Do you know how secure your Microsoft 365 really is?
After seven working days you know where your company stands — in writing, without jargon. You get an answer for your insurer and clients, a plan for your IT provider and a presentation for your board. A personal handover, fixed price from €990.
Do any of these sound familiar?
What you hold after seven working days
Not a list of technology — answers to the questions people ask you.
The yardstick is CIS Benchmark Level 1, an internationally recognised baseline for Microsoft 365. The scan only reads and changes nothing. The rights to the report are entirely yours — share it with whoever you like.
Book a 30-min intro call →What it costs you not to know
The major client who asks for evidence will not wait until you are ready. The insurer asks questions whose unanswered version sets the premium — or, after an incident, the cover. And when something happens, recovery often fails not on the technology but because nobody knows which state was the right one.
The scan has a one-off price and includes a personal handover. The open questions cost nothing — until someone asks them.
Scope, timing and the free introductory call
The Nexus.365 Security Scan is a one-off read-only assessment against CIS Benchmark Level 1. After commissioning and read-only connection, the report is delivered in seven working days. The handover normally takes 60–90 minutes, longer if needed. Implementation is not included in the scan. It does not include ongoing attack detection, incident response or forensics.
The 30-minute introductory call is free. With the read-only connection in place, we can discuss initial findings. It does not replace the complete paid Security Scan.
The report provides a technical basis for decisions. It does not replace a formal audit or guarantee certification or full compliance.
Transparent, with nothing hidden
A fixed one-off price, set by your Microsoft 365 licence tier — not by small print. No follow-on costs, no subscription, no minimum term.
| Product | Licence tier | Price* | What is included |
|---|---|---|---|
| Nexus.365 Security Scan | Business Premium | from €990 one-off | Risk status, action plan with effort in days, management presentation, reporting call |
| Nexus.365 Security Scan | E3 / E5 / E7 | from €1,690 one-off | Same as Business Premium — with more features to review |
| Add-on: Azure Security & Cost | optional, only alongside the scan | €490 one-off | Azure security and cost review in addition to the scan |
* Plus VAT where applicable — for business clients outside Germany the place-of-supply rules apply. Fixed price, fixed end date, no follow-on commitment. Pricing follows your Microsoft licence, not the scope of the review: an E5 environment has more features that can be reviewed — and more that are paid for but switched off.
Request a quote directly
You know what you need? Enter your details and receive a binding quote by email. No purchase, no payment — nothing is ordered until you accept the quote. The scan starts after that.
What clients say about the work
Five voices from four companies. Excerpts from published feedback on working with Philipp Schmidt, translated from the German originals.
“Outstanding work as a Microsoft 365 consultant. We were particularly impressed by the support with TISAX, ISO 27001 and the security audit, and by the implementation of MFA, MAM and conditional access. The work has left a lasting positive mark on our company.”
“Excellent support implementing macOS with Microsoft Intune, and in hardening and de-risking our IT environment. Persistence on complex topics and a pragmatic approach made the difference.”
“As Microsoft 365 solution architect, instrumental in improving our IT infrastructure strategically and making it fit for the future. The comprehensive approach to security, governance and compliance stands out in particular. Clear recommendation.”
“I found Philipp to be a competent service provider who is very hard to unsettle. The main task was to bring Intune (iOS) up to standard. That worked really well.”
“Under Mr Schmidt’s leadership, we developed into a forward-looking cloud-first company. He successfully implemented Microsoft 365 and introduced MFA with YubiKeys and Conditional Access.”
Questions before you start
So nothing is left open before you commit.
What does the Nexus.365 Security Scan cost?
Pricing follows your Microsoft licence: from €990 for Business Premium, from €1,690 for E3, E5 or E7 — one-off, plus VAT where applicable. If you want Azure reviewed too, add the Security & Cost add-on for €490. Fixed price, fixed end date, no follow-on commitment.
What access do you need to our IT?
A read-only account — no administrator rights, no write access. The scan changes nothing and works with settings and metrics, not with your email or documents. Your tenant content stays in your environment. Assessment-data processing is described in our privacy notice. You or your IT provider receive the full list of read permissions in advance.
What does doing nothing cost me?
A single taken-over account, or one day of standstill, usually costs more than the scan. On top of that sits what never shows up on an invoice: a deferred audit, a client who will not wait for the evidence, an insurance premium that climbs without a documented position.
How does this fit with TISAX, ISO 27001, NIS2 and GDPR?
The report does not replace a certification, but it answers a large share of the questions asked along the way: the risk status shows on one page where you stand against the CIS Benchmark, ISO 27001 and NIS2. The management presentation comes with it, ready to give unchanged to your board or insurer.
Who is the scan for?
Any organisation running Microsoft 365 — one seat or a hundred thousand, wherever you are based. You need no technical knowledge: the risk status and the management presentation are written for leadership, the technical part for your IT provider.
After seven working days the report is on your desk.
If the situations above match your Microsoft 365 reality, the scan supplies the missing starting point: in writing, prioritised, in business language. You decide afterwards, at your own pace, what gets implemented.
Book a 30-min intro call →Not a first attempt on your environment.
The scan is a standardised procedure, not a project reinvented for every client — and it works the same whether you run one seat or a hundred thousand.
Expert
Microsoft certified: SC-100 Cybersecurity Architect Expert · SC-401 Information Security Administrator · Microsoft 365 Certified: Administrator Expert (MS-102) — and, should it ever be needed, professional indemnity cover through Markel Insurance SE for our work in your environment.