---
title: Datatechs - Security Audit
description: Independent Microsoft 365 security audits benchmarked against CIS and Cyber Essentials. Clear findings, prioritised remediation, fixed price.
image: https://www.datatechs.co.uk/hubfs/raw_assets/public/datatechs-theme/images/Datatech_OG.png
---

[Skip to content](https://www.datatechs.co.uk/audit#main-content)

[![Datatechs home](https://www.datatechs.co.uk/hs-fs/hubfs/Datatech%20Consulting%20Limited.png?width=2130&height=676&name=Datatech%20Consulting%20Limited.png "Datatechs home")](https://www.datatechs.co.uk?hsLang=en-gb) 

[![](https://www.datatechs.co.uk/hubfs/Datatech%20Consulting%20Limited%20-%20INVERT.png)](https://www.datatechs.co.uk/?hsLang=en-gb)

[Home](https://www.datatechs.co.uk/?hsLang=en-gb)

[Services](https://www.datatechs.co.uk/services?hsLang=en-gb)

[M365 Security Audit](https://www.datatechs.co.uk/audit?hsLang=en-gb) [Professional Services and Consultancy](https://www.datatechs.co.uk/services/professional-services?hsLang=en-gb) [IT Helpdesk and Support](https://www.datatechs.co.uk/services/it-helpdesk?hsLang=en-gb) [Managed Compliance](https://www.datatechs.co.uk/services/managed-compliance?hsLang=en-gb) [Power Platform](https://www.datatechs.co.uk/services/power-platform?hsLang=en-gb) [Azure and Cloud Infrastructure](https://www.datatechs.co.uk/services/azure-cloud-infrastructure?hsLang=en-gb)

[View all services →](https://www.datatechs.co.uk/services?hsLang=en-gb)

[Security Audit](https://www.datatechs.co.uk/audit?hsLang=en-gb)

[CIS M365 Benchmark](https://www.datatechs.co.uk/audit/cis-m365?hsLang=en-gb) [CIS Intune Benchmark](https://www.datatechs.co.uk/audit/cis-intune?hsLang=en-gb) [Cyber Essentials](https://www.datatechs.co.uk/audit/cyber-essentials?hsLang=en-gb)

[View the full audit →](https://www.datatechs.co.uk/audit?hsLang=en-gb)

[MSP Partners](https://www.datatechs.co.uk/msp-partners?hsLang=en-gb)

Resources

Free Downloads

[M365 Security Essentials Checklist](https://www.datatechs.co.uk/resources/m365-security-essentials?hsLang=en-gb) [Intune Security Essentials Checklist](https://www.datatechs.co.uk/resources/intune-security-essentials?hsLang=en-gb)

[About](https://www.datatechs.co.uk/about?hsLang=en-gb) [Blog](https://www.datatechs.co.uk/blog?hsLang=en-gb) 

[Contact Us](https://www.datatechs.co.uk/contact?hsLang=en-gb)

[Home](https://www.datatechs.co.uk/?hsLang=en-gb) [Services](https://www.datatechs.co.uk/services?hsLang=en-gb)

[M365 Security Audit](https://www.datatechs.co.uk/audit?hsLang=en-gb) [Professional Services and Consultancy](https://www.datatechs.co.uk/services/professional-services?hsLang=en-gb) [IT Helpdesk and Support](https://www.datatechs.co.uk/services/it-helpdesk?hsLang=en-gb) [Managed Compliance](https://www.datatechs.co.uk/services/managed-compliance?hsLang=en-gb) [Power Platform](https://www.datatechs.co.uk/services/power-platform?hsLang=en-gb) [Azure and Cloud Infrastructure](https://www.datatechs.co.uk/services/azure-cloud-infrastructure?hsLang=en-gb) 

[Security Audit](https://www.datatechs.co.uk/audit?hsLang=en-gb)

[CIS M365 Benchmark](https://www.datatechs.co.uk/audit/cis-m365?hsLang=en-gb) [CIS Intune Benchmark](https://www.datatechs.co.uk/audit/cis-intune?hsLang=en-gb) [Cyber Essentials](https://www.datatechs.co.uk/audit/cyber-essentials?hsLang=en-gb) 

[MSP Partners](https://www.datatechs.co.uk/msp-partners?hsLang=en-gb) Resources

[M365 Security Essentials Checklist](https://www.datatechs.co.uk/resources/m365-security-essentials?hsLang=en-gb) [Intune Security Essentials Checklist](https://www.datatechs.co.uk/resources/intune-security-essentials?hsLang=en-gb) 

[About](https://www.datatechs.co.uk/about?hsLang=en-gb) [Blog](https://www.datatechs.co.uk/blog?hsLang=en-gb) [Contact Us](https://www.datatechs.co.uk/contact?hsLang=en-gb)

SECURITY AUDITS

# Not sure which security audit you need?

Tell us what you need to achieve and we will point you towards the right assessment, the appropriate level and what it will help you prove.

