- Chris Hoffmann, CTO and CISO
Unlocking Greater Cyber Security Value from Your Microsoft Licensing Investment
Last week, I presented at the DTSL Technology Leadership Briefing roadshow in Wellington, Nelson and Christchurch, under the theme “Unlock Greater Cyber Security Value from your Microsoft Licensing Investment.”
Across all three sessions, the engagement was excellent. The audiences were receptive, asked great questions, and were clearly thinking about how cyber security applies to their own organisations. It was also clear that cyber security is no longer just a technical issue. It is now a business resilience, governance and leadership conversation.
For many organisations, Microsoft 365 has become the centre of day-to-day work. Email, Teams, SharePoint, OneDrive, identity, devices and business applications all sit around the Microsoft ecosystem. That means Microsoft is no longer just a productivity platform. It is one of the most important security control points an organisation has.
One of the key messages I wanted to get across was that many businesses already own more cyber security capability than they realise. The issue is that those controls are not always enabled, configured, monitored or well understood. Some organisations have invested in Microsoft 365 licensing but are still largely using it for email, Office apps and Teams. Others have security features switched on, but without a clear view of how they work together or what risk they are meant to reduce.
During the sessions, I worked through a number of realistic cyber risk scenarios. These were not dramatic, movie-style hacking examples. They were based on the types of incidents we see across our own customer base. A compromised mailbox. A fake invoice. A user approving an unexpected MFA prompt. A supplier account being used as a path into another business.
I used those examples because that is where the risk usually lives. In my role as CISO for the DTSL Group, I see how quickly a small weakness can become a real incident. Often it is not one major failure. It is a mix of things: an account without the right controls, a process that relies too heavily on trust, a lack of visibility, or uncertainty about who should respond.
The area I pushed hardest was staff awareness and training. Not the old tick-box style training that people click through once a year, but current, practical training that reflects the way attacks are actually changing.
Business email compromise is a good example. Traditionally, people were taught to look for poor spelling, strange wording or obvious red flags. That advice is no longer enough. With AI-assisted phishing and business email compromise, attackers can produce emails that are well written, well timed and much more believable. They can copy tone, context and style in a way that makes the message feel normal.
That changes the training requirement. Staff need to understand the new threat, but they also need clear business processes to fall back on. How do we verify a change of bank account? What do we do if an urgent payment request comes from a senior person? Who do staff ask when something feels slightly off?
For a few people in the room, the scenarios were a little unsettling. That was not really the point, but it was useful. Good cyber security conversations should create pause. They should make people think about what would actually happen inside their own organisation if one of those events occurred.
Who would notice? Who would respond? What logs would be available? Which accounts would be exposed? What process would stop money leaving the door? How quickly could the business recover?
Microsoft provides a strong set of tools to help improve readiness, including identity protection, MFA, conditional access, endpoint management, email security, device compliance and reporting. But the tools are only part of the answer. The real value comes when technical controls, staff training and business process all line up.
For most organisations, the answer is not to do everything at once. It is to focus on the things that reduce the most likely and most damaging risks. Current staff training. Strong identity controls. Well-managed MFA. Clear payment verification processes. Visibility of sign-ins and risky activity. Device compliance. Email protection. Regular review of administrative access. Clear incident response steps. Good backup and recovery thinking.
These are not always glamorous areas, but they are the foundations that make a real difference.
The roadshow reinforced for me that cyber security is now a leadership issue. Technical teams have an important role to play, but they cannot carry the risk alone. Boards, executives and managers need enough understanding to ask good questions, make informed decisions and support sensible investment.
The discussions in Wellington, Nelson and Christchurch showed that there is a real appetite for practical, grounded cyber security guidance. People are not looking for scare tactics. They are looking for clarity. They want to understand the risks, know where they stand, and make sensible improvements.
That is exactly where Totality can help.
By looking at cyber security through the Microsoft lens, we can help organisations make better use of the tools they already have, identify the gaps that matter, and build a more practical security posture over time.
The DTSL Technology Leadership Briefing was a great opportunity to have those conversations, and I look forward to continuing them in the next round of roadshows.
