Microsoft 365 is secure enough out of the box to pass a sales demo, and not quite secure enough for a real company. Five settings take an afternoon and remove most of the risk.
1. Multi-factor authentication for everyone — including the director
Password-only mailboxes are the single most common way small companies get compromised. Turn MFA on for every account, not just the technical ones. The usual objection is that it is inconvenient; the usual alternative is explaining to clients why invoices went out from your address with someone else's bank details.
2. Block or review forwarding rules
The classic attack: someone gets into a mailbox, creates a quiet rule that forwards everything to an outside address, and waits for an invoice to appear. Disable automatic external forwarding, and check existing rules — this takes minutes and is rarely done.
3. Check who can send as whom
Shared mailboxes such as info@ or accounts@ often accumulate permissions over the years. People leave; the access stays. Review the list twice a year.
4. Turn on audit logging before you need it
If an account is compromised, the first question is what was accessed and when. Without logging, nobody can answer it. It is free and off by default in some plans.
5. Decide what happens on day one and on the last day
Have a written routine for a new starter and a leaver: accounts, licences, mailbox delegation, device access. Most leaks happen in the gap between someone leaving and their access being removed.
What we do not do
We are not compliance consultants. We configure the platform, keep the accounts and devices in order and explain plainly what each setting does; responsibility for your data and processes stays with you. That boundary is deliberate — it is why our prices stay flat.