Toronto / GTA professional firms

Microsoft 365 & Cyber Risk Scorecard for Professional Firms

A practical self-review for professional-firm leaders who want clearer evidence about Microsoft 365 access, administrator roles, staff departures, sharing, recovery and IT ownership. It is not a compliance audit or formal security rating.

What does this scorecard evaluate? It organizes leadership questions around identity and sign-in controls, privileged administration, onboarding/offboarding, external sharing and email, device responsibility, backup/recovery, documentation and incident ownership. The goal is to identify what your firm can verify, what is only partly verified and what is still unknown.

Boundary: A completed scorecard describes the state of your evidence. It does not certify compliance, prove that Microsoft 365 is secure or calculate the probability of a cyber incident.

Who it is for

A leadership self-review for Toronto and GTA professional firms

Use it when a managing partner, COO, office administrator or operations leader needs to ask better questions of an internal IT team or current provider without starting with vendor jargon.

Law firmsAccounting / CPA firmsInsurance / mortgage firmsProfessional services

What to review

Six evidence areas before you rely on assumptions

Identity & sign-in

Know which accounts are active, how sign-in protections are applied and how urgent access revocation is handled.

Administrator access

Identify privileged accounts and whether broad roles have a documented operational reason.

User lifecycle

Review onboarding, role changes and departures so old access is not left to assumption.

Sharing & email

Clarify external access, guest-sharing ownership and the process for suspicious email or account activity.

Devices & recovery

Understand device responsibility, Microsoft 365 recovery expectations and who can show restore evidence.

Ownership & escalation

Know who administers the environment, where documentation lives and who leads incident escalation.

How to score it

Use evidence states, not a made-up risk percentage

For every question, mark the state that best matches what can be demonstrated today.

VerifiedCurrent configuration, documentation, records or a repeatable process can be shown.
Partly verifiedSome evidence exists, but scope, ownership or consistency is incomplete.
UnknownThe firm cannot currently confirm the answer or identify reliable evidence.
Not applicableThe question genuinely does not apply to the current environment.

Scorecard preview

Ten questions worth answering before the download

The PDF contains the full worksheet and action pages. These questions are intentionally visible and useful without a form.

QuestionEvidence to look for
Who has privileged Microsoft 365 or Microsoft Entra administrator access?Current role assignments and a named owner for review.
How is multifactor authentication applied to users and administrators where appropriate?Current configuration or policy evidence rather than a verbal assumption.
What happens when an employee or contractor leaves?A repeatable departure checklist covering sign-in, sessions, groups, apps, data and devices as applicable.
How are external sharing and guest access reviewed?Known sharing settings, guest lists or access-review evidence appropriate to the environment.
Who owns email-security configuration and suspicious-account escalation?A named internal/provider responsibility and escalation path.
Which business devices are managed, and who is responsible for access when a device is lost or reassigned?Current device records and a repeatable support/security process.
Which Microsoft 365 data is covered by the firm’s recovery approach?Documented scope, exclusions and ownership.
When was important data last restored successfully?Recent restore/test evidence for the actual data or scope tested.
Where is current administration and recovery documentation stored?A location accessible to authorized people during an incident.
Who owns unresolved access, security or recovery gaps?A named owner and next action rather than an open-ended issue list.

Questions for your IT provider

Turn an “unknown” into an evidence request

  • Show us who has privileged access today and why each assignment exists.
  • Walk us through what happens to Microsoft 365 and application access when someone leaves.
  • Show us how guest/external access is reviewed for the way our firm collaborates.
  • Explain what is included in our recovery approach and show evidence from a recent restore or recovery test.
  • Show us where current administration, escalation and recovery documentation is maintained.

Technical reference notes

Primary Microsoft guidance behind several review prompts

Scallex uses these references to bound the checklist. Microsoft documentation remains the authority for current product behaviour and configuration requirements.

Technical references reviewed August 17, 2026.

Next step

Want help reviewing what the scorecard uncovered?

Use the Free IT Assessment when access, recovery or ownership questions need a broader business IT review. The assessment is a separate next step from this ungated resource.