[Help me choose](https://www.datatechs.co.uk/audit#choose) [Compare all audits](https://www.datatechs.co.uk/audit#compare)

Independent guidance. Fixed scope. Fixed fee. A clear report you can act on.

FIND YOUR AUDIT

## Two or three questions. One clear recommendation.

You do not need to know what any of the frameworks are called. Answer in plain English and we will tell you where to start and why.

Question 1 of 3

← Back

Start again

What has prompted you to look for an audit?

This tells us which part of your organisation the assessment needs to cover.

Meet a certification or contractual requirement A customer, insurer, tender or regulator has asked for evidence of your security controls. Check Microsoft 365 security You want to know whether accounts, email, files and Microsoft 365 services are configured securely. Check company devices You want to know whether laptops and other managed Windows devices are properly secured. Review everything relevant You are unsure where the risk sits, or believe more than one area needs reviewing. 

What evidence have you been asked to provide?

Requirements are worded in different ways. The wording usually points at one particular assessment.

Cyber Essentials You need the verified baseline certification. Cyber Essentials Plus You need the controls to be independently tested. The requirement mentions Microsoft 365 or cloud security The requesting organisation expects evidence about the security of your Microsoft 365 environment. The requirement mentions managed devices or endpoint security The requesting organisation expects evidence about laptops, desktops or device-management controls. I have been given a requirement, but I am not sure what it means Send us the wording and we will work out which assessment it is actually asking for. 

How much assurance do you need?

Benchmarks come at two depths. Most organisations start at the first.

A strong practical baseline Suitable for most small and medium-sized businesses wanting to address common Microsoft 365 security risks. Additional security depth Suitable when contractual, regulatory or risk requirements justify stricter controls. I am not sure We will confirm the appropriate benchmark level with you. 

How much assurance do you need?

Benchmarks come at two depths. Most organisations start at the first.

A strong practical baseline Suitable for most small and medium-sized businesses wanting consistent security across managed devices. Additional security depth Suitable when contractual, regulatory or risk requirements justify stricter device controls. I am not sure We will confirm the appropriate benchmark level with you. 

Which areas may need reviewing?

Choose as many as apply. More than one assessment may be sensible, and we will say so rather than sell you all three.

Microsoft 365 accounts, email and files Identities, mailboxes, file sharing and collaboration. Intune-managed Windows devices Laptops and desktops managed through Microsoft Intune. Cyber Essentials readiness Preparing for the certification, or checking you would pass. I am not sure what should be in scope We will help work out what is worth assessing. 

What is driving the level you need?

This is what usually decides how deep the assessment should go.

General security improvement You want a sensible baseline and a prioritised plan of what to address. A customer, tender or insurer Another organisation expects evidence of specific security controls. A regulatory or compliance requirement The audit needs to support a formal governance or assurance need. Higher-risk or sensitive operations Your risk profile may justify stronger, deeper controls. I am not sure We will confirm the appropriate level with you.

Continue

Choose at least one option to continue.

Recommended starting point

#### Why this fits

#### What it helps you understand or prove

#### What you receive

- A clear view of where you currently stand
- Findings ranked by importance
- A practical plan showing what to address first
- A walkthrough with a senior consultant

[Help me choose](https://www.datatechs.co.uk/contact?hsLang=en-gb) [View full audit details](https://www.datatechs.co.uk/audit#compare)

Ask us to confirm this recommendation. Nothing is sent until you follow the link.

COMPARE THE AUDITS

## Prefer to compare the options?

Each audit answers a different question. Start with the outcome you need rather than the framework name.

MICROSOFT 365

### Protect your accounts, email and business data.

CIS Microsoft 365 Foundations Benchmark Audit

Best when

Microsoft 365 is where your identities, email, files and collaboration services live.

Available levels

- Level 1: a strong practical baseline for most SMEs
- Level 2: additional defence in depth for higher-risk or regulated environments

Outcome

Understand which Microsoft 365 settings are secure, which require attention and what to fix first.

See what we check

- Entra ID identity and administrative access
- Conditional Access: the rules deciding who can sign in, from where and on what device
- Exchange Online
- SharePoint and OneDrive
- Microsoft Teams
- Application consent and OAuth: what third-party apps are allowed to do with your data
- Audit and data-protection settings

[Explore the M365 audit →](https://www.datatechs.co.uk/audit/cis-m365?hsLang=en-gb)

MICROSOFT INTUNE

### Check whether company devices are properly secured.

CIS Microsoft Intune Benchmark Audit

Best when

You use Intune to manage Windows devices, security policies, compliance and access.

Available levels

- Level 1: a practical managed-device security baseline
- Level 2: stricter settings for higher-risk or controlled environments

Outcome

Understand whether device policies are consistently protecting company devices and data.

