Your Microsoft 365 was set up by someone who has since left.
Often the person who set up Microsoft 365 has moved on, and nobody knows which settings were left open. Our fixed-fee Microsoft 365 security review looks at every setting, every sign-in and every personal phone that connects, and then we harden it. You end up with every setting closed, labelled and written down, on any plan from Business Premium to E5.
Nobody has checked your security against a standard.
If your security has never been measured against a standard, it's hard to know where you stand or what to fix first. Our ISO 27001-based cybersecurity review works through about 180 questions across some 20 control areas of ISO/IEC 27001. Each control is rated adequate, partial or inadequate, with the quick wins listed first, and you can run it once or on a schedule such as twice a year.
A vendor holds your customers' data.
More of your customers' data now sits with outside vendors, and it is hard to know how well each one protects it. We carry out vendor risk assessments, so you know who holds your data, what the risks are and what to ask of each vendor.
A client has sent you a security questionnaire.
Larger clients often send long security questionnaires before they sign or renew. We help you answer them accurately, so your answers stand up to scrutiny and match what you actually do.
A new system will collect personal information, such as fingerprints at the door.
Before a new system starts collecting personal information, you need to understand what you're taking on. We write the privacy impact assessment first, and any legal questions go to trusted privacy specialists. You end up with a clear record of what is kept and why, with the risks recorded and the right notices posted.
Something looks wrong, and nobody knows who to call.
When something looks wrong, the hardest part is often not knowing who to call. We act as your fractional CISO on retainer, working alongside whoever runs your day-to-day IT. When you call, someone answers, and the level of support is agreed in the retainer.
Where to start
We'd suggest starting with the Microsoft 365 security review. Write to us at [email protected] and we'll arrange it.
Questions
What is the first step?
The first step is usually a fixed-fee Microsoft 365 security review and hardening, for any plan from Business Premium to E5.
Is SigOct an MSP?
No. We handle security and governance, and we work alongside whoever runs your day-to-day IT.
What is the ISO 27001-based cybersecurity review?
It's a fixed-scope inspection of your security controls against ISO/IEC 27001. It covers about 180 questions across some 20 control areas, and each control is rated adequate, partial or inadequate, with the quick wins first. You can run it once or on a schedule, such as twice a year.
Do you give privacy law advice?
No. We carry out the privacy impact assessment, and legal analysis under PIPEDA or Alberta's PIPA goes to trusted privacy specialists.