A free check of your Microsoft 365. Every account. Then 30 minutes explaining what we found, in plain English.
Free, and no obligation.
Plenty of people who land here should close the tab. Better we say so now than waste an hour of both our lives.
These are the things business owners say to us before we start.
"Someone left last year and I honestly could not tell you whether their access was ever turned off."
"I heard about a business that paid an invoice into the wrong bank account. It was for eighty grand."
"A client sent us a security questionnaire and I had to guess at half the answers."
"We pay for IT support every month. I have no idea whether any of this is covered."
"Half my team is on their own laptops and phones. I have never thought about it until now."
"If something went wrong tomorrow I would not know where to start."
When your business email was set up, a long list of protections came switched off. Not broken. Just off, waiting for someone to turn them on. Microsoft leaves that to you, and most businesses never get to it, because it is nobody's job. Your IT support fixes what breaks. Nothing breaks when a protection is off, so nobody looks. Years go by.
A 25 person accounting firm in Sydney. They had IT support. They had never had a problem.
If one person's account had been broken into, the intruder could have set it to secretly copy every message out of the business. No warning. Nobody told. This is exactly how invoices end up paid into the wrong bank account.
Their accounts were never switched off. Same passwords as the day they walked out the door.
Devices nobody had touched in months, still able to reach company files.
Two of their three email addresses had nothing stopping it. A scammer could email their clients, as them, asking to be paid.
If that password had ever turned up in a leak, that was the whole front door.
The "quick favour, can you transfer this today" email would have landed like any other.
Nineteen problems in total. Every one of them a setting that had been sitting switched off since the day they started.
Same business, same team. Nothing bought, nothing replaced, nobody retrained.
There is no catch, but there is a reason, and you deserve it straight.
The checking part is automatic, so one more costs us almost nothing. What it does cost us is the half hour one of our people spends going through it with you. That is why we do ten of these a month rather than a hundred.
Out of those ten, a few will ask us to sort out what we found. That is where we make our money.
The rest take the report to whoever already looks after them and get it fixed without us. That is genuinely fine. We would rather these holes got closed than left open, and a business that trusts us this year tends to call us in a few years' time.
That is the whole thing. No pressure, and no decision you have to make on the call.
You are not spending money here, so the only thing you are risking is about forty minutes of your time. We would rather be straight about what you get for it.
If we find things, we will tell you plainly what they are, what they could cost you, and what we would suggest doing. Nothing happens after that unless you say so.
If we find you are in good shape, we will say that too, and you will have it in writing to show whoever asks. That is a perfectly good outcome and we are not going to invent problems to avoid it.
Either way, the report is yours to keep, and nothing goes any further unless you decide it should.
One account gets broken into. Someone reads quietly for a fortnight, waits for you to invoice a client, then emails that client with different bank details.
The invoice figure is an example, not a statistic. Put your own average invoice in and the answer does not change much.
One screen, about ten minutes. If your IT provider handles that side, forward it to them.
Runs quietly in the background. Nobody in your team will notice a thing.
You get the written report, then we spend 30 minutes going through what we found and what it means for you.
No. We look at your settings, not your messages. We are not opening your inbox, your documents or your files, and we could not tell you what is in any of them. You will see a list of exactly what we are looking at before you approve anything.
Not at all. Nothing changes, nothing gets switched off, nobody has to log in again. It runs in the background and your staff will not know it happened.
That is rather the point. You do not need to. We do the looking, then explain what we found the way we would explain it to a mate over coffee. If we use a word you do not know, we have done our job badly.
It should not be. Most businesses we do this for have an IT provider and we are not asking you to change that. Think of it as a second set of eyes. If they have it covered, you will have proof, and you can send them the report either way.
Because the checking part is automatic and costs us almost nothing. Some businesses read what we find and ask us to sort it out, which is where we make our money. Plenty take the report to whoever already looks after them, and that is completely fine by us.
We tell you what we would recommend doing about it, and what that would cost. Every business is different, so the price depends on how much is out of place. You will have the recommendation and the costing in front of you before anything happens, and nothing goes ahead unless you approve it. Saying no thanks and keeping the report is a perfectly good outcome too.
This is the one we hear most, and it is the one that costs people. Almost none of this is personal. It is automated, sweeping around looking for whoever left the door open. Being small does not hide you. It just means nobody has checked.
You switch off our access whenever you like, in a couple of clicks. It is your account and it stays entirely in your hands.
Ten minutes to set up, then a 30 minute call. The report is yours to keep.
Free, and no obligation.
P.S. If you scrolled straight to the bottom, here it is in four lines.
Your business email has a list of protections that came switched off, and nobody has ever checked which ones. We will look, for nothing, and send you a written report.
Then we spend thirty minutes explaining it to you without a single acronym.
The report is yours whatever you decide to do next. The only thing you lose by not doing it is knowing.