DSE Cybersecurity · Technical security assessment

Turn identity sprawl into a Zero Trust roadmap.

A point-in-time advisory review of where account takeover, standing privilege, and unreviewed access actually sit, and a sequenced path toward a Zero Trust target state. We work from the evidence you can produce, describe the target design and its trade-offs, and hand you a roadmap a named owner can execute against.

For the leader who owns identity risk. Advisory and readiness work. Not an implementation service, not an audit, not a certification.

Platform advisory scope

Where a named platform is in scope.

Most of this work is vendor-neutral. Where the evidence in scope is a specific identity or productivity platform DSE is approved to name, the reviewed scope is stated in approved wording. The identity-directory scope reads: A structured, point-in-time manual advisory review of client-provided Microsoft Entra portal configuration and exports, with an evidence register, findings, and remediation priorities. The productivity-suite scope reads: A structured, point-in-time manual advisory review of client-provided Microsoft 365 portal configuration and exports, with an evidence register, findings, and remediation priorities.

This is an owner-approved advisory and evaluation scope with no independent certification, partner, or reseller status. Implementation, hardening, and monitoring require separate evidence and scope. Every other identity or productivity platform is advisory and evaluation context only and is scoped separately with evidence.

Named methodology

Current identity state, then the road to Zero Trust.

The Identity and Zero Trust Advisory Method follows DSE's bounded-evidence assessment method: a bounded evidence request, focused interviews, a business-context severity rating, and a roadmap with named owners. The lane-specific layer maps identity lifecycle, authentication strength, privileged access, application and device access, and segmentation against the Zero Trust tenets in NIST SP 800-207, framed as a staged roadmap rather than a single leap.

01 · Scope

Scope and boundary

We agree the systems, environments, data types, review period, and exclusions in writing before any evidence is collected, with a stated reason for each exclusion.

02 · Evidence

Bounded evidence request

A defined request for client-provided exports, screenshots, screen shares, and documents. We do not request administrator credentials and we do not run automated scans.

03 · Interviews

Focused interviews

Short, targeted conversations with the people who own the controls, to test how the design actually operates rather than how a diagram says it should.

04 · Rating

Business-context severity

We rate each observed gap by likelihood and business impact, and record evidence strength alongside it. Severity is a business-context rating, not a vulnerability score, and the method is explained in the report.

05 · Findings

Evidence-linked findings

Each finding states what we observed, why it matters, the supporting evidence, the recommended action, and a named accountable owner.

06 · Roadmap

Roadmap with named owners

Immediate actions and a sequenced roadmap that balances risk reduction, dependencies, effort, and cost, with named owners and an executive readout for leadership.

Typical timebox: 3 to 5 weeks after kickoff and timely evidence access. Larger, multi-environment, or high-complexity engagements are scoped separately. Fees are scoped after the diagnostic and confirmed in writing before work begins.

Evidence reviewed

What we review, and what we do not touch.

We assess client-provided directory and identity exports, group and role membership exports, conditional-access or access-policy exports, privileged-role inventories, joiner-mover-leaver process documentation, and application access lists, supplemented by screen shares where a live view is faster than an export.

We do not request administrator credentials, we do not connect tooling to your environment, and we do not run automated scans. The review is manual and evidence-based, so it stays inside a boundary you can see and revoke.

Deliverables

Named artifacts. Not a slide deck.

01

Identity and access evidence register

Every identity and access control in scope with the evidence you produced, a business-context severity, an accountable owner, and a target date.

02

Privileged access findings

Standing privilege, orphaned accounts, shared administrative credentials, and break-glass paths reviewed against least-privilege intent, with the exposures that matter flagged.

03

Authentication and access-policy review

Multi-factor coverage, legacy authentication paths, and conditional access or equivalent policy reviewed against the target posture, with the gaps that let account takeover through.

04

Zero Trust maturity read

A staged read of your current posture against the NIST SP 800-207 tenets, so the roadmap targets the highest-leverage moves first.

05

Joiner-mover-leaver review

The access lifecycle assessed for the reviews and revocations that actually happen versus the ones the policy assumes.

06

Prioritized Zero Trust roadmap

Immediate actions and a sequenced roadmap balancing risk reduction, dependencies, effort, and cost, with named owners and an executive readout.

Sample output

A scorecard leaders can act on.

Synthetic sample — not client data. It contains no client information and is not a finding about any organization.

The sample table scrolls horizontally on smaller screens. Keyboard users can focus the labeled table region and use horizontal navigation.

Synthetic identity and access scorecard excerpt — not client data
Control areaObserved evidenceSeverityRecommended move
Privileged accessSeveral administrative roles are assigned permanently with no time-bound elevation or periodic recertification.HighMove to time-bound elevation, set a recertification cadence, assign an owner.
AuthenticationMulti-factor is enforced for most staff, but a legacy authentication path remains enabled for a shared mailbox.HighDisable the legacy path, migrate the shared mailbox, confirm coverage evidence.
Access lifecycleLeaver access is removed on a manual ticket with no periodic reconciliation of active accounts.ModerateAdd a scheduled reconciliation of active accounts against current staff.

Final ratings depend on the environment, the evidence, and the agreed method. We do not convert findings into a purported certification score.

Frameworks referenced

Framework structure, no vendor claims.

We use the Zero Trust tenets of NIST SP 800-207 as the target model and NIST CSF 2.0 as the organizing structure. These frameworks shape how we describe outcomes; they do not make this an accredited assessment, and the roadmap is advisory.

How the work is delivered

Accountable delivery, disclosed clearly.

DSE delivers through documented in-house expertise and qualified specialists from our expert network, selected for the technologies and risks in scope. DSE remains accountable for scope, quality, integration, and outcomes. Where specialist or partner delivery is involved, we disclose that role clearly.

Accountable owner: DSE delivery leadership.

Clear boundaries

Advisory roadmap, not assurance.

This is a point-in-time assessment of the identity, access, and Zero Trust evidence and documentation in the agreed scope. It is not legal advice, not an audit, not a certification, and not an attestation. It does not guarantee compliance or any enforcement or examination outcome. It does not make your organization secure and does not prevent, detect, or reduce the likelihood of any security incident; it documents risk against a defined scope at a point in time. DSE does not operate a 24/7 security operations center, does not provide continuous monitoring or managed detection and response, does not perform live incident response or digital forensics and incident response (DFIR), does not run penetration tests, and does not resell licenses. Where you need any of those, we help you scope the requirement and select a provider you contract directly. Remediation implementation is performed only where it is separately scoped in writing. Counsel, auditors, and assessors retain their respective roles.