Central Power Systems: The Microsoft 365 Security Assessment That Justified Full Hardening
How a 400-employee industrial firm used a structured Microsoft 365 Security Assessment to expose MFA gaps, unprotected data, and NIST 800-171 non-compliance — and walked away with a defensible roadmap that became the catalyst for full environment hardening.
Headline Outcomes
Four measurable results defined the assessment. As a result, leadership gained the visibility needed to move from gap discovery to informed decision-making and strategic alignment.
Documented security visibility across Exchange, SharePoint, OneDrive, Teams, and Entra ID.
Identified accounts and access patterns operating without modern authentication controls.
Mapped current state against NIST 800-171 controls to surface non-compliance areas.
Actionable, prioritized remediation plan that became the foundation for the full hardening project.
A 400-Employee, 22-Location Industrial Firm Operating on Assumptions, Not Evidence
Central Power Systems & Services (CPSS) is a 400-employee industrial firm operating across 22 locations — a distributed footprint where every Microsoft 365 misconfiguration multiplies across geographies, business units, and access patterns. Like many mid-market industrial organizations, CPSS had adopted Microsoft 365 over time: licenses were purchased, mailboxes were created, SharePoint sites were built, and Teams was deployed. However, the environment was never designed with security as a primary goal.
Leadership knew the environment had grown faster than the security practices surrounding it. However, they did not have a documented view of where the gaps actually existed. MFA coverage was uncertain. Data sensitivity was undocumented. Conditional Access was inconsistent. And while NIST 800-171 was on the radar as an industry expectation, no one had mapped the current state against the standard.
Before CPSS could confidently invest in security improvements, they needed something different: a structured Microsoft 365 Security Assessment that would turn assumptions into evidence, surface the gaps in writing, and put a defensible roadmap in front of leadership — one that decision-makers could fund with confidence.
Why Operating Without Visibility Was the Real Risk
In a 400-employee, 22-location environment, the absence of an evidence-backed security posture isn’t a documentation gap — it’s an exposure surface. Without the assessment, CPSS faced four clear risks. As a result, leadership lacked the visibility needed to make informed security decisions.
Identity and Access Exposure
Without MFA coverage analysis and Conditional Access visibility mapping, the front door of the environment remained a question mark. Consequently, identity-related risks could persist without detection.
Unprotected Sensitive Data
Data was flowing through SharePoint, OneDrive, and Teams without documented sensitivity labels, DLP controls, or retention policies. As a result, business-critical information faced unnecessary exposure.
NIST 800-171 Misalignment
As an industrial firm with growing exposure to federal supply chain expectations, CPSS faced increasing compliance pressure. Furthermore, operating outside NIST 800-171 guidance increased compliance risk.
Unfundable Hardening Decisions
Without a structured assessment, any proposal to invest in hardening was an opinion — not an evidence-backed business case. Leadership couldn’t responsibly fund what wasn’t documented. Therefore, necessary security improvements remained difficult to prioritize and approve.
A Structured Microsoft 365 Security Assessment Delivered Through Cyber Watchtower
Jadex Strategic Group delivered the engagement through its Cyber Watchtower platform, applying a structured Microsoft 365 Security Assessment methodology designed to convert environment ambiguity into evidence. As a result, leadership received a clear view of current risks, security gaps, and improvement opportunities.
Tenant Discovery and Configuration Baseline
Conducted full tenant discovery across Exchange, SharePoint, OneDrive, Teams, and Entra ID — documenting the current configuration baseline, license status, and administrative model.
Identity and Access Posture Analysis
Analyzed MFA coverage, legacy authentication exposure, Conditional Access policy gaps, privileged account hygiene, and inactive user accounts — surfacing where identity controls were strong and where they weren’t.
Data Protection and Compliance Posture Review
Reviewed sensitivity label usage, DLP policy coverage, retention configuration, audit log readiness, and external sharing status across SharePoint, OneDrive, and Teams — documenting where data was protected and where it wasn’t.
NIST 800-171 Gap Analysis
Mapped the current Microsoft 365 environment against NIST SP 800-171 control families — quantifying alignment, surfacing gaps, and translating regulatory expectations into specific tenant configuration actions.
Prioritized Remediation Roadmap and Leadership Briefing
Delivered a written assessment report, a prioritized remediation roadmap, and a leadership briefing — translating findings into a fundable hardening plan with effort, sequencing, and risk reduction articulated clearly.
From Assumptions to Evidence — and a Funded Path Forward
The Cyber Watchtower assessment gave CPSS something they couldn’t generate internally: a defensible, evidence-backed view of their Microsoft 365 environment and a prioritized roadmap that leadership could fund with confidence. Consequently, decision-makers gained the clarity needed to move forward with hardening efforts.
Documented Security Posture
CPSS now operates with a written baseline of their Microsoft 365 environment across identity, data, collaboration, and compliance — replacing assumptions with evidence.
MFA and Identity Gaps Identified
The assessment surfaced specific accounts, access patterns, and Conditional Access posture issues operating without modern authentication controls — closing the visibility gap on identity.
Unprotected Data Exposed
Sensitivity label gaps, DLP coverage shortfalls, and unmanaged external sharing were documented across SharePoint, OneDrive, and Teams — turning hidden risk into visible, addressable findings.
NIST 800-171 Alignment Quantified
The assessment delivered a quantified gap analysis against NIST 800-171 control families — giving CPSS a concrete starting point and a defensible benchmark for industrial supply chain compliance conversations.
A Fundable Hardening Roadmap
Leadership walked away with a prioritized remediation plan — effort, sequencing, and risk reduction articulated clearly enough to fund decisively. The roadmap became the foundation for the CPSS Hardening engagement that followed.
A Catalyst, Not a Report on a Shelf
Most security assessments end as PDFs in a folder. This one became the catalyst engagement — directly leading to CPSS’s full Microsoft 365 hardening initiative and demonstrating the Watchtower model in action.
The assessment converted what we suspected into what we could see — in writing, mapped to a standard, and prioritized for action. That’s what made it fundable. And that’s what turned it from a report into the start of the hardening work that came next.
Turn Your Microsoft 365 Posture Into Documented, Fundable Action.
Like CPSS, your environment may have grown faster than the security model around it. However, assumptions do not reduce risk. Therefore, a structured Cyber Watchtower assessment helps transform uncertainty into evidence and evidence into action.
