B BROCENT

The Free Scan That Found Twenty Gaps: A Hong Kong Nonprofit's Microsoft 365 Security Audit

A composite scenario from Hong Kong: a thirty-person nonprofit assumes Microsoft 365 is secure out of the box, and a free Quick Security Check surfaces about twenty findings in an afternoon — none of them Microsoft's fault, all of them settings nobody had ever reviewed. What the free check covers, what it honestly does not, and where continuous management takes over.

A small team gathered around laptops in a bright office, discussing findings together, representing a Hong Kong nonprofit reviewing the results of a free Microsoft 365 security check
In short: A Hong Kong nonprofit assumed Microsoft 365 was secure out of the box because "Microsoft handles that." A free Quick Security Check — a Secure Score review, a ScubaGear baseline and a one-hour walkthrough — surfaced around twenty findings in an afternoon. None of them were Microsoft's fault. All of them were settings nobody had ever looked at.

The industry: running a whole organisation on a tenant nobody has ever reviewed

Hong Kong's nonprofits, charities and professional associations run on Microsoft 365 in much the same way small businesses do, with one difference that matters: there is usually even less IT capacity behind it.

A twenty-to-forty-person association typically has an operations manager who owns "IT" alongside membership administration, event logistics, the website and the finance system. There is no IT department, and often no external IT provider on any kind of retainer — just someone who set up the tenant years ago, possibly a volunteer, possibly a board member's contact, possibly a staff member who has since left.

What that tenant holds is not trivial. Member and donor records, sometimes going back decades. Beneficiary information, which for a social-service organisation can be about as sensitive as data gets. Grant applications and funder correspondence. Payroll and HR files. Board papers. Photographs and consent forms. Bank details for suppliers and for the organisation itself. And because associations run on committees and rotating volunteers, that material has been shared, re-shared and delegated across a lot of accounts over a lot of years.

Then there is the assumption that quietly underlies all of it: *Microsoft is a large and serious company, we are paying them, and therefore this is handled.*

Half of that is right. Microsoft does run the platform, and runs it well — the datacentres, the patching of the service itself, the resilience. But how your tenant is configured is your side of the line, and it is configured however it was configured on day one, plus whatever anyone has changed since. Nobody at Microsoft is reviewing your admin roles or your sharing defaults. That gap between "we use Microsoft 365" and "our Microsoft 365 tenant is configured securely" is the entire subject of this article.

The scenario: twenty findings in under an hour

Here is a composite picture, drawn from how organisations of this size actually operate rather than from any one named client.

A Hong Kong nonprofit with about thirty staff has been on Microsoft 365 for six years. It was set up by a consultant who did a competent job of migrating the mailboxes and then, quite reasonably, finished the engagement. Since then the organisation has grown, run four or five major programmes, taken on and released a stream of interns and project staff, and changed executive directors once.

The operations manager takes up an offer of a free security check — mostly, she will admit later, because it was free and did not require a procurement process. She grants read-only access, which takes about fifteen minutes, and an hour-long walkthrough is scheduled for the following week.

The report comes back with roughly twenty findings. Not one of them is exotic. They are, in aggregate, a portrait of six years of ordinary organisational drift:

Multi-factor authentication is enabled for some accounts but not enforced for all of them, and the accounts without it include two that have administrative rights. There are five global administrators in a thirty-person organisation, three of whom are people who were given the role for a specific one-off task years ago. A shared mailbox has sign-in enabled and a password nobody has rotated. Several SharePoint sites and dozens of individual files are shared via "anyone with the link" links that never expire, created for a funder review in 2023. Guest accounts from a partner organisation are still active two programmes later. Legacy authentication protocols that bypass modern sign-in controls are still permitted. There is no conditional-access policy of any kind. Mailbox auditing is on by default but nobody has ever looked at it, and no alert would reach a human if something unusual happened. A former staff member's account was converted to a shared mailbox rather than being properly de-licensed, and it still has permissions on two team sites.

