Security Assessment
In today's rapidly evolving threat landscape, most organisations lack visibility into their true security posture. Without a structured assessment, critical gaps in identity, device, data, and network security remain hidden — creating exposure that attackers are designed to exploit.
VSS's Zero Trust Readiness Assessment is a structured 2–3 day workshop that evaluates your organisation's security posture across all six Zero Trust pillars, using Microsoft Secure Score, Compliance Manager, and the Microsoft Cybersecurity Reference Architecture (MCRA) as benchmarks. The result is a prioritised remediation roadmap tailored to your risk profile, compliance obligations, and budget.
Our assessment methodology is adapted from the CISA Zero Trust Maturity Model and the Microsoft Security Adoption Framework (SAF), providing a five-level maturity scale that benchmarks where you are today and defines a clear path forward.
Comprehensive security posture assessment using industry-leading frameworks.
Why assess before you act?
Organisations that invest in security without first understanding their baseline waste resources on low-impact controls while critical vulnerabilities persist. A structured assessment ensures every dollar is directed at the highest-impact, fastest-to-fix controls first.
VSS always begins engagements with a gap assessment and risk-ranked remediation roadmap. We never start with the technically interesting — we start with what matters most to your business.
Many organisations have already paid for security features they have not yet activated. Our licensing review often reveals significant untapped value in existing Microsoft 365 subscriptions.
Assessment services include:
Establish and track your Microsoft Secure Score as the primary quantitative measure of security posture.
Benchmark your organisation against the CISA Zero Trust Maturity Model across all six pillars.
Map your current controls to KDPA 2019, GDPR, ISO 27001, NIST CSF, and sector-specific regulations.
Identify all unsanctioned SaaS applications in use via Defender for Cloud Apps.
Receive a prioritised 12-month implementation plan with actionable recommendations.
90-minute sponsor alignment session to align leadership on the Zero Trust business case.
Zero Trust Readiness Assessment Workshop
Begin your security transformation with a structured 2\u20133 day workshop. Receive a comprehensive readiness report with Secure Score baseline, gap analysis, and prioritised 12-month roadmap.
Read More6 Pillars Assessed
Identity, Devices, Applications, Data, Networks, and Security Operations.
Secure Score Baseline
Quantitative measure of your current security configuration.
Compliance Mapping
Gap analysis against KDPA 2019, GDPR, ISO 27001, and more.
12-Month Roadmap
Prioritised remediation plan with estimated timelines and costs.
Zero Trust Readiness Assessment Workshop
A structured 2\u20133 day engagement to baseline your security posture
Comprehensive Security Posture Review
The VSS Zero Trust Readiness Assessment is a structured workshop that evaluates your organisation's current security posture across all six Zero Trust pillars. Using Microsoft Secure Score, Compliance Manager, and the Microsoft Cybersecurity Reference Architecture (MCRA) as benchmarks, we deliver a prioritised remediation roadmap tailored to your risk profile, compliance requirements, and budget.
Assessment Engagement Phases
Structured delivery from scoping through to actionable roadmap
VSS Activities
Whiteboard session mapping current architecture (geography, cloud usage, threats, compliance). Identify business and technical drivers. Define project sponsor and stakeholder team.
Customer Deliverables
Current state architecture map, risk and gap register, agreed scope and success criteria
VSS Activities
Microsoft Secure Score assessment. Compliance Manager regulatory gap analysis. MCRA-aligned architecture review across all six pillars. Privileged access audit. Shadow IT discovery via Defender for Cloud Apps.
Customer Deliverables
Zero Trust Readiness Report, Secure Score baseline, prioritised remediation roadmap
VSS Activities
Consolidate findings into a formal written report. Present prioritised remediation plan with estimated timelines, licensing requirements, and resource needs. Executive briefing.
Customer Deliverables
12-month implementation roadmap, licensing review, executive summary for board
Assessment Deliverables
What you receive from the Zero Trust Readiness Assessment
CISA Zero Trust Maturity Model
Five-level maturity scale adapted from CISA and Microsoft SAF to benchmark customer progress
Traditional
No formal security baseline. Passwords only, no MDM, no SIEM, flat networks, open data sharing.
Initial
Partial MFA deployment, some MDM rollout, SSO for select apps, manual labelling, basic logging.
Advanced
MFA + SSO for all users, Conditional Access, all devices enrolled, labels deployed, ZTNA replacing VPN, Defender XDR live.
Optimal
PIM, risk-based Conditional Access, EDR live, CASB active, auto-labelling, micro-segmentation, Sentinel SIEM active.
Adaptive
Passwordless, AI-driven analytics, DevSecOps integrated, Insider Risk, automated policy enforcement, Security Copilot.
