Where could your employees accidentally expose company information while using AI?
Your team is already using AI — sanctioned or not. FBE assesses your Microsoft 365 environment and your organisation’s real AI usage, scores the risk, and hands you a staged plan to fix what we find. AI adoption you want, without the data leakage you fear.
Identity & Microsoft 365
MFA coverage, risky sign-ins, legacy authentication, Conditional Access, dormant users, guest accounts, privileged roles, external sharing, Secure Score.
Your data
Where sensitive HR, finance and customer files actually live, who they are shared with, public links, retention, backups, classification and DLP.
AI usage & shadow AI
ChatGPT, Claude, Gemini, Copilot and the tools you have never heard of: personal AI accounts, browser AI extensions, AI meeting bots, and connectors with standing access to your drives.
Shadow AI is the finding that surprises everyone
- An employee copies a customer spreadsheet into a personal ChatGPT account.
- HR uploads résumés to an unknown AI résumé tool.
- Finance runs statements through an AI PDF analyser.
- Marketing connects an AI tool to the company drive — and it keeps that access.
- Someone installs a browser extension that can read every page they open.
Microsoft now ships tooling for exactly this problem — Purview DSPM for AI, Defender for Cloud Apps, Conditional Access. Most businesses have some of it in their licence already and none of it switched on. Our job is finding what is exposed, turning on what you already own, and telling you plainly what is left.
You get a scorecard, not a 70-page PDF
One number out of 100 with a risk band, seven area scores, the findings in red and amber, and a remediation roadmap staged over the first 24 hours, 7 days and 30 days. It lives in your FBE workspace, and when we reassess next quarter you see the score move.
AI Security Snapshot
For 5–25 employees
from US$499
- Microsoft 365 configuration
- MFA coverage and admin roles
- External sharing
- AI usage overview and basic shadow-AI check
- AI policy and backup posture
- Scorecard, ten recommendations, 60-minute review
Security & Governance Assessment
For 20–100 employees
from US$1,250
- Everything in the Snapshot
- User, account and privileged-access review
- SharePoint / OneDrive permissions
- DLP and sensitivity labelling
- Full AI application inventory — sanctioned and not
- Data exposure review and vendor risk
- AI policy, staff questionnaire, remediation roadmap
- Executive report, technical report, risk matrix
Security Implementation
After an assessment
from US$2,500
- MFA and Conditional Access rollout
- Purview, sensitivity labels, DLP
- Defender controls and admin hardening
- Guest cleanup
- AI acceptable-use policy, sanctioned-AI list
- Staff training
What the first month looks like
- First 24 hoursCompromised and risky accounts, missing MFA, dangerous admin access, exposed public sharing — closed.
- First 7 daysConditional Access, guest review, an AI acceptable-use policy your staff actually acknowledge, a sanctioned-AI list, privileged-account separation.
- First 30 daysPurview and DLP, sensitivity labels, Defender controls, shadow-AI monitoring, staff training, an incident-response procedure.
Every fix is verified and every claim sits in your scorecard, where the next assessment either proves the improvement or says so. Start with a conversation — it costs nothing to find out where you stand.