Why the standard matters
A plain findings list says fourteen accounts have no MFA. A mapped finding says the same thing, then names the control it fails and attaches the evidence. Same work on our side. Very different on yours, because the second one can go to an insurer, a client's security team or your own board without being rewritten first.
Most small firms do not need a framework programme. They need their existing exposure described in language the person asking has to accept.
What it is worth to you
Three things tend to pay for this, and none of them are the report itself.
Deals you would otherwise lose. Enterprise clients and their insurers increasingly send a security questionnaire before signing. A mapped assessment answers most of it directly, with evidence, in a day rather than a fortnight of guessing. Firms lose work at that stage more often than they realise, and usually never find out why.
Licence spend you are already wasting. Every assessment includes a page on what you pay for and do not use. On a tenant of any size that often covers the fee on its own, and unlike the fee, the saving repeats every month.
The incident you do not have. The three findings most likely to end badly are a leaver who can still read email, an unpatched build, and an admin account with no MFA. All three are cheap to close once someone has actually looked. The cost of not looking arrives all at once, usually on a Friday.
NIST CSF 2.0, and the parts we actually cover
CSF 2.0 has six functions: Govern, Identify, Protect, Detect, Respond and Recover. Microsoft 365 and Intune live mostly in Identify, Protect and Detect, and that is where our report scores you, control by control.
Govern, Respond and Recover need decisions, people and practice rather than settings. We tell you plainly what is missing there and we stay out of writing your policies for you. You do not need a consultant inventing a governance function nobody will ever run.
CIS Benchmarks, the settings layer
CSF tells you which outcome to aim at. It does not tell you which Intune toggle. The CIS Microsoft 365 Foundations Benchmark and the CIS Windows Benchmark do, and both map cleanly onto Intune configuration profiles and security baselines.
So every finding carries two references: the control you are failing, and the exact setting that closes it. That is the difference between a report you read and a report you can act on.
Essential Eight, for Australian clients
If you report against the Essential Eight instead, the same assessment produces a maturity level per mitigation strategy: application control, patch applications, configure macro settings, user application hardening, restrict admin privileges, patch operating systems, multi factor authentication, regular backups.
We score where you are today and price what reaching Maturity Level One or Two would actually take, rather than asserting you are already there.
What a mapped finding looks like
Three real examples, anonymised. Every finding in the report is laid out this way.
| Control | What we found | Evidence | The fix | Effort |
|---|---|---|---|---|
| CSF PR.AA-03 CIS M365 1.1.1 | Fourteen of sixty one accounts can sign in with a password alone | Entra sign in logs, per user list attached | Conditional Access policy requiring MFA for all users, report only first, then enforced | Half a day |
| CSF PR.PS-02 CIS Windows 18.9 | Update rings exist but forty devices sit on a build past end of support | Intune update ring membership export | Rebuild rings, move the estate to Autopatch, verify over two cycles | Two days |
| CSF PR.DS-01 CIS M365 3.1 | BitLocker on by default, recovery keys never checked, nine devices have no key escrowed | Intune encryption report | Fix the policy, force re escrow, verify every key restores | One day |
What we are not
We are not auditors and we do not certify anyone. There is no NIST certification for a company of your size, whatever a vendor may have implied, and CSF is a framework rather than a pass or fail exam.
What we do is get your tenant into a state where an assessor, an insurer or your largest client's security team has nothing easy to complain about, and hand you the evidence in writing. If you later need a formal audit, you walk into it prepared instead of guessing.
Where it starts
The $750 Full Security Assessment, with the mapping included at no extra cost. Tell us which standard you report against and the report comes out in that language. If you do not report against anything yet, CSF is the sensible default and the one most insurers and enterprise clients recognise.