The operations manager's reaction is the common one, and it has two parts. The first is alarm. The second, and more useful, is relief — because every one of these is a setting, and settings can be changed. Nothing on the list requires new software, new budget, or a project. It requires someone to have looked, once, and then to decide what to fix first.

That is the whole value of the exercise. The organisation did not have a security problem it was ignoring. It had a security posture it could not see.

What "we assumed it was secure by default" actually costs

The gap is invisible until something forces it into view. No monitoring, no alerting, and no periodic review means the first indication of a problem is the problem itself — a donor receiving a fraudulent payment request from a real staff address, or a funder's due-diligence questionnaire arriving with questions the organisation cannot answer.

Oversharing is the failure nobody intended. Almost every finding in the list above was created by someone helpful, solving a real problem, quickly. Share a folder with a funder. Give a consultant admin rights so they can fix something. Keep a departed colleague's mailbox open so the handover is smooth. Each decision was defensible at the time; none of them was ever revisited, because there was no mechanism that would revisit them.

Nonprofits are attractive targets for unsophisticated attacks, precisely because they look approachable. The threat is rarely advanced. It is a compromised mailbox used to redirect a donation or a supplier payment, or a convincing message to a finance officer that appears to come from the executive director. These attacks depend on weak sign-in controls and on nobody watching — not on technical sophistication.

Funders and corporate partners increasingly ask. Grant agreements and corporate-partnership due diligence now routinely include questions about data handling and access control. An organisation that cannot answer is not usually rejected outright; it just finds the process harder each cycle, and the reasons are rarely stated.

Personal data obligations do not scale down with headcount. A nonprofit holding member, donor and beneficiary data in Hong Kong carries the same responsibility for it as a much larger organisation would. What "reasonable steps" look like in any specific case is a question for your own advisers, but the practical starting point is the same everywhere: you cannot demonstrate you are protecting data in a system whose configuration you have never examined.

Brocent's perspective: the value of the free check is that it is genuinely free and genuinely fast

Brocent has run IT operations across Asia since 2007, from Beijing originally, with a Hong Kong office since 2016 and group headquarters in Singapore since 2021. We deal with a lot of organisations whose first honest answer to "when was your Microsoft 365 configuration last reviewed?" is "never."

What we have learned from that is a slightly unfashionable thing to say: the hardest part is not the assessment, it is getting anyone to start. A paid audit — even a reasonably priced one — creates a decision gate. Someone has to justify the spend before knowing whether there is a problem, which means the organisations most likely to have serious findings are the least likely to look, because they have the least budget and the least certainty.

So the Quick Security Check is free for teams up to 150 users, with no card and no scoping call. That is not a trial or a teaser version. It is a real assessment: a Microsoft Secure Score review, an automated baseline check using CISA's open-source ScubaGear tooling, an MFA and conditional-access quick check, a top-20 list of prioritised findings, and a one-hour walkthrough with an engineer who explains each finding in plain language.

We should be equally straightforward about its limits, because overselling a free assessment would defeat the point of offering one. The Quick Security Check is a posture check, not an audit-grade report. Microsoft's Secure Score only reads settings that its API exposes, and no auditor or cyber-insurer accepts it as a formal assessment. There are controls that no automated tool can see — whether break-glass emergency-access accounts exist and are properly protected, how Entra administrative roles are actually restricted, what Teams external-app policies permit, how Power BI sharing is governed. Checking those requires the full CIS Microsoft 365 Benchmark, which is a different, paid engagement.

For most nonprofits, that distinction resolves cleanly. If you have never looked, the free check will find plenty, and fixing what it finds is where the return is. The audit-grade report matters when someone external needs evidence — a funder, an auditor, an insurer — not when you are trying to work out what to fix first.

What this looks like in practice

Access takes about fifteen minutes and is read-only. You grant read consent to the tenant. That is the whole setup. No agent is installed, no configuration is changed, and nothing is altered during the assessment.

