From Very High Risk to Continuous Assurance
How a 160+ User Organization Reduced Microsoft 365 Residual Risk From Very High to Low
-
160+ Microsoft 365 Users
-
Very High → Low Residual Risk
-
17% → 97% Remediation Completion
-
12+ Conditional Access Policies Deployed
-
No User Access Disruptions During Deployment
-
3-Year M365 Assurance Engagement Following Remediation
How a 160+ User Organization Reduced Microsoft 365 Residual Risk From Very High to Low
A mature Microsoft 365 security program requires more than enabling a handful of security features.
When Redeemer Cyber assessed the Microsoft 365 environment of a 160+ user organization, the organization already had an experienced internal IT administrator and an established managed service provider. Yet a detailed assessment against the CIS Microsoft 365 Foundations Benchmark + the Redeemer Cyber Foundations Benchmark revealed significant gaps across identity, email, data protection, privileged access, and other areas of the tenant.
At the beginning of remediation, only 17% of the 161 assessed controls were complete, and the organization's overall Microsoft 365 residual risk was rated Very High.
Over the course of the remediation engagement, Redeemer Cyber worked alongside the organization's longtime IT administrator and MSP to address the findings, strengthen licensing, deploy new security controls, and carefully test changes before enforcement.
By project close:
Remediation completion increased from 17% to 97%.
Overall residual risk decreased from Very High to Low.
More than a dozen Conditional Access policies were deployed without disrupting legitimate user access.
The organization subsequently transitioned from a one-time remediation project into a three-year M365 Assurance engagement designed to maintain its security posture as Microsoft 365 and the CIS benchmark continue to evolve.
The Organization
The client is an established U.S. organization with fewer than 100 employees and more than 160 Microsoft 365 users.
The organization's technology environment was supported by a longtime internal IT administrator and an established managed service provider (MSP). Redeemer Cyber was brought into the engagement through the MSP to provide specialized Microsoft 365 security assessment and remediation expertise.
This model allowed each party to focus on its area of expertise. The internal IT administrator contributed more than a decade of institutional knowledge, the MSP continued to support the organization's broader technology needs, and Redeemer Cyber provided specialized Microsoft 365 security expertise aligned to the CIS Microsoft 365 Foundations Benchmark.
The Microsoft 365 environment was hybrid and initially used a mixture of Microsoft 365 Business Premium and lower-tier Microsoft 365 licensing.
The organization had IT resources and institutional knowledge in place. What it did not have was a comprehensive view of how its Microsoft 365 configuration aligned with a recognized security baseline.
The Assessment: Significant Gaps Beneath the Surface
Redeemer Cyber performed a comprehensive Microsoft 365 Security Assessment against version 6 of the CIS Microsoft 365 Foundations Benchmark + version 1.10 of the Redeemer Cyber Foundations Benchmark, encompassing 161 security controls.
The assessment identified an overall residual-risk rating of Very High.
Among the findings:
-
73% of the 161 benchmark controls were Not Implemented
-
75% of Redeemer Cyber's Top 20 prioritized critical controls were Not Implemented
-
33 controls were classified as Critical and recommended for immediate remediation
-
Multifactor authentication was not fully implemented
-
Phishing-resistant MFA was not implemented
-
Privileged Identity Management was not implemented
-
Automated risky-user Conditional Access response was not implemented
-
Authentication did not require a managed or compliant device
-
SharePoint and OneDrive external-sharing restrictions were not fully implemented
-
Outbound anti-spam limits were not implemented
-
DMARC was only partially implemented
At the start of the subsequent remediation project, just 28 of 161 controls, or approximately 17%, were considered complete.
The assessment provided the organization and its MSP with a prioritized roadmap rather than simply a list of failed configuration checks.
Enabling the Security Capabilities Needed for Remediation
The assessment also identified an important prerequisite: licensing.
The organization was operating with a mixture of Microsoft 365 Business Premium and lower-tier licensing. Some of the security capabilities appropriate for the environment could not be implemented consistently under the existing licensing model.
Before remediation began, the organization worked with its MSP to standardize and expand its Microsoft 365 licensing based on capabilities identified during the assessment. This gave Redeemer Cyber access to additional identity and threat-protection capabilities during remediation while allowing the MSP to continue managing the customer's broader Microsoft technology and licensing relationship.
This expanded the controls available during remediation and enabled greater use of Microsoft's automated identity and threat-protection capabilities.
For example, the improved licensing made it possible to implement risk-based Conditional Access capable of automatically responding to medium- and high-risk authentication events rather than relying exclusively on manual intervention.
The assessment therefore influenced more than configuration changes. It helped the organization align its Microsoft investment with the security architecture it wanted to achieve.
Remediation: Combining Security Expertise With Institutional Knowledge
Redeemer Cyber worked directly with the organization's internal IT administrator throughout remediation.
This collaboration was important.
The administrator had supported the organization for more than a decade and understood its users, applications, operational requirements, and technology environment in detail. Redeemer Cyber brought specialized Microsoft 365 security expertise and a remediation methodology built around the CIS M365 Foundations benchmark.
Rather than treating remediation as a bulk configuration exercise, the organizations worked through the findings together.
Lower-effort controls that were appropriate for the internal administrator to address could be completed outside scheduled remediation sessions. More complex controls requiring security architecture decisions, testing, change management, or specialized Microsoft 365 expertise were addressed collaboratively.
Business requirements, licensing, technical dependencies, and organizational risk tolerance were considered throughout the process.
