Microsoft 365 & Cyber Security Consultant · Christchurch NZ · PureLayer FREEMicrosoft 365 exposure check for NZ nonprofits & small businesses. No passwords needed.Book your free security check
Get in touch

You know who manages your IT. Do you know who still has access?

Don't assume. Verify. I independently check your Microsoft 365 security: who has access, whether MFA and security controls are actually enforced, and what risk your organisation still owns. For NZ nonprofits and small businesses.

Free exposure check: outside-in email and domain checks, a 30-minute call, and your top 3 risks in writing. No passwords or access needed.

Full security assessment (paid): the complete internal review below, with evidence and a remediation plan.

Full security assessment: what you receive

A complete account and privilege review
A clear view of responsibilities outside provider scope
Inactive and orphaned accounts identified
Administrative access mapped and risk rated
A security design and prioritised remediation plan
Every finding explained and documented in full
44%¹
of large NZ businesses surveyed suffered a successful cyber-attack in the previous 12 months.
118%²
rise in direct financial losses reported to NZ's NCSC in Q3 2025 ($12.4m, up from $5.7m the previous quarter).
99%+³
of identity-based attacks can be blocked by MFA, per Microsoft's Digital Defense Report 2025.
¹ Kordia NZ Cyber Security Report 2026 ↗ ² NCSC Quarter 3 Report 2025 ↗ ³ Microsoft Digital Defense Report 2025 ↗
Most NZ businesses find the problem after something has gone wrong. The ones that act early avoid becoming the next case study.
Find hidden Microsoft 365 risk →
Device governance
Licensing strategy
Vendor evaluation
Microsoft 365 and Entra ID
Identity governance
IPP 3A
ISO 27001 aligned
No lock in
NZ specialist
Everything yours to keep
Device governance
Licensing strategy
Vendor evaluation
Microsoft 365 and Entra ID
Identity governance
IPP 3A
ISO 27001 aligned
No lock in
NZ specialist
Everything yours to keep
Typically outside the scope of a standard managed service agreement

Infrastructure support is covered.
Governance oversight is not.

Standard managed service agreements keep systems available. Ownership of identity, security decisions, and organisational risk often remains undefined.

Standard MSP scope
Outside standard MSP scope
Devices and software staying online
Former staff accounts still active in the system
Microsoft 365 email and helpdesk support
Who actually has admin access right now and why
Backups being configured
Whether backups have ever actually been tested
Software updates and patching
Brand impersonation and domain monitoring
Day to day operational issues
Governance documentation and director liability exposure

Access sprawl across MSPs and third parties is one of those risks that only becomes visible when something goes wrong. Good to see someone building a practice specifically around that gap.

Laurent Halimi Founder and CEO, CYBERR

How PureLayer works

One operating model.
Two distinct layers.

Strategic layer
PureLayer
Independent security oversight.
Security architecture designed around the organisation before remediation begins. Identity, endpoint protection, backup, and cloud controls are selected and validated against business risk and compliance requirements.
Identity governance Risk remediation Security architecture Cloud configuration and implementation Compliance advisory Device governance Director visibility Transition and recovery ISO 27001 aligned architecture
Infrastructure provider
Essential infrastructure management.
Monitoring, patching, backups, and helpdesk remain essential services. PureLayer complements that work with independent oversight and can take responsibility for this layer directly when required.
Monitoring Patching Backups Microsoft 365 Device management

Source: MSP Trends 2026, Worksent, March 2026

When a provider relationship ends

When a provider relationship ends, organisations can be left without working backups, endpoint protection, complete documentation, or clear ownership. PureLayer restores visibility, designs the remediation plan, and carries out the technical work directly. Vendor relationships and approvals are managed throughout so the right controls return in the right order.

Identity and access governance

Find out who actually has
the keys to the business

01
Every account reviewed
Every user, administrator, service account, and shared mailbox assessed. Inactive identities, excessive privilege, Entra ID roles, and conditional access are reviewed.
A verified view of every identity and privilege
02
Systems and ownership mapped
Platforms, providers, credentials, and responsibilities documented in one organisational record.
Clear ownership across the environment
03
Prioritised remediation plan
Authentication, email security, and backup improvements defined in the order that matters most.
Practical direction based on business risk
04
Documentation yours to keep
Decisions, controls, responsibilities, and next steps documented in full. No lock in.
Knowledge remains with the organisation
Security architecture hardening

The uplift that closes
every open door.

Once the gaps are understood, each control is strengthened in sequence. The work covers identity, cloud configuration, devices, protection, recovery, and staff capability, aligned with the control areas ISO 27001 expects.

01
Identity and access
Microsoft Entra ID configured correctly. MFA enforced, administrator roles reviewed, and privilege reduced to what each person needs.
Identity controls applied consistently
02
Cloud configuration
Microsoft 365 settings reviewed across mail flow, domain records, conditional access, and licensing, then configured to match how the organisation operates.
Configuration matched to the organisation
03
Device management
Microsoft Intune brings devices under consistent policy, with security settings applied and monitored centrally.
Consistent control across every enrolled device
04
Endpoint protection
Microsoft Defender for Business deployed across enrolled devices to detect malware, ransomware, and unusual activity.
Endpoint protection working across the fleet
05
Firewall and network
Firewall and network settings reviewed, documented, and hardened where controls are missing or no longer appropriate.
Network controls verified
06
Backup and recovery
Backup implemented for email, files, and Teams content, kept separate from the live environment and tested so recovery is possible when needed.
Recovery designed and verified
07
Password management
A password manager introduced across the organisation, replacing exposed or shared records with a controlled vault.
Secure handling of shared credentials
08
Staff training
Practical training delivered through a private digital hub with guided learning, quick references, and completion tracking so the new controls hold in daily work.
Staff understand the controls they use
09
Ongoing visibility
Microsoft Secure Score, audit logging, alerting, and Entra risk signals configured to provide a continuing view of the environment.
Ongoing visibility after the uplift
Ongoing threat advisory response

When a vendor flags a threat,
someone actually checks it.