The Secure Score review puts a number on where you are. Microsoft's own scoring gives a baseline and, more usefully, a trend line to measure against later. It is not the destination, but it is a starting coordinate that everybody involved can understand.

The ScubaGear baseline check runs an independent standard. ScubaGear is CISA's open-source Microsoft 365 baseline tooling — a published, external set of expectations rather than a vendor's opinion. Running it means the findings are measured against something you can go and read for yourself.

MFA and conditional access get looked at specifically. In practice this is where the highest-severity findings usually sit for an organisation of this size: accounts without MFA enforced, administrative accounts among them, legacy authentication still permitted, and no conditional-access policy governing where and how sign-ins are allowed.

You get a top-20 prioritised list, not a raw dump. This matters more than it sounds. A tool can generate hundreds of observations; that is not useful to an operations manager with four hours a week for IT. The list is ordered by what actually reduces risk fastest.

The one-hour walkthrough explains each finding in plain language. What it means, what could go wrong, roughly how much effort it takes to fix, and whether it can wait. There is no obligation attached to this conversation, and it is the part most organisations say was the most valuable — because a finding you do not understand is a finding you will not act on.

If more depth is warranted afterwards, the path is explicit rather than implied. The CIS Benchmark Audit covers the full CIS Microsoft 365 Benchmark at Levels 1 and 2 across Entra ID, Defender, Purview, Exchange Online, SharePoint and Teams — including the manual controls Secure Score cannot see — and produces an auditor- and insurer-ready evidence pack with a prioritised remediation roadmap and effort estimate, at a fixed US$2,500–4,500. Beyond that, a Hardening & Compliance engagement adds guided remediation to Secure Score 80+ and policy hardening, quoted per tenant. Most nonprofits of this size do not need either straight away. It is worth knowing they exist, and what they cost, before someone tells you an M365 review is a five-figure consulting project.

Three ways organisations handle Microsoft 365 security

Assuming the defaults are secure

  • The reasoning: "It's Microsoft, they handle security."
  • What it costs: nothing, and it is by far the most common position.
  • What you get: whatever the tenant was configured to on day one, plus every change made since by anyone with rights, none of it reviewed. Sharing links, guest accounts and admin roles accumulate quietly.
  • The real problem: it is not a small amount of protection, it is an unknown amount — and unknown behaves like zero at the exact moment it matters.

A paid third-party security audit

  • What it is: a comprehensive assessment against a recognised benchmark, producing evidence-grade documentation.
  • What you get: full coverage including manual controls, a defensible report for auditors, funders and insurers, and a remediation roadmap.
  • What it costs: real money — and, more limiting for a nonprofit, a decision that has to be justified before anyone knows whether there is a problem to justify it.
  • When it is right: when someone external needs evidence, or when the free check has already surfaced enough to warrant going deeper.

A free scored check with a prioritised report

  • What it is: a Secure Score review, a ScubaGear baseline, an MFA and conditional-access check, a top-20 findings list and a one-hour walkthrough — free for teams up to 150 users, with no scoping call.
  • What you get: a real picture of your current posture, an ordered list of what to fix, and an explanation of each item, at no cost and with no obligation.
  • What you do not get: the manual-control coverage and evidence-grade documentation of a full CIS benchmark audit.
  • When it is right: when nobody has ever reviewed the tenant — which is where most nonprofits and associations genuinely are.

Frequently asked questions

Is the audit really free?

The Quick Security Check is free for teams up to 150 users, with no card required and no scoping call. It is a real assessment producing a real scored report, not a sample or a partial version. The paid tiers — the CIS Benchmark Audit at a fixed US$2,500–4,500, and Hardening & Compliance quoted per tenant — exist for organisations that need audit-grade evidence or guided remediation, and they are published prices rather than a quote you have to ask for.

What happens during the one-hour walkthrough?

