top of page

What Three Community Bank Microsoft 365 Assessments Revealed

An anonymized analysis of CIS Microsoft 365 security findings across three established United States community banks.

  • 3 Community Banks Assessed

  • $3.2B+ Combined Assets

  • 700+ Microsoft 365 Users

  • 35% to 65% of the top 20 critical controls were Not Implemented.

  • 31-45% of critical controls Not Implemented

  • 35-54% of benchmark controls Not Implemented

Significant Security Gaps Can Remain Even in Mature, Regulated Microsoft 365 Environments

Community banks operate in a highly regulated environment where cybersecurity is already a significant priority. They often have dedicated IT resources, established security practices, cybersecurity insurance requirements, regulatory examinations, and technology vendors supporting their environments.

Yet Microsoft 365 is a large and continually evolving platform. Having security tools in place does not necessarily mean every available security control has been fully configured.

Redeemer Cyber recently performed CIS Microsoft 365 security assessments for three established community banks in the United States. The institutions ranged from fewer than 50 employees to approximately 200 employees, operated across multiple locations, and ranged from hundreds of millions to more than $1 billion in total assets.

All three organizations had internal IT resources and meaningful Microsoft 365 security controls already in place.

Despite that existing security maturity, each assessment identified significant opportunities for additional Microsoft 365 hardening.

The Assessment Population

The three banks represented substantially different Microsoft 365 environments​​​

Two assessments were performed against version 7 of the CIS Microsoft 365 Foundations Benchmark, which contained 180 controls. The third was performed against version 6, which contained 161 controls.

Because the benchmark versions contain different numbers of controls, percentages are used where appropriate when comparing assessment results.

bank table.png

Finding #1: More Than One-Third of Benchmark Controls Were Not Implemented at Every Bank

The percentage of CIS Microsoft 365 controls classified as Not Implemented was:

  • Bank A: 54%

  • Bank B: 35%

  • Bank C: 36%

 

The median was 36% Not Implemented.

This means that even the strongest of the three environments had more than one-third of the assessed CIS Microsoft 365 security controls completely unimplemented.

These results should not be interpreted as evidence that community banks generally have a particular level of Microsoft 365 security maturity. Three institutions are too small a sample to establish industry prevalence. Instead, they demonstrate that substantial configuration gaps can exist even within established and regulated organizations with dedicated IT resources.

Finding #2: Missing Controls Included High-Priority Security Measures

The number of missing controls alone does not tell the entire story. Some controls have substantially greater security implications than others.

Redeemer Cyber prioritizes a subset of 20 controls considered particularly important to reducing Microsoft 365 security risk.

Among those Top 20 controls, the percentage classified as Not Implemented was:

Top 20 controls Not Implemented:

  • Bank A: 65%

  • Bank B: 45%

  • Bank C: 35%

The median bank had 45% of these Top 20 controls Not Implemented.

Redeemer Cyber's M365 Security Assessment also assigns a Critical severity to controls that warrant immediate remediation. Among controls classified as Critical:

  • Bank A: 26 of 58, or 45%, were Not Implemented

  • Bank B: 18 of 58, or 31%, were Not Implemented

  • Bank C: 18 of 53, or 34%, were Not Implemented

 

In other words, between approximately one-third and nearly one-half of the controls classified as Critical by Redeemer Cyber were completely unimplemented across these three assessments.

Finding #3: These Were Not Unprotected Microsoft 365 Environments

Perhaps the most important observation is what the assessments did not find.

These were not Microsoft 365 tenants with no security controls in place.

 

All three banks had implemented or at least partially implemented multifactor authentication. All three had blocked legacy authentication. All three had disabled SharePoint external sharing. All three had at least partially established emergency access, or "break-glass," accounts. Each also had internal IT resources responsible for its technology environment.

 

Two of the three had external sender warnings configured in Exchange Online. Privileged Identity Management was at least partially implemented in two environments.

 

These organizations had already taken meaningful steps to secure Microsoft 365.

 

The assessments identified what remained.

Finding #4: "We Have MFA" Did Not Mean Identity Security Was Complete

Multifactor authentication is one of the most important identity security controls available to an organization, but simply determining whether MFA exists provides an incomplete picture of identity security.

 

All three banks had MFA at least partially deployed.

 

A deeper review revealed additional differences.

 

Bank A had MFA fully implemented for users but only partially implemented for administrators. Phishing-resistant MFA was not implemented, automated Conditional Access response for risky users was not configured, and managed or compliant devices were not required for authentication.

 

Bank B had MFA partially implemented for both users and administrators. Automated risky-user Conditional Access was not configured, and authentication did not require a managed or compliant device.

 

Bank C had fully implemented MFA for users and partially implemented MFA for administrators. It had made additional progress, including partial implementation of phishing-resistant MFA, Privileged Identity Management, risky-user Conditional Access automation, and device-based authentication requirements.

 

The question, therefore, is not simply:

 

"Does the organization have MFA?"

 

A more complete assessment asks:

 

Which identities are protected, what authentication methods are permitted, how are privileged identities handled, what happens when Microsoft detects identity risk, and under what conditions is authentication permitted?

