Cyber Security Review

Cyber exposure often starts in Microsoft 365, email, identity or access. It rarely stays there

For many organisations the issue is not that no controls exist. It is that the exposure sits across several areas at once — identity, email, Microsoft 365, access and backup. Inlight IT helps make sense of how those risks connect and identify the practical actions that matter most.

  • A conversation about where exposure sits, not a generic audit
  • Shaped around the concern you arrive with
  • Practical next actions, prioritised
Common areas in the conversation
Microsoft 365 and identity
Entra ID posture, MFA, Conditional Access and privileged access
Email and payment workflows
Business email compromise, forwarding risk and payment verification
Endpoint and device posture
Coverage, policy consistency and whether alerts are actioned
Backup and testing scope
Microsoft 365 backup exposure and penetration testing scope
Connected exposure

Cyber risk rarely sits in one place. It is now one connected conversation.

A loosely controlled Microsoft 365 tenant is not only a Microsoft 365 problem. Business email compromise is not only an email problem. Select an area below to see what it usually connects to. The practical question is not "which cyber product do we need?" It is "where does the real exposure sit, and what should be addressed first?"

Where exposure concentrates

The same weaknesses often appear across several cyber concerns.

Six areas where exposure most commonly concentrates in Australian environments. Select one to see what usually needs attention.

Microsoft 365 and Entra ID
Security depends on identity, access policy, tenant configuration, administrator hygiene, external sharing, app consent, mailbox controls, logging and alerting. Native Microsoft capability is strong, but only when configured and operated with the right controls. Common exposure areas include Conditional Access gaps, weak MFA methods, unmanaged app consent, stale accounts, excessive administrator access, risky external sharing, mailbox forwarding and insufficient visibility into tenant-level security events.
Business email compromise and payment verification
BEC sits between technology and business process. A fraudulent supplier payment request, compromised mailbox or executive impersonation attempt may succeed even when email filtering is in place. The risk often sits across mailbox access, forwarding rules, display-name impersonation, SPF/DKIM/DMARC posture, supplier verification, finance approvals and payment-change controls. The question is not only whether an email is malicious. It is whether the business process can resist a convincing fraudulent request.
Identity and privileged access
Identity is now one of the main control planes in the environment. Email, files, cloud applications, admin portals and remote access all sit behind user and administrator identity. MFA coverage matters, but so does MFA quality, Conditional Access coverage, privileged role hygiene, break-glass access, stale users, risky sign-ins, admin consent and session controls. "MFA is enabled" does not automatically mean identity exposure is under control.
Endpoint and device posture
Endpoint protection may be deployed, but coverage, policy consistency, alert visibility and remediation pathways still matter. A tool that is installed but not monitored or acted on does not materially reduce exposure. Endpoint posture becomes more important when the organisation is dealing with account compromise, phishing, lateral movement risk, external access, unmanaged devices or uncertainty about whether alerts are being reviewed and actioned.
Microsoft 365 backup and recovery exposure
Microsoft 365 native retention is not the same as independent backup. That distinction becomes important when the concern includes accidental deletion, malicious deletion, cyber attack, compromised administrator accounts, retention gaps, large-volume restore or cyber insurance evidence. For many organisations, the backup question is not only about data protection. It is also about identity, administrator separation, restore testing, retention, recovery evidence and what would happen if the tenant itself became part of the incident.
Penetration testing and validation
Penetration testing should validate a specific concern. It may be external exposure, internal movement, web application weakness, Microsoft 365 or cloud configuration, phishing susceptibility or assumed compromise. The useful question is not simply "should we get a penetration test?" It is "what do we need the test to prove, and what scope will produce evidence we can act on?"
The practical problem

The issue is often clear enough to worry about, but not clear enough to scope.

This is where many CIOs, Heads of IT and internal technology teams get stuck. They may know Microsoft 365 needs review, but not whether the priority is Conditional Access, app consent, external sharing, privileged access, mailbox rules, backup or alert visibility. They may know business email compromise is a risk, but not whether the weakness is technical, procedural, financial approval workflow, mailbox monitoring, supplier verification or user behaviour.

They may be asked for penetration testing, but not know whether the useful scope is external, internal, web application, Microsoft 365 or cloud configuration, phishing simulation or assumed-compromise testing. They may have a cyber insurance renewal, board question or customer due diligence request, but not enough evidence to answer confidently. The practical need is not another generic cyber report. It is a clear view of where the exposure sits, what matters most and what should be addressed first.

Practical support

We help make the exposure clear enough to act on.

Inlight IT helps Australian organisations review the areas where cyber exposure commonly concentrates: Microsoft 365, identity, email security, business email compromise, payment verification, endpoint posture, privileged access, Microsoft 365 backup, external exposure and testing scope. The work follows the concern you actually have, rather than a fixed template.

Where the material exposure sits, and which controls are present but not strong enough

Whether the issue is technical, procedural or both

What should be remediated first, and what needs validation

What can be handled internally, and where specialist support is required

One organisation may need to understand whether Microsoft 365 and Entra ID are configured defensibly. Another may need to reduce business email compromise and payment redirection risk. Another may need to know whether penetration testing is the right next step, and what the test should prove. The aim is to make the exposure clear enough to act on.

Common questions

Practical questions about what a review is, and is not.

Is this a productised assessment with fixed deliverables?

No. A Cyber Security Review is the starting point when the concern cuts across several cyber areas and is not yet narrow enough to pin to a single piece of work. Its job is to locate the concern and identify the practical next step, not to sell a fixed-scope assessment. Where a narrower, productised engagement is the right answer, such as an Essential Eight Assessment or a Recovery Readiness Assessment, the review points there.

Where does the exposure usually sit?

It varies by organisation, which is the point. It commonly concentrates across Microsoft 365 and Entra ID, identity and privileged access, email and business email compromise, payment verification, endpoint posture, Microsoft 365 backup and penetration testing scope. The same weaknesses often appear across several of these at once, which is why a connected view helps.

We think we need a penetration test. Is that the right first step?

Sometimes, and sometimes not. A test is useful when the scope is clear and the organisation knows what it needs to validate. External, internal, web application, cloud configuration and phishing simulation all answer different questions. The value comes from the right scope, not from commissioning a generic test. A review helps decide what the test needs to prove first.

How is this different from Managed Cyber Security or an Essential Eight Assessment?

A Cyber Security Review helps locate a cross-cutting concern and decide the next step. Managed Cyber Security is the ongoing operating layer for organisations that need continuous monitoring and response. An Essential Eight Assessment establishes a defensible maturity position at a point in time. The review often points to one of these once the material exposure is clear.

Is business email compromise a technical problem or a process problem?

Usually both. Many BEC attacks succeed without malware or obvious malicious links because they exploit trust, timing and workflow. The risk sits across mailbox access, forwarding rules, impersonation, SPF/DKIM/DMARC posture, supplier verification, finance approvals and payment-change controls. The question is whether the business process can resist a convincing fraudulent request, not only whether an email is malicious.

Practical next step

Understand where the exposure sits before deciding the work.

Discuss your cyber security position