Compromised email accounts
A weak, reused or stolen password can give an attacker access to years of correspondence, invoices and client details.
A focused, practical review for independent estate and letting agencies — looking at the Microsoft 365 controls that can contribute to compromised accounts, email fraud and payment fraud.
Free initial health check · read-only review · no obligation
Estate and letting agencies handle sensitive correspondence, client information, deposits and payment instructions through email every day. Many useful security improvements come down to ordinary configuration and account hygiene rather than anything exotic.
A weak, reused or stolen password can give an attacker access to years of correspondence, invoices and client details.
An attacker with access to a mailbox may monitor a transaction and intervene when payment instructions are being exchanged.
Hidden mailbox rules can redirect or hide correspondence without being obvious to the person using the account.
Where multi-factor authentication is not consistently enforced, a leaked password may be enough to access an inbox.
Accounts sometimes have more administrative access than their role requires, increasing the potential impact of compromise.
Sharing and access settings can sometimes make documents, sites or information available more widely than intended.
A focused, read-only review of your Microsoft 365 tenant, designed specifically for small independent agencies. It is intended to be useful on its own, whether or not you work with Uriel Security afterwards.
A focused set of checks aimed at common, actionable Microsoft 365 weaknesses in smaller organisations. The assessment is practical rather than exhaustive.
Whether multi-factor authentication is enabled and consistently enforced across staff and administrative accounts.
Who holds administrative access, and whether that access is broader than the role requires.
Baseline Microsoft 365 security settings compared with sensible small-business expectations.
Mailbox and transport rules that could silently redirect, hide or alter correspondence.
Sign-in activity, legacy authentication and other indicators of weaker account hygiene where available.
How documents, sites and other resources can be shared outside the organisation.
Whether Microsoft security defaults or Conditional Access are in place and sensible for the available licence.
A general view of configuration health, with anything unusual or unnecessarily exposed called out.
Additional checks relevant to how a small agency actually uses Microsoft 365 day to day.
This is a focused review, not a penetration test or exhaustive audit. It is designed to surface practical issues worth addressing, not to claim that every possible weakness has been found.
No raw technical export and no wall of jargon. The aim is to give an owner or director a clear view of what matters and what to do next.
You can take the findings to your existing IT provider, address them internally, or discuss next steps with Uriel. The report is yours to use.
Uriel Security is a specialist consultancy run by an experienced cybersecurity professional. You deal directly with the person carrying out the assessment.
You deal directly with the person carrying out the assessment.
Recommendations are sized to what a small agency can realistically act on.
Findings are written for business owners and directors, not just technical teams.
The free health check is intended to be useful in its own right.
Uriel Security is run by [YOUR NAME], a cybersecurity professional with a background spanning cybersecurity and incident management across financial services, government organisations, SMEs, operational technology, aviation and housing.
Postgraduate cybersecurity qualification.
Professional cloud infrastructure security certification.
Experience across financial services, government organisations, SMEs, operational technology, aviation and housing.
MSP engineering experience supporting diverse organisations, technology environments and operational needs.
Experience includes work with organisations such as Arhag Housing, Gateway Housing, River Clyde Homes, Cartrefi Conwy and Hawkins\Brown.
The breadth comes from working in an MSP environment, supporting different clients and operating environments across security, infrastructure and incident response.
Designed to take as little of your time as possible.
Fill in the short form. We will get back to arrange access and answer any questions.
A read-only review is carried out against the checks described above.
You receive a plain-English report with findings, impact and recommended actions.
Yes. There is no charge for the initial Microsoft 365 Security Health Check and no obligation to purchase anything afterwards.
Yes, temporary read-only access is needed to review the configuration properly. Access should be limited to what is required for the assessment and can be revoked by you.
Yes. The health check is a review only. No settings, permissions or configuration are changed as part of the assessment.
Arranging access and providing context typically takes around 15–20 minutes. The review itself is carried out separately and you will be told roughly when to expect the report.
No. Any recommended changes are left for you or your IT provider to action, unless you separately ask Uriel Security to help with implementation.
You receive the written report and can act on it yourself, through your existing IT provider, or with further help from Uriel Security if you choose.
Yes. The report is written so that you can take the findings to your existing IT provider. Uriel can also discuss the recommendations with you if that is useful.
No. The health check is designed to be useful on its own. There is no expectation to engage Uriel Security for further work.
Tell us a little about your agency and we will be in touch to arrange the review.
Uriel Security works remotely with independent agencies across the UK.