Insurers, vendors, and CERT NZ issue security advisories constantly. PureLayer assesses what applies to the organisation, checks the actual environment, and gives a clear response based on evidence.

01
Advisory assessed
The notification is mapped against the organisation's systems, services, and infrastructure to establish whether it applies.
Relevance established before action begins
02
Exposure verified
Headers, DNS records, ports, versions, and configurations are checked directly to confirm the exposure.
An answer supported by evidence
03
Ownership resolved
Where ownership or purpose is unclear, the gap is escalated and resolved before the advisory is closed.
Every affected system accounted for
04
Response documented
What was checked, what was found, and what was done is recorded for the board, insurer, or auditor.
A clear record of the decision and response
What actually changes

Before the engagement.
After the engagement.

Microsoft 365 environment before and after a PureLayer governance engagement Two panels showing the state of a Microsoft 365 environment before and after engagement. Before Typical Microsoft 365 environment After Post governance engagement User accounts Unknown. Never fully audited. Former staff access Multiple accounts still active Admin access Shared. Undocumented. Untested. MFA enforcement Not enforced for any account Email authentication SPF, DKIM, DMARC absent Governance documentation None exists Identity Secure Score Typically 25% or below User accounts Every account verified and documented Former staff access All identified, staged for closure Admin access Named owners. Privileges mapped. MFA enforcement Enforced. Conditional access defined. Email authentication SPF, DKIM, DMARC configured Governance documentation Full framework. Organisation owns it. Identity Secure Score Remediation plan in place
What changes after the assessment

Organisational exposure
identified and owned.

01
Former staff accounts resolvedFormer staff accounts are identified, documented, and prepared for closure.
02
Responsibility gaps exposedEvery responsibility outside standard provider scope is named, prioritised, and assigned.
03
Ownership establishedSystems, accounts, credentials, and provider relationships are documented with clear owners.

What I look for

The gaps that usually get missed.

These are the gaps I check first. They're easy to miss, and costly when someone else finds them before you do.

Admin access nobody can account for.

Former IT providers, ex-staff and forgotten partner accounts that still hold the keys to your Microsoft 365, often with no record of who has what.

Admin access
Security you've paid for but never switched on.

Many Microsoft 365 licences include MFA enforcement and Conditional Access. Paying for them doesn't mean they're on.

Licensing
Dashboards that say "protected" when they're not.

A portal can report a policy as applied when the device says otherwise. I check the device itself, not just the dashboard.

Device security
A copycat website stealing customer payments.

For one client, a fake site outranked the real business in search and harvested customer payment details. I traced it, built the evidence and got it taken down.

Brand impersonation · client case
Check yours for free →
LF

Who you'll work with

Hi, I'm Lee.

I'm a Microsoft security and identity consultant based in Christchurch, working with organisations across New Zealand. I spend my days inside Microsoft 365, Entra ID, Intune and Defender, finding what's been missed and fixing it properly.

Earlier in my career I delivered enterprise HR, payroll and ERP systems for large organisations in Australia, New Zealand and the UK, including Telstra, Air New Zealand, British Telecom, Sky TV in Scotland and the University of Sydney, where I designed the access-control framework for the HR and payroll system. I then took time out to raise my family, and returned in 2024 through formal cybersecurity retraining, founding PureLayer in 2025. Today I work hands-on in Microsoft 365, Entra ID, Intune and Defender for NZ nonprofits and small businesses that don't have a security team of their own. Everything I do is documented, and the documentation is yours to keep.

Christchurch basedWorks NZ-wideISO 27001 alignedNZ Privacy Act 2020Postgrad Cybersecurity, UC (in progress)

Client reviews

★★★★★
5.0 · Google Reviews
★★★★★

"Absolutely outstanding service. Lee went above and beyond to help us resolve a serious issue, and did it quickly, professionally, and without any fuss. What really stood out was the level of care and attention to detail and genuinely wanted the best outcome for us. Communication was clear the whole way through, and handled everything with confidence and expertise, which gave us a lot of peace of mind during a stressful situation. It's rare to come across someone this reliable, I wouldn't hesitate to recommend Lee to anyone needing help in this space."

G
Google Review
Verified client · 5 stars
★★★★★

"Outstanding service from Lee and she's very knowledgeable on how to protect businesses from cyber threats, definitely recommended!"

W
Will · Local Guide
Verified client · 5 stars · 11 weeks ago
★★★★★

"Lee is amazing and very knowledgeable. Highly recommend."

M
Marie Healy
Verified client · 5 stars
Start the conversation

Start with
an assessment.

Share your name and email to begin. Nothing changes without your approval.

Responds within 24 hours, usually the same day.
All engagements are confidential.
Information handled under the NZ Privacy Act 2020.
Or email directly: lee@purelayer.co.nz

No obligation. Lee responds within 24 hours.

Thanks, that is through to Lee.
She will be in touch within 24 hours.
1