Pass/Fail Isn't a Security Assessment
- Kyle Cira

- Jul 7
- 3 min read

Security scanning tools have become incredibly powerful.
Many leverage AI and automation to audit Microsoft 365 environments against hundreds of security controls in just minutes.
They're excellent at answering one question:
"Is this control configured exactly as expected?"
But security is about much more than checking boxes.
Not Every "Security Assessment" Is Created Equal
Unfortunately, the term "Security Assessment" is used very broadly in the cybersecurity industry.
Some providers primarily deliver the output of an automated compliance scanner. They run the tool, generate a pass/fail report, and present the results as a completed assessment—sometimes charging thousands of dollars for what is largely an automated process.
Automated scanning certainly has value. We use automation ourselves wherever it makes sense.
But automation should be the starting point, not the finished product.
At Redeemer Cyber, we believe a true Microsoft 365 Security Assessment requires expert analysis.
That means taking the time to:
Review controls that cannot be audited automatically
Evaluate partially implemented controls
Identify compensating controls
Consider business context and operational requirements
Provide practical, prioritized remediation guidance
Our goal isn't simply to tell you what failed.
It's to explain why it matters, how much it increases your risk, and what the best path forward looks like.
That's the difference between printing a report and delivering a professional security assessment.
Compliance vs. Security
Most automated tools evaluate a security control and return one of two outcomes:
✅ Pass
❌ Fail
If 100% of the control's requirements are met, the tool reports a Pass.
If even one requirement isn't met, the tool reports a Fail.
This binary approach works well for measuring compliance.
It does not necessarily measure security.
Security Exists in the Gray Areas
Real environments are rarely black and white.
Consider a security control that's:
80% implemented
Functionally accomplishing its objective
Missing one configuration recommendation
A compliance scanner reports:
❌ Fail
An experienced security assessor asks different questions:
Does the control still reduce risk?
Is the intent of the control being achieved?
What business requirements drove this implementation?
Is the remaining gap material or negligible?
These questions can't be answered by a scanner alone.
Compliance Is an Input to Risk—Not the Whole Picture
One misconception we frequently see is the assumption that compliance equals risk.
It doesn't.
Compliance is one input into determining risk.
Risk also depends on factors such as:
Business context
Asset value
Threat likelihood
Existing compensating controls
Potential operational impact
Organizational risk tolerance
A true security assessment considers all of these.
A Simple Example
Imagine two houses are on fire.
From a compliance perspective, both receive the same result:
❌ Critical
But from a risk perspective, they aren't equal.
House #1
A family's primary residence.
Everything they own is inside.
Their pets are inside.
The consequences are catastrophic.
House #2
A vacant investment property.
Nobody lives there.
No valuables are stored inside.
It's fully insured.
Both structures are burning.
Both represent serious incidents.
But the impact is dramatically different.
An automated tool sees identical conditions.
An experienced assessor sees context.
And context changes how risk should be understood and prioritized.
Why We Include "Partially Implemented"
At Redeemer Cyber, our Microsoft 365 Security Assessments don't stop at Pass or Fail.
We also use:
Partially Implemented
This allows us to recognize situations where:
The control substantially reduces risk
The intent of the control has largely been achieved
Minor improvements are still recommended
Our partially implemented findings include notes explaining:
What's in place
Considerations for improvement
That gives organizations a far more accurate picture of their security posture than a binary result ever could.
Tools Still Have an Important Place
None of this means compliance scanners aren't valuable.
They absolutely are.
They're excellent for:
Continuous monitoring
Detecting configuration drift
Identifying missing settings
Supporting compliance initiatives
But they shouldn't be mistaken for a comprehensive security assessment.
Security isn't simply about whether a setting is "On" or "Off."
It's about understanding how well your environment is actually protected.
Final Thoughts
Automation has transformed cybersecurity, and AI-powered compliance tools are becoming better every year.
But security is still about more than binary outcomes.
Organizations deserve assessments that consider context, intent, compensating controls, and real-world business risk—not just whether a checkbox is checked.
At Redeemer Cyber, we combine automation with expert analysis to provide Microsoft 365 Security Assessments that go beyond compliance and focus on what matters most: reducing real-world risk.
If you're relying solely on Pass/Fail reports, you may be missing the bigger picture.
Contact Redeemer Cyber today to gain a deeper understanding of your Microsoft 365 security posture.




Comments