Skip to main content
ConfidentialSecurity Posture BriefingSIG-SEC-2605-APX
Security Posture  //  May 2026

Apex Heating & Cooling

Your security posture, the exposures that matter, and what to fix before renewal.

Confidence●●●●High
72/100
Posture Score
3
Critical Findings
86%
MFA Coverage
11
Open Findings
Bottom Line

Your posture scores 72/100 — solid, but three admin accounts still lack MFA and audit logging is off. These are exactly the exposures that fail cyber-insurance questionnaires and invite ransomware. All three are fixable this month.

What

3 of 14 admin accounts can sign in without MFA.

Why

Privileged accounts are the #1 ransomware entry point.

Expected Impact

Closeable this week — the single biggest risk reduction available.

Findings Register

01 / FINDINGS
FindingSeverityAreaStatus
Admin accounts without MFA ◂ YOUCriticalIdentityOpen
Unified audit log disabled ◂ YOUCriticalLoggingOpen
Legacy auth protocols enabled ◂ YOUCriticalIdentityOpen
No conditional access policiesHighIdentityOpen
Inactive accounts not disabledMediumIdentityOpen
External sharing unrestrictedMediumDataReview

Secure Score by Category

FIG. 01
Device
81%
Apps
75%
Data
70%
Identity
64%
Identity is your weakest category — and the highest-leverage to fix.

Critical Exposures

02 / RISK
3 CRITICAL
MFA Gap

3 of 14 admin accounts can sign in with a password alone.

No Audit Trail

Unified audit logging is off — a breach would be invisible after the fact.

Legacy Auth

Basic authentication protocols remain enabled, bypassing MFA entirely.

Quick Wins

03 / UPSIDE
Enable Logging

Turning on unified audit logging is a one-click, zero-cost win.

Insurance Ready

Closing the MFA gap likely satisfies your cyber-insurance MFA requirement outright.

Recommended Action
Enforce MFA on all admin accounts and enable unified audit logging this week.
Expected: Posture score 72 → ~85; meets the cyber-insurance MFA requirement.

Remediation Plan

04 / ACTIONS
Enforce MFA on the 3 remaining admin accounts
Enable unified audit logging in Microsoft Purview
Disable legacy authentication protocols
Draft a baseline conditional-access policy
Sources & Reliability
Microsoft Secure Score
Entra ID
Microsoft Purview
Defender

Findings reflect the Microsoft 365 tenant as of the report date. On-prem systems and third-party SaaS are out of scope for this briefing.