee, the saving repeats every month.

The incident you do not have. The three findings most likely to end badly are a leaver who can still read email, an unpatched build, and an admin account with no MFA. All three are cheap to close once someone has actually looked. The cost of not looking arrives all at once, usually on a Friday.

NIST CSF 2.0, and the parts we actually cover

CSF 2.0 has six functions: Govern, Identify, Protect, Detect, Respond and Recover. Microsoft 365 and Intune live mostly in Identify, Protect and Detect, and that is where our report scores you, control by control.

Govern, Respond and Recover need decisions, people and practice rather than settings. We tell you plainly what is missing there and we stay out of writing your policies for you. You do not need a consultant inventing a governance function nobody will ever run.

CIS Benchmarks, the settings layer

CSF tells you which outcome to aim at. It does not tell you which Intune toggle. The CIS Microsoft 365 Foundations Benchmark and the CIS Windows Benchmark do, and both map cleanly onto Intune configuration profiles and security baselines.

So every finding carries two references: the control you are failing, and the exact setting that closes it. That is the difference between a report you read and a report you can act on.

Essential Eight, for Australian clients

If you report against the Essential Eight instead, the same assessment produces a maturity level per mitigation strategy: application control, patch applications, configure macro settings, user application hardening, restrict admin privileges, patch operating systems, multi factor authentication, regular backups.

We score where you are today and price what reaching Maturity Level One or Two would actually take, rather than asserting you are already there.

What a mapped finding looks like

Three real examples, anonymised. Every finding in the report is laid out this way.

ControlWhat we foundEvidenceThe fixEffort
CSF PR.AA-03
CIS M365 1.1.1
Fourteen of sixty one accounts can sign in with a password aloneEntra sign in logs, per user list attachedConditional Access policy requiring MFA for all users, report only first, then enforcedHalf a day
CSF PR.PS-02
CIS Windows 18.9
Update rings exist but forty devices sit on a build past end of supportIntune update ring membership exportRebuild rings, move the estate to Autopatch, verify over two cyclesTwo days
CSF PR.DS-01
CIS M365 3.1
BitLocker on by default, recovery keys never checked, nine devices have no key escrowedIntune encryption reportFix the policy, force re escrow, verify every key restoresOne day

What we are not

We are not auditors and we do not certify anyone. There is no NIST certification for a company of your size, whatever a vendor may have implied, and CSF is a framework rather than a pass or fail exam.

What we do is get your tenant into a state where an assessor, an insurer or your largest client's security team has nothing easy to complain about, and hand you the evidence in writing. If you later need a formal audit, you walk into it prepared instead of guessing.

Where it starts

The $750 Full Security Assessment, with the mapping included at no extra cost. Tell us which standard you report against and the report comes out in that language. If you do not report against anything yet, CSF is the sensible default and the one most insurers and enterprise clients recognise.

Book the $750 assessment

Talk to an engineer, not a sales deck.

Fifteen minutes on video. Tell us roughly how many people and devices, and we will tell you what we would look at first and what it would cost.

Book a 15 minute callOr email [email protected]. An engineer replies within one business day.