top of page
All Posts


5 Essential Security Measures for Microsoft 365 You Shouldn't Ignore
5 Essential Security Measures for Microsoft 365 You Shouldn't Ignore

Kyle Cira
Jul 30, 20253 min read


Redeemer Cyber: Your Friendly Neighborhood Spi…CIS M365 Consensus Team Member!
I’m excited and humbled to share that Redeemer Cyber is officially part of the Center for Internet Security (CIS) Microsoft 365 Consensus Team! This is the team that helps steer the development of the CIS Microsoft 365 Foundations Benchmark — the global standard for securing Microsoft 365 environments. What This Means The CIS Microsoft 365 Benchmark is relied upon by businesses, municipalities, and organizations worldwide as a trusted framework for securing Microsoft 365. The

Kyle Cira
5 days ago2 min read


Opinion: Why AI-Driven Remediation Is Dangerous
Artificial intelligence has become deeply embedded in cybersecurity tooling, but not always appropriately. AI excels at pattern recognition, telemetry analysis, and surfacing potential risks at scale. But when it comes to automated remediation in production environments , AI can quickly cross from helpful to harmful. Every Production Environment Is Unique No two organizations operate the same way. Even within the same industry, environments differ in meaningful ways: Approval

Kyle Cira
Jan 72 min read


Microsoft’s Zero Trust Assessment Tool: Valuable, but Only Covers About 25% of CIS M365 v6
Microsoft offers a free Zero Trust Assessment tool that organizations can use as a starting point to evaluate their Microsoft 365 security posture. It’s accessible, easy to run, and provides meaningful insight—but it’s important to understand what it does and what it doesn’t do.When measured against the CIS Microsoft 365 Benchmark v6, Microsoft’s Zero Trust Assessment covers roughly 25% of the controls. That doesn’t make it useless—but it does mean it should be viewed as a fi

Kyle Cira
Dec 17, 20253 min read


Deep Dive: Implementing CIS M365 v6 Control 2.1.15 (L1) – Ensure Outbound Anti-Spam Message Limits Are in Place
The CIS Microsoft 365 Benchmark v6 introduces control 2.1.15 (L1) “Ensure outbound anti-spam message limits are in place”, which helps organizations contain abuse of compromised accounts and prevent domain-wide reputational damage.
This blog provides a full breakdown of why this control matters, how to implement it, and why Redeemer Cyber played a key role in bringing this control to life.

Kyle Cira
Dec 2, 20255 min read


Top 5 New Controls in the CIS Microsoft 365 Benchmark Version 6
The Center for Internet Security (CIS) recently released version 6 of the Microsoft 365 Security Benchmark, and with it comes several powerful new controls designed to strengthen cloud security and reduce modern threat risks.

Kyle Cira
Nov 12, 20253 min read


Redeemer Cyber Deliverables Are Now Updated to the Latest CIS Microsoft 365 Benchmark v6!
The Center for Internet Security (CIS) recently released version 6 of the Microsoft 365 Security Benchmark on October 31, 2025, bringing new and updated recommendations that strengthen organizational cloud security.
Redeemer Cyber is proud to announce that all of our Microsoft 365 Security Assessment and Remediation deliverables are now fully aligned to CIS M365 v6—within just one day of its release.

Kyle Cira
Nov 5, 20252 min read


The Limitations of Microsoft 365 Cybersecurity Scanning Tools
Automated scanning tools are powerful—but they’re not perfect. Many organizations rely entirely on them to evaluate their Microsoft 365 security posture, only to discover later that “100% compliant” didn’t mean what they thought it did.
Here’s the reality: even the best Microsoft 365 cybersecurity scanning tools can only go so far.

Kyle Cira
Oct 22, 20252 min read


Assess, Remediate, and Maintain with Redeemer Cyber
Cybersecurity isn’t a one-and-done event — it’s a continuous process. That’s why Redeemer Cyber’s “The Works” Microsoft 365 Assurance Package is built around a simple but powerful principle: Assess. Remediate. Maintain.

Kyle Cira
Oct 8, 20252 min read


The Redeemer Cyber Advantage
In today’s threat landscape, every business is being told they need cybersecurity. Managed Service Providers (MSPs) offer to “take care of IT and security.” Managed Security Service Providers (MSSPs) sell 24×7 monitoring and alerts. Automated tools promise a quick scorecard that tells you how secure—or insecure—you are.
So why choose Redeemer Cyber instead? Because none of those approaches are designed to deliver what you actually need: non-invasive, expert-led and thorough

Kyle Cira
Oct 1, 20253 min read


Why SharePoint Needs to Be Secured on Day 1
SharePoint and OneDrive are powerful tools for collaboration, but they come with risks if left in their default state. Too often, organizations roll out Microsoft 365 and focus on productivity first—leaving security as an afterthought. Unfortunately, this creates a perfect window of opportunity for attackers.

Kyle Cira
Sep 24, 20252 min read


How Redeemer Cyber Helps Shape the CIS Microsoft 365 Benchmark
Over the years, our founder has submitted more than 60 accepted tickets to CIS—ranging from corrections and enhancements to refinements in control impacts and rationale.
This dedication earned him recognition as one of just 15 officially credited contributors to the CIS M365 Benchmark, trusted worldwide by businesses, governments, and non-profits.

Kyle Cira
Sep 18, 20252 min read


Top Ten Reasons to Consider Microsoft 365 E5
Cyber Budget When it comes to Microsoft 365 licensing, many organizations hesitate at the price tag of Microsoft 365 E5. But in practice,...

Kyle Cira
Sep 10, 20253 min read


Top 5 Microsoft 365 “Gotchas” I Wish I Knew Sooner
Microsoft 365 is a powerful platform, but it comes with quirks that can surprise even experienced administrators. Over the years, I’ve...

Kyle Cira
Sep 3, 20252 min read


Why Redeemer Cyber Standardized on the CIS Microsoft 365 Benchmark
We’ve standardized on the CIS Microsoft 365 Foundations Benchmark—the most trusted, comprehensive, and actionable security benchmark available for Microsoft 365.
Here’s why we not only use it—but contribute to it.

Kyle Cira
Aug 27, 20252 min read


8 Tangential Benefits of an Independent Expert-Led Security Assessment
Cyber Analyst at work When organizations think of a security assessment, the immediate value that comes to mind is identifying...

Kyle Cira
Aug 20, 20252 min read


Story Time: How User App Consent Crippled a Business (Yes, This Really Happened)
Cyber attacker sends Phishing email. Based on a True Story A user received a phishing email and—like many unsuspecting employees—clicked...

Kyle Cira
Aug 13, 20252 min read


Thoughtfully implementing MFA while balancing Risk and User Experience
Secure Shield Multi-Factor Authentication (MFA) is one of the most effective ways to prevent unauthorized access, and many organizations...

Kyle Cira
Aug 5, 20252 min read
bottom of page
