Fully utilized across organizationPartially utilized (some tools/workloads)Licensed but minimally usedNot using Microsoft security stack
Fully enforced with Zero Trust approachPartially implementedBasic MFA onlyLimited or no controls
Fully managed and securedPartially managed (mixed tools)Using legacy tools (SCCM/AV only)No centralized management
Advanced protection (Defender for Office 365, Safe Links/Attachments)Basic protection (spam filtering only)Third-party solution in placeLimited protection
Fully implemented across data estatePartially implementedPlanned but not implementedNot in place
Centralized SOC with SIEM/XDR (e.g., Sentinel)Multiple tools with partial visibilityReactive/manual monitoringNo centralized monitoring
Full visibility and control (CASB in place)Partial visibilityLimited visibilityNo visibility
Ready with structured data and integrationsPartially readyExploring use casesNot ready
Unified CNAPP (e.g., Defender for Cloud)Native tools per cloudLimited security controlsNo dedicated cloud security
tool sprawllack of visibilitycompliance gapsalert fatigue
Based on your responses and selections, please find your score below.
A detailed report has been shared to your email.