Cybersecurity
Cybersecurity · Capability

Microsoft 365 hardening

Secure-score-driven hardening of email, sharing and device access — closing the doors most attacks actually walk through.

Microsoft 365 ships with Secure Score, a running measurement of how your tenant's actual configuration compares to Microsoft's recommended baseline across identity, email, devices and apps. It's a genuinely useful starting point because it's specific: not "is email secure" but which individual settings — external forwarding rules, unmanaged legacy authentication protocols, missing device compliance policies — are pulling the score down, each with a defined remediation and effort estimate.

The reason to work through it methodically is that most breaches into Microsoft 365 don't come through a novel exploit; they come through an inbox rule quietly forwarding mail to an external address, an anonymous SharePoint link shared once and never revoked, or a personal unmanaged phone with full mailbox access. Hardening sharing defaults, tightening device access policies and closing legacy protocols is unglamorous work, but it's exactly the set of doors attackers actually walk through, not the ones that make headlines.

The actual products

Microsoft Secure Score

Baseline configuration scoring across identity, email, devices and apps, with a remediation and effort estimate per setting.

Defender for Office 365 (E5)

Email, attachment and link threat protection — the layer most phishing attempts actually hit first.

Exchange Online Protection

Baseline spam and phishing filtering included in every Microsoft 365 email plan.

Part of Cybersecurity

The more connected your operations become, the more there is to protect. We secure identities, devices, information and cloud environments — pragmatically, in the order that reduces the most risk first, with the Microsoft and Acronis tooling your licences likely already include.

Also part of Cybersecurity
Questions we hear about Cybersecurity
We're a small company — are we really a target?

Yes, precisely because attackers assume your defences are weaker — roughly half of small businesses report attacks. The good news: five essentials stop the large majority of real-world attacks — multi-factor authentication, modern endpoint protection, email security, tested backups and staff awareness. You need those five done properly, not twenty products.

Is multi-factor authentication really necessary?

It is the highest-impact control per pula you will ever spend: Microsoft's research puts MFA at blocking about 99.9% of automated credential attacks. It is already included in your Microsoft 365 licence — the work is enforcing it properly, with conditional access and no legacy-authentication loopholes. Cyber insurers now treat it as mandatory.

What do cyber insurers require before covering us?

Three controls have become effectively non-negotiable: MFA on email, admin and remote access; endpoint detection and response on every device; and tested, immutable backups. Just as important is documented evidence of all three — most declined applications fail on proof, not on tooling. We implement the controls and produce the evidence pack.

What does Botswana's Data Protection Act require of us?

The Data Protection Act, 2024 — in force since 14 January 2025 — applies to any processing of personal data in Botswana. It requires appropriate technical and organisational security measures, notification of breaches to the Commission within 72 hours, and a data protection officer for certain categories of processing. Penalties reach BWP 50 million or 4% of global turnover. The technical half of compliance is exactly the security baseline above.

Our staff are the weak link — what do we do about phishing?

Most incidents start with a phished credential, so treat people as a control, not a liability: awareness training with phishing simulations, email filtering in front of the inbox, and MFA behind it so a single click is never fatal. It is inexpensive, measurable, and insurers recognise it.

Platforms: Microsoft Entra ID · Microsoft 365 · Acronis Cyber Protect · Azure