VSS - Virtual Support Services

    Zero Trust Security Assessment

    Understand where you are today. Define where you need to be. Build a roadmap to get there.

    Learn about our assessment methodology

    Security Assessment

    In today's rapidly evolving threat landscape, most organisations lack visibility into their true security posture. Without a structured assessment, critical gaps in identity, device, data, and network security remain hidden — creating exposure that attackers are designed to exploit.

    VSS's Zero Trust Readiness Assessment is a structured 2–3 day workshop that evaluates your organisation's security posture across all six Zero Trust pillars, using Microsoft Secure Score, Compliance Manager, and the Microsoft Cybersecurity Reference Architecture (MCRA) as benchmarks. The result is a prioritised remediation roadmap tailored to your risk profile, compliance obligations, and budget.

    Our assessment methodology is adapted from the CISA Zero Trust Maturity Model and the Microsoft Security Adoption Framework (SAF), providing a five-level maturity scale that benchmarks where you are today and defines a clear path forward.

    Comprehensive security posture assessment using industry-leading frameworks.

    Comprehensive security posture assessment using industry-leading frameworks.

    Why assess before you act?

    Organisations that invest in security without first understanding their baseline waste resources on low-impact controls while critical vulnerabilities persist. A structured assessment ensures every dollar is directed at the highest-impact, fastest-to-fix controls first.

    VSS always begins engagements with a gap assessment and risk-ranked remediation roadmap. We never start with the technically interesting — we start with what matters most to your business.

    Many organisations have already paid for security features they have not yet activated. Our licensing review often reveals significant untapped value in existing Microsoft 365 subscriptions.

    Assessment services include:

    Secure Score Baseline

    Establish and track your Microsoft Secure Score as the primary quantitative measure of security posture.

    Maturity Assessment

    Benchmark your organisation against the CISA Zero Trust Maturity Model across all six pillars.

    Compliance Gap Analysis

    Map your current controls to KDPA 2019, GDPR, ISO 27001, NIST CSF, and sector-specific regulations.

    Shadow IT Discovery

    Identify all unsanctioned SaaS applications in use via Defender for Cloud Apps.

    Remediation Roadmap

    Receive a prioritised 12-month implementation plan with actionable recommendations.

    Executive Briefing

    90-minute sponsor alignment session to align leadership on the Zero Trust business case.

    Zero Trust Readiness Assessment Workshop
    Assessment Service

    Zero Trust Readiness Assessment Workshop

    Begin your security transformation with a structured 2\u20133 day workshop. Receive a comprehensive readiness report with Secure Score baseline, gap analysis, and prioritised 12-month roadmap.

    Read More

    6 Pillars Assessed

    Identity, Devices, Applications, Data, Networks, and Security Operations.

    Secure Score Baseline

    Quantitative measure of your current security configuration.

    Compliance Mapping

    Gap analysis against KDPA 2019, GDPR, ISO 27001, and more.

    12-Month Roadmap

    Prioritised remediation plan with estimated timelines and costs.

    Zero Trust Readiness Assessment Workshop

    A structured 2\u20133 day engagement to baseline your security posture

    Comprehensive Security Posture Review

    The VSS Zero Trust Readiness Assessment is a structured workshop that evaluates your organisation's current security posture across all six Zero Trust pillars. Using Microsoft Secure Score, Compliance Manager, and the Microsoft Cybersecurity Reference Architecture (MCRA) as benchmarks, we deliver a prioritised remediation roadmap tailored to your risk profile, compliance requirements, and budget.

    2\u20133 Day WorkshopDelivered on-site or remotely

    Assessment Engagement Phases

    Structured delivery from scoping through to actionable roadmap

    Phase 0Discovery & Scoping
    Week 1–2

    VSS Activities

    Whiteboard session mapping current architecture (geography, cloud usage, threats, compliance). Identify business and technical drivers. Define project sponsor and stakeholder team.

    Customer Deliverables

    Current state architecture map, risk and gap register, agreed scope and success criteria

    Phase 1Assessment
    Weeks 2–4

    VSS Activities

    Microsoft Secure Score assessment. Compliance Manager regulatory gap analysis. MCRA-aligned architecture review across all six pillars. Privileged access audit. Shadow IT discovery via Defender for Cloud Apps.

    Customer Deliverables

    Zero Trust Readiness Report, Secure Score baseline, prioritised remediation roadmap

    Phase 2Roadmap & Recommendations
    Week 4

    VSS Activities

    Consolidate findings into a formal written report. Present prioritised remediation plan with estimated timelines, licensing requirements, and resource needs. Executive briefing.

    Customer Deliverables

    12-month implementation roadmap, licensing review, executive summary for board

    Assessment Deliverables

    What you receive from the Zero Trust Readiness Assessment

    Current state architecture map across all six Zero Trust pillars
    Microsoft Secure Score baseline with quarterly target recommendations
    Risk and gap register identifying critical vulnerabilities
    Regulatory gap analysis against applicable compliance frameworks
    Prioritised remediation roadmap with 12-month implementation plan
    Executive summary report for leadership and board presentation
    Licensing review identifying unused security features already paid for
    Sponsor alignment session with CEO/CIO/CISO briefing

    CISA Zero Trust Maturity Model

    Five-level maturity scale adapted from CISA and Microsoft SAF to benchmark customer progress

    Level 1

    Traditional

    No formal security baseline. Passwords only, no MDM, no SIEM, flat networks, open data sharing.

    Level 2

    Initial

    Partial MFA deployment, some MDM rollout, SSO for select apps, manual labelling, basic logging.

    Level 3

    Advanced

    MFA + SSO for all users, Conditional Access, all devices enrolled, labels deployed, ZTNA replacing VPN, Defender XDR live.

