Skip to content

“We’re running on Microsoft, So we’re safe…” It can be a dangerous assumption

Secure At Work
By Kenneth van Surksum |
Woman behind a laptop using MS365

“Our security is under control. After all, we’re using a secure, reliable, and trusted platform.” It’s a logical assumption. Microsoft 365 is one of the world’s most mature and secure cloud platforms, and Microsoft invests billions in cybersecurity every year. “So everything is fine. We’re safe.”

That’s what the Dutch police thought too…

A secure platform is not automatically the same as a secure organization. This became clear when it emerged in early 2026 that, during a cyber incident affecting the Dutch police*, not all of the recommended security measures within their Microsoft 365 environment had been implemented. As a result, the impact of the attack was greater than necessary, and recovery took longer than it would have if the environment had been fully configured in accordance with Microsoft’s security recommendations. In hindsight, the police acknowledged that part of the damage could potentially have been prevented or significantly reduced had the configuration been fully aligned with the recommended security baseline.

Not because Microsoft failed. But because the way the environment had been configured and managed ultimately determined the actual level of risk. And that is precisely the challenge many CISOs, IT managers, and even managed service providers MSPs face every day. If it can happen to the police, could it happen to your organization? The answer is: probably yes.

A Microsoft 365 environment is never truly finished

Anyone responsible for information security in Microsoft 365 knows that an environment is rarely, if ever, in a final state. There is no point at which you can confidently say, “This is secure now, and it will stay that way.” New employees join the organization. Roles change. External parties are granted access. Projects require temporary exceptions. At the same time, Microsoft continuously evolves the platform by introducing new features, settings, and security standards that can all affect your security posture.

Individually, these are all logical and necessary developments. Together, however, they mean that the environment is constantly changing. So how do you stay in control? No matter how carefully the environment was originally configured, that initial setup gradually becomes a historical reference rather than a reflection of today’s reality.

When does trust quietly turn into risk?

Most organizations start their Microsoft 365 journey with a well-defined set of security principles. Decisions are made about identity and access management, multi-factor authentication (MFA), external access, and administrative privileges. These decisions are often made with the help of external experts and according to industry best practices. At that point, confidence is entirely justified. But then something much less visible begins.

But then something much less visible begins.

Small changes, temporary exceptions, and practical workarounds start to accumulate.
A supplier receives additional permissions to complete a migration. An administrator keeps an account active longer than planned because other systems still depend on it.
A newly introduced Microsoft feature is enabled without a full reassessment of the existing security policies.

None of these actions is problematic on its own. In fact, they’re often necessary to keep the business running. Together, however, they create something entirely different: a gradual drift away from the original security baseline.

And that’s exactly where it becomes dangerous

A Microsoft 365 environment rarely becomes insecure because of a single mistake.
Risk almost always develops unnoticed through the accumulation of small deviations that nobody individually considers significant. Collectively, however, they can create a serious security exposure.

How do you explain that to an executive team that believes everything is secure?

For CISOs, this often leads to a difficult conversation. On paper, everything appears to be in order. Policies are in place. Monitoring is active. Audits have been completed. Yet a single question from the boardroom can be surprisingly difficult to answer: “If everything was properly secured, how could this still happen?”

The challenge isn’t the technical explanation. It’s the expectation that security is a fixed state. Cloud environments aren’t static—they’re dynamic by nature. The reality is that many organizations still approach security as though it’s a project with a beginning and an end.
Microsoft 365 doesn’t work that way. It’s an environment that changes every day and therefore should be reassessed every day.

Why a point-in-time assessment is no longer enough

Many organizations rely on periodic assessments, audits, or security reviews.
These are valuable tools. But they always describe the past. At the time of the assessment, everything may indeed have been configured correctly. The very next day, that may no longer be true. As soon as changes are introduced, a gap begins to emerge between the validated configuration and the actual production environment. In cloud environments where changes occur daily, that gap can quickly become permanent.

Is it securely configured—or is it still securely configured?

It may seem like a subtle distinction, but it fundamentally changes the way organizations should think about information security. More and more organizations are realizing that maintaining control over Microsoft 365 isn’t primarily about deploying more security tools—even though that’s often the first instinct.

It’s about maintaining visibility. Visibility into changes. Visibility into deviations from the intended security baseline. And the ability to immediately identify when reality no longer matches the original design. Not to blame administrators.But to prevent well-intentioned changes from unintentionally introducing new security risks.

Continuous visibility into the security status of your Microsoft 365 environment

At Secure at Work, that’s exactly what we focus on: continuously providing visibility into the security state of your Microsoft 365 environment against an established security baseline. Not as a one-time snapshot, but as an ongoing comparison against the standard. So organizations no longer have to assume their environment is still configured correctly—they can actually demonstrate it.

One question ultimately remains

If your Microsoft 365 environment were assessed today against the same security standard you relied on when reassuring your executive team…Would it still deliver the same answer?

We’d be happy to start that conversation with you.

*Source used: RTL News / ANP January 23, 2026

Recommended Blogs