 

Those distinctions are difficult to capture through a simple security questionnaire.

Finding #5: Premium Microsoft Licensing Did Not Guarantee Security Configuration

All three banks had access to significant Microsoft security capabilities.

 

  • Bank A used a combination of Microsoft 365 E5 and Microsoft 365 Business Premium licensing.

  • Bank B predominantly used Microsoft 365 Business Premium.

  • Bank C predominantly used Microsoft 365 E3 combined with Microsoft Entra ID P2.

 

Yet substantial CIS control gaps remained in each environment.

 

Licensing determines which security capabilities an organization can use. It does not configure those capabilities.

 

This distinction is particularly important with products such as Microsoft 365 Business Premium, Microsoft 365 E3/E5, and Microsoft Entra ID P2, where organizations may already own security capabilities that require deliberate configuration, policy design, testing, and ongoing maintenance before they provide their intended protection.

Finding #6: Similar Organizations Can Have Very Different Security Gaps

The three assessments also demonstrate why Microsoft 365 security should not be reduced to a generic checklist.

For example, Bank A had no phishing-resistant MFA, no Privileged Identity Management, no automated risky-user Conditional Access response, and no requirement for authentication from a managed or compliant device.

 

Bank C had partially implemented each of those areas, but other gaps remained. External sender warnings were not configured, DMARC was not implemented, and several important identity and email controls remained only partially implemented.

 

Bank B fell somewhere between the two environments in several areas.

 

The appropriate remediation plan therefore depends on the organization's existing configuration, licensing, architecture, operational requirements, and risk tolerance.

What These Assessments Suggest

The most important lesson from these three engagements is not that the banks had done nothing to secure Microsoft 365.

It is almost the opposite.

Each institution had internal IT resources. Each had invested in Microsoft licensing. Each had implemented foundational security controls. Each had already addressed recognizable risks such as legacy authentication.

Yet a detailed assessment against the CIS Microsoft 365 Foundations Benchmark still identified substantial areas for additional hardening.

Across the three institutions:

  • 35% to 54% of benchmark controls were Not Implemented.

  • 35% to 65% of Redeemer Cyber's Top 20 prioritized controls were Not Implemented.

  • 31% to 45% of controls classified as Critical by Redeemer Cyber were Not Implemented.

 

This illustrates the difference between having Microsoft 365 security controls and systematically validating the configuration of the Microsoft 365 environment against an established security benchmark.

The Role of a Microsoft 365 Security Assessment

A Microsoft 365 security assessment should provide more than a vulnerability count or the pass/fail results of a common automated configuration scan.

 

Redeemer Cyber evaluates Microsoft 365 environments against the CIS Microsoft 365 Foundations Benchmark and examines areas including identity, authentication, Conditional Access, privileged access, Exchange Online, Microsoft Defender, SharePoint and OneDrive, Microsoft Teams, auditing, data protection, and other tenant-level security configurations.

 

The resulting findings are prioritized so organizations can distinguish between controls requiring immediate attention and lower-priority opportunities for continued hardening.

 

The objective is not necessarily to implement 100% of every benchmark recommendation.

 

Licensing limitations, business requirements, technical dependencies, operational impact, and organizational risk tolerance can all influence whether a particular recommendation is appropriate.

 

Instead, the goal is to understand the organization's current Microsoft 365 security posture, identify meaningful gaps, determine which risks should be addressed, and establish a defensible path toward a more secure tenant.

About This Analysis

This analysis is based on three anonymized Microsoft 365 security assessments performed for established community banking institutions in the United States. The engagements were delivered through Redeemer Cyber channel relationships.

Two assessments used version 7 of the CIS Microsoft 365 Foundations Benchmark, containing 180 controls, while one used version 6, containing 161 controls.

 

Organization sizes, asset values, user counts, locations, licensing quantities, and other identifying characteristics have been generalized or approximated to protect client confidentiality.

 

Assessment findings and percentages have been retained to preserve the integrity of the analysis.

 

The results represent these three assessed environments only. They should not be interpreted as a statistically representative study of community banks, the banking industry, or Microsoft 365 tenants generally.

Assess. Remediate. Maintain.

Microsoft 365 security is not determined solely by whether an organization owns premium licensing, has enabled MFA, or has an internal IT team.

The configuration beneath those investments matters.

 

A benchmark-based assessment provides organizations with an independent view of that configuration, identifies gaps that may otherwise remain unnoticed, and provides a prioritized roadmap for strengthening the environment.

 

For organizations that have already invested heavily in Microsoft 365 security, the question may no longer be whether security controls exist.

 

It may be whether those controls have been implemented as comprehensively as the organization believes.

How Does Your Microsoft 365 Environment Compare?

Redeemer Cyber's Microsoft 365 Security Assessment evaluates your environment against the latest CIS Microsoft 365 Foundations Benchmark, the Redeemer Cyber Foundations Benchmark, identifies security gaps, and provides a prioritized roadmap with supporting documentation and a remediation tracker.

 

Ready to benchmark your Microsoft 365 security posture? Contact Redeemer Cyber to discuss an assessment.

Contact us to request a Microsoft 365 Security Assessment today.

bottom of page