logo
logo
Sign in

Department of Homeland Security: Some IT Consultants weaken Office 365 Security

avatar
Ascent InfoSec
Department of Homeland Security: Some IT Consultants weaken Office 365 Security

The DHS has issued a memo essentially stating that some IT consulting firms and Managed IT service providers (MSPs) involved in Office 365 migrations are not properly securing the cloud productivity suite for customers.

On the one hand, such statements can give the overall IT consulting and IT services market a black eye.

But on the other hand, partners that communicate the warning (and proper Office 365 security settings) to end-customers can likely differentiate themselves from others.

“Since October 2018, the Cybersecurity and Infrastructure Security Agency (CISA) has conducted several engagements with customers who have used third-party partners to migrate their email services to O365.

The organizations that used a third party have had a mix of configurations that lowered their overall security posture (e.g., mailbox auditing disabled, unified audit log disabled, multi-factor authentication disabled on admin accounts).

In addition, the majority of these organizations did not have a dedicated IT security team to focus on their security in the cloud.

collect
0
avatar
Ascent InfoSec
guide
Zupyak is the world’s largest content marketing community, with over 400 000 members and 3 million articles. Explore and get your content discovered.
Read more