In the recent Microsoft Digital Defense Report we learnt how the last year has brought unprecedented change to both the physical and digital world. This means that defending against cybercriminals continues to be complex, ever evolving, and a never-ending challenge for organisations. As we continue to work in a hybrid or remote environment, we all need to ensure we protect our data, networks, infrastructure, and endpoints.
Knowing your strengths and weaknesses is key to understanding your security posture. You need to know where to invest your time and resources with a well-informed security strategy.
As we talk with customers around the UK the trends are clear. With the complexity of an evolving landscape, how do you prioritise your people and resources? How do you stay ahead of new threats? How do you inform key stakeholders of where the risks are? And how do you stack up against other organisations?
Find your score
To address your security posture, Microsoft Secure Score and Azure Secure Score are integrated free tools that will help you as a security administrator or leader to strengthen your security strategy and mitigate risks. They assess your posture against a baseline created from our unique global perspective. We gain this perspective from analysing 8 trillion signals per day and with our thousands of security experts working across Microsoft.
Both scores provide you with an Enterprise-wide view of prioritised recommendations. This helps you remediate your risks and improve your score. Each recommendation shows the impact on security, plus the impact on those users related to the change. This helps you to plan and manage changes effectively.
“Our previous security posture reporting was not as quantifiable as Microsoft Secure Score. It’s given me a lot more insights into where we’re at and it does so without oversimplification. When I share it with other executives, it’s very clear. They can see what our posture is like and where we’ve got areas of improvement. I’ve even used it to secure additional budget.”
– Director of technology and security, professional services.
Microsoft Secure Score and Azure Secure Score allows you to:
- Assess your security posture across identity, devices, information, apps, and infrastructure. Benchmark your organisation’s status over time and compare it to other organisations.
- Identify areas to improve and create a plan. Evaluate each recommendation using the intelligence and guidance provided to determine which areas to prioritise.
- Report improvements to stakeholders and make the case for change. Use reports to track and maintain progress, identify regressions, and report back to you to stakeholders. This provides clear evidence of impact and helps you make the business case for the changes to your security strategy.
Strengthen your Microsoft 365 security
Microsoft Secure Score assesses your Microsoft 365 tenant and recommends configuration changes to improve your posture. You can assess your organisation’s entire digital estate from a centralised dashboard in the Microsoft 365 Security Center. You can monitor and work on the security of Microsoft 365 identities, apps and devices.
It can help you:
- Report on the current state of your organisation’s security posture.
- Drive posture improvements into production. Improve your security posture by providing discoverability, visibility, guidance, and control.
- Use integrated workflow capabilities to help determine potential user impact and the procedures necessary to implement each recommendation in your environment.
- Compare with benchmarks and establish key performance indicators (KPIs).
You can view metrics, and trends and compare your score with similar organisations. The Microsoft Secure Score integrates with other Microsoft products. The score can also reflect when you’ve used a third-party solution to address recommended actions. You can then use these metrics to clearly demonstrate the progress you’re making to better secure your environment.
Assess your cloud infrastructure with Azure Secure Score
With the Azure Secure Score, you can assess your Azure infrastructure and get recommendations on configuration changes or further protection. You can find the Azure Secure Score in the Azure Security Center. It continually assesses your resources, subscriptions, and organisation for security issues. It then aggregates all the findings into a single score so that you can immediately understand your current security situation.
You can then go in-depth on the recommendations page to view the outstanding actions. Recommendations are grouped into security controls. Each control is a logical group of related security recommendations and reflects your vulnerable attack surfaces. Your score only improves when you remediate all the recommendations for a single resource within a control. Note that only built-in Azure Security recommendations affect your Azure Secure Score.
Improve your remote security posture
With a remote or hybrid workforce, security is high on an organisation’s list. As we all shifted to a distributed workforce, the security perimeter changed. This was echoed in security leader’s concerns, as they worried about ensuring employees could easily and securely access their work.
Microsoft Secure Score and Azure Secure Score make it easy to improve your posture across a set of controls and solutions such as multi-factor authentication, manage devices and enforce conditional access to ensure you can keep your distributed workforce safe.
When you add these scores to your regular reporting and Security KPIs, you get measurable data. This helps you to clearly demonstrate the progress you’re making to better secure your environment. That way, you can ensure no matter where employees are working from, they are secure.
Find out more
Speak to your Partner or your Microsoft Customer Success Account Manager about a score assessment.
About the author
Mark leads the Cyber Security Product Marketing team at Microsoft, focussing on the go-to-market strategy for Cyber Security, Compliance and Identity. He is also the Accessibility Programme Lead for the UK. Mark is passionate about building an environment in which people want to achieve their best. He has developed and enabled his team to empower the UK workplace to rethink productivity, streamline business processes and protect their business.