Apex Heating & Cooling
Your security posture, the exposures that matter, and what to fix before renewal.
Your posture scores 72/100 — solid, but three admin accounts still lack MFA and audit logging is off. These are exactly the exposures that fail cyber-insurance questionnaires and invite ransomware. All three are fixable this month.
3 of 14 admin accounts can sign in without MFA.
Privileged accounts are the #1 ransomware entry point.
Closeable this week — the single biggest risk reduction available.
Findings Register
01 / FINDINGS| Finding | Severity | Area | Status |
|---|---|---|---|
| Admin accounts without MFA ◂ YOU | Critical | Identity | Open |
| Unified audit log disabled ◂ YOU | Critical | Logging | Open |
| Legacy auth protocols enabled ◂ YOU | Critical | Identity | Open |
| No conditional access policies | High | Identity | Open |
| Inactive accounts not disabled | Medium | Identity | Open |
| External sharing unrestricted | Medium | Data | Review |
Secure Score by Category
FIG. 01Critical Exposures
02 / RISK3 of 14 admin accounts can sign in with a password alone.
Unified audit logging is off — a breach would be invisible after the fact.
Basic authentication protocols remain enabled, bypassing MFA entirely.
Quick Wins
03 / UPSIDETurning on unified audit logging is a one-click, zero-cost win.
Closing the MFA gap likely satisfies your cyber-insurance MFA requirement outright.
Remediation Plan
04 / ACTIONSFindings reflect the Microsoft 365 tenant as of the report date. On-prem systems and third-party SaaS are out of scope for this briefing.