Security governance service

Microsoft 365 security
that stays locked down

Cloudservices Secure gives NZ businesses a strong Microsoft 365 security baseline, then monitors it continuously to make sure it stays that way. We work alongside your existing IT provider — we do not replace them.

Stronger security postureWe harden Microsoft 365 against common threats like phishing, credential theft, and unauthorised access.
Ongoing drift monitoringYour security settings are continuously checked so important protections do not quietly slip out of place over time.
Clear monthly reportingYou get plain-English Secure Score reporting that shows what changed, what improved, and what needs attention next.

Three Microsoft 365 security plans

Each plan builds on the one before it. Most businesses start on Secure+ because it covers the controls most commonly required by cyber insurers and the threats NZ SMBs face most often.

Secure

$459/month up to 10 users

+$6/user from user 11

For businesses that want strong, reliable Microsoft 365 security without complexity. Covers the fundamentals that protect against credential theft, phishing, and unauthorised access.

  • Multi-factor authentication for users and admins
  • Block legacy sign-ins and unauthorised app access
  • Email labels, endpoint protection, encryption, and audit logging
  • Configuration drift monitoring and monthly Secure Score reporting

Secure Pro

$1,739/month up to 10 users

+$14/user from user 11

For professional services firms, regulated organisations, and businesses with Privacy Act, FMA, insurance, or due diligence obligations.

  • Everything in Secure+
  • Approved-device access and just-in-time admin controls
  • Access reviews, phishing-resistant MFA, and stronger endpoint controls
  • Extended audit retention for documented governance evidence

All prices are NZD ex-GST. GST-inclusive totals for up to 10 users are $527.85 for Secure, $1,033.85 for Secure+, and $1,999.85 for Secure Pro.

Security governance, not another helpdesk

Cloudservices Secure focuses on Microsoft 365 configuration, hardening, and monitoring. Your existing IT provider keeps handling everyday support, licensing, and infrastructure unless you agree otherwise.

1

Set the baseline

We configure Microsoft 365 to a strong security baseline that matches the plan you choose and the way your business works.

2

Harden access

We secure logins, admin access, email protections, and device controls so common attack paths are closed off early.

3

Monitor for drift

We continuously watch for security settings that change or fall out of line with your approved baseline, then act on alerts.

4

Report in plain English

You receive a monthly Secure Score summary so you can see what changed, what improved, and what needs attention next.

Compare every included control

A filled circle means the feature is included in that plan. This table is written in plain language so you can see what each control means for your business, not just the Microsoft feature name.

Feature What it means for your business Secure Secure+ Secure Pro
Keeping your accounts secure
Multi-factor authentication (MFA)Every user verifies their identity with a second step before accessing Microsoft 365, so a stolen password alone is not enough.
MFA for administratorsAdmin accounts are protected by stricter sign-in rules because they are a higher-value target for attackers.
Block old-style login methodsLegacy username-and-password sign-ins are disabled so attackers cannot bypass modern security checks.
Automatic risk detectionMicrosoft sign-in risk signals can block or challenge suspicious logins automatically when compromise is detected.
Block unauthorised app connectionsStops third-party apps getting access to your Microsoft 365 data without approval, which is a common phishing trick.
Restrict who can create appsLimits who can register new apps in your Microsoft 365 tenant, reducing accidental or malicious data exposure.
Geographic access controlsBlocks sign-ins from countries you have not approved, cutting down a large amount of opportunistic attack traffic.
Admin portal lockdownRestricts access to the Microsoft 365 admin centre and applies tighter controls even when approved admins sign in.
Require approved devicesOnly managed devices that meet your security standard can access Microsoft 365 services and data.
Just-in-time admin access (PIM)No one keeps permanent admin rights. Access is requested for a task, time-limited, and fully logged.
Scheduled access reviewsRegular reviews help confirm people still need the access they have, supporting good governance and Privacy Act obligations.
Phishing-resistant login (hardware MFA)Stronger MFA methods reduce the chance of attackers intercepting or tricking users into approving a login.
Remove phone and text MFAMoves users away from weaker SMS and voice methods to more secure authenticator-app sign-ins.
Protecting your email
External email warning labelsMessages from outside your business are clearly marked so staff can spot phishing and impersonation attempts faster.
Block dangerous attachmentsExecutable files are blocked before they reach inboxes, reducing a common malware delivery path.
Stop emails forwarding outside the businessBlocks automatic forwarding to external addresses, which helps prevent quiet data leakage during email compromise.
Email domain authentication (DMARC)Makes it far harder for someone to send messages pretending to come from your business domain.
Anti-impersonation protectionDetects email that looks like it is from an executive, supplier, or trusted contact when it is not.
Safe link and attachment scanningLinks and attachments are checked in a secure environment before staff open them, helping catch newer threats.
Automatic threat containmentWhen a threat is detected, Microsoft can start automated investigation and containment much faster than a manual review.
Protecting your devices
Antivirus and endpoint protectionMicrosoft Defender is configured across managed devices to protect against malware, ransomware, and other threats.
Automatic Windows updatesSecurity patches are applied promptly so known vulnerabilities are closed before they can be exploited.
Full-disk encryptionData on a lost or stolen device stays unreadable without the correct credentials.
Tamper protectionHelps prevent security software from being switched off by mistake or by malware.
Credential GuardProtects Windows credentials stored in memory, making it harder for malware to extract and reuse them.
Attack surface reductionBlocks common attack techniques such as suspicious macros, script abuse, and unexpected process launches.
Advanced attack surface reductionAdds stronger protection for higher-risk scenarios, including persistence and process-injection techniques.
Control PowerShell and scripting toolsApplies tighter controls to admin scripting tools that attackers often abuse to move through a network.
Monitoring and reporting
Full audit loggingKeeps a record of who signed in, what changed, and what activity took place across Microsoft 365.
Mailbox activity loggingRecords key mailbox activity so email-based incidents can be investigated with a proper evidence trail.
Configuration drift monitoringContinuously checks your settings against the approved security baseline and alerts us if something changes.
Monthly Secure Score reportProvides a plain-English monthly summary of Microsoft Secure Score, changes made, and areas to consider next.
Extended audit retentionRetains logs for 90 days instead of the standard 30 days, helping with investigations and compliance evidence.