Pillar-by-Pillar Maturity Assessment
We assess your organisation across all six Zero Trust pillars against the maturity model
| Pillar | L1 Traditional | L2 Initial | L3 Advanced | L4 Optimal | L5 Adaptive | Year 1 Target |
|---|---|---|---|---|---|---|
Identity | Passwords only; no MFA | MFA enabled for some users | MFA + SSO for all; Conditional Access basic | PIM, SSPR, risk-based CA | Passwordless; AI-driven risk analytics | Level 3–4 |
Devices | No MDM; no visibility | Partial MDM rollout | All devices enrolled; compliance policies | Compliance gates for all access; EDR live | Zero-touch autopilot; drift auto-remediation | Level 3 |
Applications | Per-app passwords; no SSO | SSO for some apps | All apps in Entra; shadow IT visible | MCAS session controls; CASB active | API security; DevSecOps fully integrated | Level 3 |
Data | No classification; open sharing | Manual labels on some data | Labels deployed; basic DLP active | Auto-labelling; DLP across all M365 | Extended to SaaS and on-premises; Insider Risk | Level 3–4 |
Networks | Flat network; VPN only | Basic segmentation; HTTPS enforced | ZTNA replacing VPN; SWG deployed | Micro-segmentation; OT/IoT isolated | Automated policy enforcement; AI anomaly detection | Level 3 |
Security Operations | No SIEM; reactive only | Basic logging; some alerting | Defender XDR live; playbooks documented | Sentinel SIEM active; threat hunting | Security Copilot; autonomous response | Level 3 |
Microsoft Secure Score Baseline
The primary quantitative measure of your security posture
What is Secure Score?
Microsoft Secure Score is the primary quantitative measure of security posture across your Microsoft 365 and Azure environment. It evaluates your configuration against best-practice security controls and provides a percentage-based score with actionable improvement recommendations.
VSS establishes your baseline Secure Score at the start of every assessment, defines quarterly target scores, and assigns ownership of remediation actions to ensure continuous improvement.
Compliance Manager
Microsoft Compliance Manager provides built-in assessment templates for major regulatory frameworks including ISO 27001, NIST CSF v2, GDPR, and PCI-DSS. It tracks your compliance posture, identifies gaps, and provides step-by-step remediation guidance.
As part of the assessment, VSS maps your current controls to applicable regulatory frameworks and produces a regulatory gap analysis with prioritised remediation steps.
Regulatory Compliance Mapping
Zero Trust controls mapped to the regulatory frameworks most relevant to East African organisations
| Regulation / Framework | Jurisdiction | VSS Zero Trust Controls |
|---|---|---|
| Kenya Data Protection Act 2019 | Kenya | Data discovery and classification (Purview), DLP policies, data subject rights support, encryption, audit trails, breach notification readiness |
| GDPR | EU / Global | Sensitivity labels with rights management, DLP policies, data residency controls, eDiscovery and audit, consent and subject rights management |
| ISO/IEC 27001 | International | Comprehensive security management via Compliance Manager with built-in ISO 27001 assessment across all six Zero Trust pillars |
| NIST CSF v2 | International | Full alignment: GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER — mapped across all Zero Trust pillars |
| PCI-DSS v4.0 | Payment Industry | Network segmentation, encryption, strong authentication (MFA/CA), access logging (Sentinel), vulnerability management |
| SWIFT CSP | Financial Sector | Privileged access security (PIM, PAWs), endpoint hardening, anomaly detection (Sentinel UEBA), network segmentation |
Shadow IT Discovery
Identifying unsanctioned applications in your environment
Defender for Cloud Apps Discovery
As part of the security assessment, VSS deploys Microsoft Defender for Cloud Apps to discover all unsanctioned SaaS applications in use across your organisation. Shadow IT is a critical risk vector \u2014 employees using personal Dropbox, Gmail, or unmanaged tools to share corporate data bypasses all security controls.
Purview Data Discovery
Microsoft Purview helps identify where sensitive data resides across your Microsoft 365 environment. The assessment identifies data classification gaps, excessive sharing permissions, and areas where data governance must be strengthened before AI adoption (Copilot for M365) can proceed safely.
Recommended First Steps
Begin your Zero Trust journey with these proven starting points
Zero Trust Readiness Assessment
VSS conducts a 2–3 day workshop and produces a written readiness report with Secure Score baseline, gap analysis, and prioritised 12-month roadmap.
Sponsor Alignment Session
A 90-minute executive briefing to align the CEO/CIO/CISO on the Zero Trust business case, regulatory obligations, and investment roadmap.
Identity & MFA Quick Win
Deploy Microsoft Entra MFA and Conditional Access for all users within 30 days. This single control eliminates the majority of credential-based attack success.
Licensing Review
VSS conducts a Microsoft 365 licensing review to identify whether customers have already paid for security features they have not yet activated.
The VSS Zero Trust Promise
Zero Trust is a journey, not a destination. Every customer starts somewhere \u2014 and every improvement matters. VSS's commitment is to meet customers where they are, prioritise ruthlessly based on real risk, deliver controls that work invisibly for good users, and build towards a continuously improving security posture that protects what matters most: your data, your people, and your business operations.