See what we check

- Device enrolment
- Compliance policies
- Security baselines
- Configuration profiles
- Endpoint protection
- Microsoft Defender
- Firewall and disk encryption
- Update policies

[Explore the Intune audit →](https://www.datatechs.co.uk/audit/cis-intune?hsLang=en-gb)

CYBER ESSENTIALS

### Meet a recognised security certification requirement.

Cyber Essentials and Cyber Essentials Plus

Best when

A customer, insurer, tender or regulator expects recognised evidence of core security controls.

Available levels

- Cyber Essentials: verified baseline certification
- Cyber Essentials Plus: the same requirements with independent technical testing

Outcome

Understand whether the organisation is ready for the required certification and what must be addressed first.

See what we check

- Firewalls and internet gateways
- Secure configuration
- Security updates
- User access control
- Malware protection
- Devices, software and cloud services in scope
- Evidence preparation

[Explore Cyber Essentials →](https://www.datatechs.co.uk/audit/cyber-essentials?hsLang=en-gb)

## Security audit terms in plain English

Only if you want them. The selector and the comparison above work without any of this.

CIS benchmark

A recognised set of recommended security settings used to assess how securely a Microsoft environment is configured.

Level 1

A practical baseline designed to reduce common risks while minimising disruption.

Level 2

Additional defence-in-depth recommendations for organisations with greater security or compliance requirements.

Intune

Microsoft's service for managing and securing company devices.

Cyber Essentials

A UK certification demonstrating that fundamental technical security controls are in place.

Cyber Essentials Plus

The same requirements as Cyber Essentials, with independent technical testing to verify the controls.

CIS ASSESSMENT LEVELS

## Level 2 includes everything in Level 1.

The levels are cumulative, not alternatives. Choosing Level 2 means the whole Level 1 baseline as well, with stricter controls layered on top.

ADDED AT LEVEL 2

### Additional defence in depth

Stricter recommendations that provide additional protection but may require more testing, planning and operational change.

THE BASELINE, BEST STARTING POINT FOR MOST SMEs

### Strong practical baseline

Practical recommendations that reduce common risks while minimising disruption to normal business operations.

Level 2

Level 1

Level 2 is not automatically the right choice for every organisation. Datatechs will help balance security requirements against operational impact.

HOW THE AUDIT WORKS

## Three stages, and you decide at every one.

Nothing is committed until the scope and the fee are agreed in writing.

1. 01
   
   STEP 01 · UNDERSTAND
   
   ### Work out what you actually need
   
   Discovery call

   We understand what has prompted the audit and what evidence or assurance you need.
   
     - –You are not expected to know the frameworks
     - –A technical consultant, not a salesperson
     - –No obligation of any kind

   YOUR LIKELY AUDIT PATH

     - Microsoft 365
     - Company devices
     - Certification
   
   One recommended audit
2. 02
   
   STEP 02 · AGREE
   
   ### Fix the scope and the fee in writing
   
   Scope agreed

   We confirm the assessment, level, systems in scope and expected deliverables.
   
     - –Fixed fee, agreed before work starts
     - –Systems in scope named explicitly
     - –Deliverables listed in writing

   WRITTEN SCOPE AND FIXED FEE

     - Systems in scope, named
     - Level agreed in writing
     - Deliverables listed
   
   FeeFixed
3. 03
   
   STEP 03 · ASSESS
   
   ### Get findings you can act on
   
   Assessment and report

   A senior consultant completes the assessment, ranks the findings and walks you through the results.
   
     - –The consultant you met does the work
     - –Findings ranked by importance
     - –Remediation optional and scoped separately

   FINDINGS REPORT AND PLAN

     1. HighestFix first
     2. ThenPlan next
     3. LowerMonitor

WHAT EVERY AUDIT INCLUDES

## A clear report, and a plan you can act on.

Findings report

Executive summary

Critical

High

Evidence

Remediation plan

### Executive clarity

- A concise summary of the overall security position
- Clear priorities for senior stakeholders

### Technical evidence

- Every applicable control reviewed
- Supporting evidence and technical findings

### Risk prioritisation

- Findings categorised by severity
- Confirmed gaps separated from items requiring review

### Action plan

- Prioritised remediation recommendations
- Findings walkthrough with a senior consultant

- Senior consultant throughout
- Fixed fee agreed upfront
- Report belongs to you
- Remediation optional, scoped separately

WHO IT IS FOR

## You may need an audit if…

Any one of these on its own is reason enough to have the conversation.

- ### You have never had an independent security review
  
  Nobody outside the team has checked how your Microsoft environment is set up.
- ### A customer, insurer or regulator needs evidence
  
  Someone wants your security position shown, not described.
- ### Your Microsoft environment has recently changed
  
  A migration, merger, growth or new device rollout leaves gaps that daily admin will not surface.
- ### You are preparing for Cyber Essentials
  
  You need to know whether you would pass, and what to fix if not.