What Cloudservices Secure covers and what it does not

This service is for Microsoft 365 security governance. It strengthens your security baseline and keeps watch over it, but it does not replace your broader IT agreement.

Included in the service

  • Microsoft 365 security configuration and hardening
  • Ongoing monitoring for configuration drift and security posture
  • Monthly Secure Score reporting in plain language
  • Guidance on which plan fits your risk and compliance needs
  • Support working alongside your existing IT provider

Not included

  • Microsoft 365 licensing, which is purchased separately through your IT provider
  • Day-to-day helpdesk work such as password resets, device setup, and software troubleshooting
  • Backup and disaster recovery unless you add it separately
  • Routers, firewalls, on-premise servers, and other network infrastructure
  • Formal incident response retainers, although we can assist with containment and investigation

Signs it is time to move up a plan

You can upgrade at any time. These are the common triggers we see when a business has outgrown its current Microsoft 365 security plan.

Move from Secure to Secure+

  • Your staff regularly receive email from clients, suppliers, or the public and you want stronger phishing protection
  • You want to lock Microsoft 365 access down to approved countries
  • Your domain is being spoofed, or you want better protection against impersonation
  • You need deeper email threat filtering without jumping straight to full governance controls

Move from Secure+ to Secure Pro

  • You operate in legal, accounting, finance, healthcare, or another regulated field
  • You need stronger evidence for Privacy Act, FMA, insurance, or due diligence obligations
  • You want just-in-time admin access, approved-device access, and scheduled access reviews
  • You need longer audit retention and tighter endpoint controls for higher-risk users

Frequently asked questions

These are the questions we hear most from businesses comparing Secure, Secure+, and Secure Pro.

Does Cloudservices Secure replace our current IT provider?

No. Cloudservices Secure is a Microsoft 365 security governance service. We work alongside your current IT provider rather than replacing their helpdesk, licensing, or infrastructure role.

Is Microsoft 365 licensing included in the monthly fee?

No. Microsoft 365 licensing is purchased separately through your existing IT provider. Our fee covers the security configuration, hardening, and ongoing monitoring work only.

What size business are these plans designed for?

The plans have a minimum of 5 users. Pricing covers up to 10 users, then adds a small per-user charge from user 11 onwards.

Can we upgrade later if our risk or compliance needs change?

Yes. Each plan builds on the one before it, and you can upgrade at any time as your team grows, your compliance obligations increase, or your risk profile changes.

Which plan do most businesses choose?

Most businesses begin on Secure+ because it covers the protections most commonly required by cyber insurers and addresses the majority of real-world threats faced by NZ SMBs.

Ready to choose the right Microsoft 365 security plan?

Talk to Cloudservices about your current setup and we will recommend the right starting point for your users, risk level, and compliance obligations.