    Level 4

    Optimal

    PIM, risk-based Conditional Access, EDR live, CASB active, auto-labelling, micro-segmentation, Sentinel SIEM active.

    Level 5

    Adaptive

    Passwordless, AI-driven analytics, DevSecOps integrated, Insider Risk, automated policy enforcement, Security Copilot.

    Pillar-by-Pillar Maturity Assessment

    We assess your organisation across all six Zero Trust pillars against the maturity model

    PillarL1 TraditionalL2 InitialL3 AdvancedL4 OptimalL5 AdaptiveYear 1 Target
    Identity
    Passwords only; no MFAMFA enabled for some usersMFA + SSO for all; Conditional Access basicPIM, SSPR, risk-based CAPasswordless; AI-driven risk analyticsLevel 3–4
    Devices
    No MDM; no visibilityPartial MDM rolloutAll devices enrolled; compliance policiesCompliance gates for all access; EDR liveZero-touch autopilot; drift auto-remediationLevel 3
    Applications
    Per-app passwords; no SSOSSO for some appsAll apps in Entra; shadow IT visibleMCAS session controls; CASB activeAPI security; DevSecOps fully integratedLevel 3
    Data
    No classification; open sharingManual labels on some dataLabels deployed; basic DLP activeAuto-labelling; DLP across all M365Extended to SaaS and on-premises; Insider RiskLevel 3–4
    Networks
    Flat network; VPN onlyBasic segmentation; HTTPS enforcedZTNA replacing VPN; SWG deployedMicro-segmentation; OT/IoT isolatedAutomated policy enforcement; AI anomaly detectionLevel 3
    Security Operations
    No SIEM; reactive onlyBasic logging; some alertingDefender XDR live; playbooks documentedSentinel SIEM active; threat huntingSecurity Copilot; autonomous responseLevel 3

    Microsoft Secure Score Baseline

    The primary quantitative measure of your security posture

    What is Secure Score?

    Microsoft Secure Score is the primary quantitative measure of security posture across your Microsoft 365 and Azure environment. It evaluates your configuration against best-practice security controls and provides a percentage-based score with actionable improvement recommendations.

    VSS establishes your baseline Secure Score at the start of every assessment, defines quarterly target scores, and assigns ownership of remediation actions to ensure continuous improvement.

    Compliance Manager

    Microsoft Compliance Manager provides built-in assessment templates for major regulatory frameworks including ISO 27001, NIST CSF v2, GDPR, and PCI-DSS. It tracks your compliance posture, identifies gaps, and provides step-by-step remediation guidance.

    As part of the assessment, VSS maps your current controls to applicable regulatory frameworks and produces a regulatory gap analysis with prioritised remediation steps.

    Regulatory Compliance Mapping

    Zero Trust controls mapped to the regulatory frameworks most relevant to East African organisations

    Regulation / FrameworkJurisdictionVSS Zero Trust Controls
    Kenya Data Protection Act 2019KenyaData discovery and classification (Purview), DLP policies, data subject rights support, encryption, audit trails, breach notification readiness
    GDPREU / GlobalSensitivity labels with rights management, DLP policies, data residency controls, eDiscovery and audit, consent and subject rights management
    ISO/IEC 27001InternationalComprehensive security management via Compliance Manager with built-in ISO 27001 assessment across all six Zero Trust pillars
    NIST CSF v2InternationalFull alignment: GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER — mapped across all Zero Trust pillars
    PCI-DSS v4.0Payment IndustryNetwork segmentation, encryption, strong authentication (MFA/CA), access logging (Sentinel), vulnerability management
    SWIFT CSPFinancial SectorPrivileged access security (PIM, PAWs), endpoint hardening, anomaly detection (Sentinel UEBA), network segmentation

    Shadow IT Discovery

    Identifying unsanctioned applications in your environment

    Defender for Cloud Apps Discovery

    As part of the security assessment, VSS deploys Microsoft Defender for Cloud Apps to discover all unsanctioned SaaS applications in use across your organisation. Shadow IT is a critical risk vector \u2014 employees using personal Dropbox, Gmail, or unmanaged tools to share corporate data bypasses all security controls.

    Purview Data Discovery

    Microsoft Purview helps identify where sensitive data resides across your Microsoft 365 environment. The assessment identifies data classification gaps, excessive sharing permissions, and areas where data governance must be strengthened before AI adoption (Copilot for M365) can proceed safely.

    Recommended First Steps

    Begin your Zero Trust journey with these proven starting points

    01

    Zero Trust Readiness Assessment

    VSS conducts a 2–3 day workshop and produces a written readiness report with Secure Score baseline, gap analysis, and prioritised 12-month roadmap.

    02

    Sponsor Alignment Session

    A 90-minute executive briefing to align the CEO/CIO/CISO on the Zero Trust business case, regulatory obligations, and investment roadmap.

    03

    Identity & MFA Quick Win

    Deploy Microsoft Entra MFA and Conditional Access for all users within 30 days. This single control eliminates the majority of credential-based attack success.

    04

    Licensing Review

    VSS conducts a Microsoft 365 licensing review to identify whether customers have already paid for security features they have not yet activated.

    The VSS Zero Trust Promise

    Zero Trust is a journey, not a destination. Every customer starts somewhere \u2014 and every improvement matters. VSS's commitment is to meet customers where they are, prioritise ruthlessly based on real risk, deliver controls that work invisibly for good users, and build towards a continuously improving security posture that protects what matters most: your data, your people, and your business operations.

    Featured services and technologies

    Zero Trust Readiness Assessment

    Compliance Manager Assessment