How we work
Four stages. Predictable outcomes. No surprises.
Every engagement follows the same structure. You know what you are getting, when you are getting it, and how much it costs — before we start.
Our four-stage process
Assess
Establish your security baseline. We map your current security posture against NIST Cybersecurity Framework, plus a SaaS-specific posture review covering identity, email, file-sharing, endpoint, and access patterns.
Deliverable: Posture report + prioritized gap list.
Plan
A roadmap your CEO can read and your auditor can verify. We prioritize the fixes that reduce risk for your business.
Deliverable: 12-month roadmap + cost projections + control ownership matrix.
Operate
We execute the roadmap directly or coach your team through it. Introduce security monitoring of identity, email, file-sharing, and endpoint surfaces.
Deliverable: Hardened tenant + documented control changes + evidence package.
Report
Monthly scorecards. Quarterly executive readouts. Audit-ready evidence and support.
Deliverable: Monthly posture scorecard + quarterly briefing + evidence library.
The technologies we secure
We work across Microsoft 365 and Google Workspace. Same capabilities, same posture, regardless of which platform you run on.
| Capability | Microsoft 365 | Google Workspace |
|---|---|---|
| Identity | Entra ID, Conditional Access, Identity Governance | Cloud Identity, Context-Aware Access, Chrome Enterprise |
| Email & collaboration | Defender for Business, Defender for Office | Gmail Security, Drive Sharing Controls |
| Endpoint | Defender for Endpoint, Intune | Google Endpoint Management, Chrome Enterprise |
| Threat detection & response | Sentinel | Google SecOps |
| Posture & compliance | Secure Score | Security Center |
Identity
Entra ID, Conditional Access, Identity Governance
Cloud Identity, Context-Aware Access, Chrome Enterprise
Email & collaboration
Defender for Business, Defender for Office
Gmail Security, Drive Sharing Controls
Endpoint
Defender for Endpoint, Intune
Google Endpoint Management, Chrome Enterprise
Threat detection & response
Sentinel
Google SecOps
Posture & compliance
Secure Score
Security Center
We work with your existing Microsoft 365 or Google Workspace investment.
What you get from us
Every engagement produces concrete, usable artifacts. Select a deliverable to preview a sample.
Posture report
A clear, prioritized picture of your current security gaps — identity, email, endpoint, and access patterns.
Control roadmap
A sequenced plan of remediation actions ranked by risk-reduction-per-dollar, with cost projections.
Evidence package
Auditor-ready documentation of every control implemented, every configuration change, and every test result.
Monthly scorecard
A single-page posture summary tracking key metrics: MFA coverage, admin role assignments, stale OAuth grants, and more.
Quarterly readout
An executive briefing that translates technical posture into business risk — written for a board, not a SOC analyst.
View Ridge Security
SampleCybersecurity Posture Assessment
Prepared for Contoso Advisory Group · January 2026
Assessment summary
View Ridge Security assessed Contoso Advisory Group's security posture across identity and authentication, access control and sharing, email and application security, device security, and security awareness. The assessment combined leadership and staff interviews with a configuration review of Entra ID, email security, and document collaboration settings.
Observations of good security practices
- Multi-factor authentication is widely used across staff accounts.
- Documents are shared via links rather than attachments as standard practice.
- High awareness of the sensitivity of client data throughout the firm.
- Minimum required access to client documents is granted to staff and clients.
- No shared accounts or passwords were observed.
- Corporate-issued laptops are prevalent.
Risk findings summary
| Priority | Vulnerability | Description |
|---|---|---|
| High | Laptop security | Inconsistent security configurations; no central management. |
| High | Email security | Basic email security in use; advanced options can increase protection. |
| High | MFA settings | Authenticator apps provide stronger protection than SMS or email codes. |
| High | Identity Secure Score | Findings from automated assessment of Entra ID security settings. |
| Medium | Security training | Security awareness and technology experience varies widely. |
| Medium | Security policy | Well understood but undocumented; not meeting best-practice standards. |
| Medium | External collaborators | No time limits or periodic reviews for shared links and collaborator access. |
| Medium | Personal accounts | Personal accounts on user-owned devices are an opening for data exposure. |
| Low | Secondary accounts | Use single sign-on where available to prevent access by former employees. |
| Low | Document backup | No backup solution providing strong resilience against ransomware. |
Detailed finding — laptop security
- Inconsistent security configurations: antimalware, device encryption, password policy, OS versions and patches.
- No central management or visibility of security configurations.
- No ability to enforce device security as a condition of access to company data.
- No ability to remotely delete company data.
Recommendation
Detailed finding — multi-factor authentication
A few Entra ID accounts are not configured to enforce MFA, though most are. Text messages (SMS) and email codes are less secure than authenticator apps.
Recommendation
Detailed finding — information security policy
Data security and handling practices are well understood and routinely followed by staff. However, policies are undocumented, which undermines their sustainability and the firm's ability to demonstrate that reasonable protections are enforced to protect client data.
Recommendation
Start with the free Posture Self-Check. See where you stand in minutes.
Identity, email, endpoint, and access patterns — assessed against the controls that matter to your customers, your auditors, and your bottom line.
Free Posture Self-Check