An engineer takes you through the findings in priority order and explains, for each one, what the setting currently does, what could go wrong because of it, roughly how much work it is to change, and whether it is urgent or can wait. It is a conversation rather than a presentation — most of the useful part is you asking what a finding means for how your organisation actually works. You keep the report either way, and there is no obligation attached.

Does this require giving Brocent permanent admin access?

No. The assessment uses read-only consent to your tenant, granted by you and revocable by you at any time. Nothing is installed, nothing is changed during the assessment, and no administrative rights are needed. If you later engage us to fix the findings, that is a separate conversation with its own separately agreed access.

How long does the audit take?

Granting read access takes about fifteen minutes. The automated portion — Secure Score review and ScubaGear baseline — runs quickly after that, and the walkthrough is one scheduled hour. From your side the total time commitment is well under two hours, which is deliberate: the assessment is designed for organisations where nobody has spare capacity, because those are the organisations most likely to have never done it.

What if the audit finds something serious?

You are told immediately rather than at the scheduled walkthrough. In practice "serious" usually means an unprotected administrative account, an active guest or former-staff account with real access, or broadly shared material that should not be broadly shared — all of which are settings that can be changed the same day. What we do not do is find something serious and then hold it hostage behind a proposal. You get the finding and a plain explanation of how to fix it, whether or not you engage us to do it.

Does this replace ongoing security management?

No, and this is worth being clear about. A point-in-time check tells you how your tenant is configured today. It does not tell you about the sharing link someone creates next month, the new starter who does not get MFA enrolled, or the guest account added for a project in the spring. Configuration drifts continuously, which is why the check is re-run annually inside our managed programmes and why continuous monitoring belongs to a managed IT plan rather than to a one-off assessment.

Is this suitable for a small nonprofit with no IT staff?

That is precisely the case it is designed for. It requires no technical preparation, no procurement process, and no in-house expertise — you grant read access, and someone explains the results to you in plain language. The prioritisation exists specifically because the person receiving the report is usually an operations manager with a few hours a week for IT, not an engineer. If your organisation is in that position, you are the intended reader, not an edge case.

Where the check fits: a first look, then someone who keeps looking

A free assessment is a good first step and a poor destination. Twenty findings tell you where you stand today. They do not stop a sharing link being created next quarter, or a new hire being onboarded without MFA, or a departing project officer's access surviving their departure by eighteen months. Configuration drift is the actual condition; a point-in-time check is a photograph of it.

What closes that loop is somebody owning the tenant continuously — enforcing MFA and conditional access as policy rather than as an intention, running onboarding and offboarding so access starts and stops when employment does, watching for the drift, and reviewing the posture on a schedule rather than when something goes wrong. That is a managed IT plan: a named team, a service desk your staff can actually reach, managed cloud services covering the Microsoft 365 estate, and a security review that recurs instead of happening once. Our plans are priced per user, per market, and published on the pricing page, which for a thirty-person nonprofit makes the budgeting conversation an arithmetic exercise rather than a discovery process.

The sensible sequence, though, is not to buy a plan today. It is to look first. Take the free Microsoft 365 security check, find out what six years of ordinary drift has actually left behind, and fix the top few findings — most of which cost nothing but an afternoon. Then decide, from evidence rather than anxiety, whether your organisation needs someone watching it continuously. If you would like to start there, get in touch and we will set up the read access and the walkthrough.

Share:

Ready to take action?

Turn these insights into a roadmap for your business.

Book a 15-minute no-obligation consultation with our APAC IT experts. We'll review your current setup and provide a tailored IT roadmap within 24 hours.

📋

Free Checklist

10 Critical Checks Before Expanding IT to Greater China

PIPL compliance, network segmentation, bilingual helpdesk setup, and more — everything your IT team needs before Day 1 in China.

Request the checklist →

📬 Monthly Asia IT Insights

China compliance updates, cybersecurity alerts, and IT tips for APAC teams — once a month.

No spam. Unsubscribe anytime.