More Than a Dozen Conditional Access Policies, With No User Lockouts
Conditional Access represented one of the most significant areas of the remediation.
More than a dozen Conditional Access policies were developed to strengthen authentication and access to the organization's Microsoft 365 environment.
These controls can provide substantial security benefits, but improperly designed or deployed Conditional Access policies can also interfere with legitimate authentication and business operations.
Rather than immediately enforcing the new policies, Redeemer Cyber and the organization's IT administrator extensively tested the configuration and evaluated its expected impact.
After validation, the policies were enabled.
Legitimate users were not inadvertently blocked from accessing Microsoft 365.
The result demonstrated an important principle of Microsoft 365 remediation: stronger security controls do not necessarily require unnecessary business disruption when implementation is deliberate, collaborative, and appropriately tested.
The Outcome: From 17% to 97% Remediation Completion
At the beginning of remediation, approximately 17% of the assessed controls were complete.
By project close, 97% of the assessment findings had been addressed.
Remediation completion does not mean that 97% of all CIS recommendations were blindly implemented.
Redeemer Cyber's remediation methodology considers a finding addressed when an appropriate disposition has been reached. Depending on the control and the organization's environment, that may include implementation or a documented decision to block, defer, or not implement a control because of licensing constraints.
Business requirements, technical feasibility, operational impact, and organizational risk tolerance are considered throughout that process.
The objective is not to pursue a perfect benchmark score regardless of business impact.
It is to ensure that findings are evaluated, risks are understood, appropriate controls are implemented, and exceptions are deliberate rather than overlooked.
The Security Outcome: Very High Risk to Low Risk
The improvement was not limited to remediation completion.
Before remediation, the organization's Microsoft 365 environment carried an overall Very High residual-risk rating.
Following remediation, its residual-risk rating had been reduced to Low.
That distinction is important.
Completing a security checklist is not the ultimate objective of remediation. The objective is to meaningfully reduce the risks affecting the organization while maintaining an environment that remains usable and aligned with business requirements.
The organization moved from an environment with widespread security gaps and dozens of Critical findings to one where the overwhelming majority of assessment findings had been deliberately addressed and remaining risk had been substantially reduced.
From a One-Time Project to Continuous Assurance
Microsoft 365 security does not remain static after remediation.
Microsoft continually develops the platform. Threats evolve. Organizations change. Licensing changes. New security capabilities become available.
The CIS Microsoft 365 Foundations Benchmark evolves as well, with new and updated recommendations released twice a year, typically in the spring and fall.
Following the successful remediation engagement, the organization chose to continue working with Redeemer Cyber through a three-year M365 Assurance engagement.
Rather than waiting several years for another major security project, Redeemer Cyber now returns twice each year in alignment with the biannual CIS Microsoft 365 Foundations Benchmark release cycle.
New and updated security controls are reviewed and remediated during these engagements. Following the second remediation cycle of the year, Redeemer Cyber performs another comprehensive Microsoft 365 Security Assessment to validate the environment against the latest benchmark and identify the next set of priorities.
The result is a recurring security lifecycle:
Assess. Remediate. Maintain.
Key Results
Key Results:

Why the Engagement Worked: IT + MSP + Security Specialist
The engagement succeeded because each party brought a different type of expertise.
The organization's internal IT administrator contributed more than a decade of institutional knowledge and understood its users, applications, and operational requirements. The MSP supported the organization's broader technology environment and helped align Microsoft licensing with the security capabilities required. Redeemer Cyber provided specialized Microsoft 365 security assessment, architecture, and remediation expertise.
Redeemer Cyber was not brought in to replace the organization's IT team or MSP. It was brought in to provide specialized depth in an area where additional expertise was valuable.
That collaborative model allowed significant Microsoft 365 security changes to be implemented while accounting for the organization's users, applications, business requirements, existing technology relationships, and risk tolerance.
About This Case Study
This case study is based on an anonymized Microsoft 365 security assessment and remediation engagement delivered through a Redeemer Cyber channel relationship.
Organization size, industry, licensing details, and other identifying characteristics have been generalized where appropriate to protect client confidentiality. Assessment and remediation outcomes have been retained to accurately represent the engagement.
Individual Microsoft 365 environments differ. The results described here should not be interpreted as a guarantee that another organization will achieve the same security posture or remediation outcome.
Assess. Remediate. Maintain.
A Microsoft 365 Security Assessment establishes the baseline.
Remediation turns findings into security improvements.
Ongoing assurance helps prevent the environment from falling behind as Microsoft 365, the CIS M365 benchmark, and the organization's own requirements continue to change.
Microsoft 365 security is not determined solely by whether an organization owns premium licensing, has enabled MFA, or has an internal IT team.
The configuration beneath those investments matters.
A benchmark-based assessment provides organizations with an independent view of that configuration, identifies gaps that may otherwise remain unnoticed, and provides a prioritized roadmap for strengthening the environment.
For organizations that have already invested heavily in Microsoft 365 security, the question may no longer be whether security controls exist.
It may be whether those controls have been implemented as comprehensively as the organization believes.
How Does Your Microsoft 365 Environment Compare?
Redeemer Cyber's Microsoft 365 Security Assessment evaluates your environment against the latest CIS Microsoft 365 Foundations Benchmark, the Redeemer Cyber Foundations Benchmark, identifies security gaps, and provides a prioritized roadmap with supporting documentation and a remediation tracker.
Ready to benchmark your Microsoft 365 security posture? Contact Redeemer Cyber to discuss an assessment.
Contact us to request a Microsoft 365 Security Assessment today.
