?

Advisory / Security Posture Baseline

Where does your
risk actually live?

Most organisations
don't have a security
problem. They have an
orientation problem.

The board asks about security posture. A compliance requirement surfaces a gap nobody can explain. A near-miss incident raises questions about what would actually happen if something failed tomorrow.

The obstacle is not the lack of tools or policies. It is not knowing where to look first. Generic security reviews produce long lists. Checklists produce scores. Neither answers the question a decision-maker actually needs answered: where does our risk actually live, and which of those risks matters most right now?

The Security Posture Baseline is built for that moment. It does not go deep into any single domain. It maps the whole surface at a level sufficient to identify where meaningful risk concentrates, produces one clear decision output, and ends with a specific recommended next step.

Not a score.
Not a checklist.
Not a health check.

Security scores measure configuration against a framework. They tell you where you sit on a scale, not which risks carry weight in your specific environment. This engagement is not that.

i

Not this

A 100-item findings list

Long findings lists shift the problem rather than solve it. If everything is a finding, nothing is a decision. The Baseline produces a short, prioritised output, not an exhaustive catalogue.

ii

Not this

A framework compliance check

ISO, CIS, NIST scores measure posture against a standard. They do not measure risk against your actual environment, dependencies, and failure modes. This engagement measures the latter.

iii

Not this

A route to ongoing dependency

The engagement ends. The deliverable belongs to you. There is no monitoring subscription, managed service, or tool licence attached. What you do with the output is your decision.

iv

Not this

A cheaper version of deeper advisory

The Baseline is deliberately shallow across a broad surface. It is not a discount version of the Microsoft Identity Assessment. It answers a different question for a buyer at a different moment in their thinking.

Four areas.
One clear decision output.

The Baseline reviews four domains at a level sufficient to identify where meaningful risk concentrates. It stops short of the depth required for a full decision framework on any single domain. That is intentional. The goal is orientation, not exhaustion.

What the Baseline does not cover: deep Entra ID tenant analysis, full Conditional Access policy review, Azure subscription-level posture, penetration testing, or compliance audit work. Those belong to deeper engagements and are deliberately out of scope here.

  • 01

    Identity access posture

    Who has access to what, whether core controls are enforced across the user base, and where authority concentrates in a way that creates meaningful blast radius. This is not a deep Entra ID assessment. It is a surface read sufficient to identify whether identity is a primary risk area or not.

  • 02

    External exposure

    What is visible from outside your perimeter: DNS posture, subdomain inventory, email authentication alignment, TLS configuration, and whether any services are exposed to the public internet that should not be. The same view an attacker or third party would assemble in the first hour.

  • 03

    Operational readiness indicators

    Whether the organisation would detect a significant event, and whether someone has the authority and capability to act on it. Not a full incident readiness assessment. Enough to identify whether response capability is a material gap or a manageable one.

  • 04

    Microsoft 365 configuration fundamentals

    For Microsoft-dependent environments: a read on whether foundational controls are enforced or absent. MFA coverage, admin account hygiene, email security configuration, and the most commonly misconfigured settings that create avoidable exposure.

A deliverable built
for decisions, not filing.

The output is short by design. It exists to support a specific decision and produce a specific next step. If a report requires two hours to read before anything can happen, it has failed.

The Baseline ends.
The decision begins.

Every Baseline engagement closes with a named next step. That step will be one of three deeper advisory engagements depending on where risk concentrated in the review.

If identity and cloud controls emerged as the primary risk area, the logical next engagement is the Microsoft Identity and Cloud Security Assessment (£4,950). It produces a full decision-grade understanding of how identity and cloud security controls behave in practice, where the blast radius actually sits, and what leadership needs to decide.

If external exposure was the most significant finding, the External Exposure Review (£2,750) addresses that surface in depth: DNS, TLS, email authentication, subdomain inventory, and unintentionally exposed services.

If operational and response capability was the primary gap, the Incident Readiness Review (£3,500) assesses detection, response authority, escalation paths, recovery capability, and single points of failure under realistic failure scenarios.

The Baseline does not recommend a deeper engagement because Dettogni offers one. It recommends it because the work surfaced a specific question that cannot be answered without that depth. The recommendation follows from evidence.

The buyer this
engagement is built for.

The Baseline is not the right engagement for every organisation. These are the situations where it is.

i

Situation

The board conversation

Leadership has asked about security posture and nobody has a defensible answer. The Baseline produces one. Short enough to present, specific enough to act on.

ii

Situation

The compliance exposure

A customer, insurer, or regulator has asked about security controls. Before committing to a full assessment, the Baseline identifies what is actually in scope and what the honest answer looks like.

iii

Situation

The near-miss or incident

Something happened, or nearly happened. The Baseline provides a fast, independent read on the actual state of the environment, separate from any internal review that may be coloured by the incident itself.

iv

Situation

Before a deeper engagement

The organisation wants to commission deeper advisory work but is not yet sure which engagement addresses the right problem. The Baseline answers that question before a larger commitment is made.

What buyers
ask before engaging.

  • Q

    How does this differ from the Microsoft Identity Assessment?

    The Baseline is broad and deliberately shallow. It identifies where risk concentrates without the depth required to produce a full decision framework on any single domain. The Microsoft Identity Assessment goes deep into Entra ID posture, Conditional Access enforcement, privileged access exposure, and Azure control-plane configuration. The Baseline tells you which direction matters most. The Identity Assessment tells you exactly what is wrong and why.

  • Q

    What access is required?

    For the identity and M365 components, a read-only application registration in the Microsoft tenant is established with client approval before the engagement begins. External exposure work requires no access. All access is scoped to the engagement and removed on close.

  • Q

    Can we use the Baseline output with our board or leadership team?

    Yes. The report is written for two audiences: the person who will act on it technically, and the person who is accountable for the decision. It does not require a technical background to understand the risk summary or the recommended next step.

  • Q

    Does the Baseline overlap with the External Exposure Review?

    There is a surface read of external exposure in the Baseline, but it is not the same depth as the standalone External Exposure Review. If the Baseline identifies external exposure as the primary risk area, the External Exposure Review is the recommended next step specifically because the Baseline did not exhaust that domain.

  • Q

    What if we don't proceed to a deeper engagement afterwards?

    The Baseline stands on its own. The deliverable and the decision output are useful regardless of whether a deeper engagement follows. There is no obligation. The recommended next step is a recommendation, not a condition.

Begin here

Three working days
to a clear answer.
£3,250 + VAT.

The first step is a short Discovery Call. Twenty minutes. Used to confirm the engagement is the right fit, agree on access requirements, and set the start date.

The Baseline is carried out personally by Alex Ulfeldt, the security engineer who operates Dettogni. No handoffs, no junior analysts.

If the Baseline is not the right engagement for your situation, that will be the outcome of the call rather than a sale. A 20-minute call that ends with a clear recommendation is a better use of your time than commissioning the wrong engagement.

Book a Discovery Call See all advisory engagements

Dettogni advisory is fixed in scope, fixed in price, and designed to end.
United Kingdom · Remote engagements