PRICING

## One agreed scope. One fixed fee.

The fee covers the assessment, findings report, remediation plan and walkthrough. Any remediation work is optional and quoted separately.

[Help me choose](https://www.datatechs.co.uk/audit#choose)

WHAT HAPPENS NEXT

## Where the audit can lead, if you want it to.

Neither service is included in the audit, and neither is assumed. Plenty of clients take the report and act on it with their own team.

1. The auditAudit findingsA prioritised list of what to address.
2. OptionalProfessional ServicesHands-on help to address selected audit findings.
   
   [View Professional Services →](https://www.datatechs.co.uk/services/professional-services?hsLang=en-gb)
3. OptionalManaged ComplianceOngoing support to maintain the required security and compliance position.
   
   [View Managed Compliance →](https://www.datatechs.co.uk/services/managed-compliance?hsLang=en-gb)

FAQ

## Common questions.

Which audit should we start with?

Start with the environment or outcome causing the greatest concern. Choose the M365 audit for tenant configuration and identity controls, the Intune audit for managed-device security, or Cyber Essentials when certification readiness is the priority. We can confirm the right scope during the discovery call.

What is the difference between CIS Level 1 and Level 2?

Level 1 provides a practical security baseline suitable for many organisations. Level 2 introduces additional defence-in-depth recommendations for environments with higher security or compliance requirements and may require more operational planning.

Can we assess both Microsoft 365 and Intune?

Yes. The scopes can be combined where both the tenant and managed-device configuration need to be reviewed. The scope, deliverables and fixed fee will be agreed before work begins.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is based on a verified self-assessment of the required technical controls. Cyber Essentials Plus covers the same requirements but adds an independent technical assessment to verify that the controls are working effectively.

Will the audit make changes to our environment?

No. The audit is an assessment and evidence-gathering engagement. No configuration changes should be made unless remediation work is separately scoped and authorised.

What do we receive at the end?

You receive a written findings report, severity-ranked risks, supporting evidence, a prioritised remediation plan and a call with a senior consultant to walk through the results.

## Still unsure? That is exactly what the discovery call is for.

Tell us what has prompted the audit and we will help confirm the right assessment, the appropriate level and the next step.

[Help me choose](https://www.datatechs.co.uk/audit#choose)

You will speak with a technical consultant. No obligation until the scope has been agreed.

[Book a discovery call](https://www.datatechs.co.uk/book-a-call?hsLang=en-gb) [View services](https://www.datatechs.co.uk/services?hsLang=en-gb)

[![Datatechs](https://www.datatechs.co.uk/hs-fs/hubfs/Datatech%20Consulting%20Limited%20-%20INVERT.png?height=56&name=Datatech%20Consulting%20Limited%20-%20INVERT.png)](https://www.datatechs.co.uk/?hsLang=en-gb)

Microsoft 365 security and compliance for organisations and MSPs.

Services

- [M365 Security Audit](https://www.datatechs.co.uk/audit?hsLang=en-gb)
- [Professional Services](https://www.datatechs.co.uk/services/professional-services?hsLang=en-gb)
- [IT Helpdesk and Support](https://www.datatechs.co.uk/services/it-helpdesk?hsLang=en-gb)
- [Managed Compliance](https://www.datatechs.co.uk/services/managed-compliance?hsLang=en-gb)
- [Power Platform](https://www.datatechs.co.uk/services/power-platform?hsLang=en-gb)
- [Azure and Cloud Infrastructure](https://www.datatechs.co.uk/services/azure-cloud-infrastructure?hsLang=en-gb)

Resources

- [Blog](https://www.datatechs.co.uk/blog?hsLang=en-gb)
- [M365 Security Checklist](https://www.datatechs.co.uk/resources/m365-security-essentials?hsLang=en-gb)

Company

- [About](https://www.datatechs.co.uk/about?hsLang=en-gb)
- [MSP Partners](https://www.datatechs.co.uk/msp-partners?hsLang=en-gb)
- [Contact](https://www.datatechs.co.uk/contact?hsLang=en-gb)
- [Book a call](https://www.datatechs.co.uk/book-a-call?hsLang=en-gb)

Contact

- [hello@datatechs.co.uk](mailto:hello@datatechs.co.uk)
- United Kingdom

© 2026 Datatechs Consulting Limited. Registered in England and Wales, company number 16868376. Registered office: Belmont Suite, Paragon Business Park, Chorley New Road, Horwich, Bolton, BL6 6HG.

[Privacy Policy](https://www.datatechs.co.uk/privacy-policy?hsLang=en-gb) [Terms](https://www.datatechs.co.uk/terms?hsLang=en-gb)