Christine Alifrangis
← Consulting Services

Security Health Assessment

Most security incidents do not require an exotic attacker. They require an ordinary weakness that nobody owned: an old account, incomplete MFA, an exposed administrator, a backup that was never tested or a control everyone assumed somebody else had configured.

Security fundamentals, examined in business context

The assessment focuses on the controls most likely to change your actual risk. I look at identity, Microsoft 365, privileged access, endpoint and account hygiene, backups, recovery and the operational processes around them. The point is not to produce fear; it is to find the gaps that are both plausible and fixable.

Identity

MFA enforcement, administrator boundaries, stale accounts, access lifecycle and the paths an attacker could use to escalate privileges.

Resilience

Backups, recovery assumptions, critical dependencies and whether the organization can actually restore operations after an incident.

Priorities

A risk-ranked remediation plan that distinguishes urgent exposure from worthwhile improvements and longer-term maturity work.

Useful security advice should be implementable

You should know what needs attention first, why it matters, who should own it and what a reasonable fix looks like. Where deeper specialist testing is appropriate, I’ll say so rather than pretending a broad assessment replaces penetration testing or a formal compliance engagement.