Don't assume. Verify. I independently check your Microsoft 365 security: who has access, whether MFA and security controls are actually enforced, and what risk your organisation still owns. For NZ nonprofits and small businesses.
Free exposure check: outside-in email and domain checks, a 30-minute call, and your top 3 risks in writing. No passwords or access needed.
Full security assessment (paid): the complete internal review below, with evidence and a remediation plan.
Standard managed service agreements keep systems available. Ownership of identity, security decisions, and organisational risk often remains undefined.
Access sprawl across MSPs and third parties is one of those risks that only becomes visible when something goes wrong. Good to see someone building a practice specifically around that gap.
Laurent Halimi Founder and CEO, CYBERR
When a provider relationship ends, organisations can be left without working backups, endpoint protection, complete documentation, or clear ownership. PureLayer restores visibility, designs the remediation plan, and carries out the technical work directly. Vendor relationships and approvals are managed throughout so the right controls return in the right order.
Once the gaps are understood, each control is strengthened in sequence. The work covers identity, cloud configuration, devices, protection, recovery, and staff capability, aligned with the control areas ISO 27001 expects.
Insurers, vendors, and CERT NZ issue security advisories constantly. PureLayer assesses what applies to the organisation, checks the actual environment, and gives a clear response based on evidence.
What I look for
These are the gaps I check first. They're easy to miss, and costly when someone else finds them before you do.
Former IT providers, ex-staff and forgotten partner accounts that still hold the keys to your Microsoft 365, often with no record of who has what.
Admin accessMany Microsoft 365 licences include MFA enforcement and Conditional Access. Paying for them doesn't mean they're on.
LicensingA portal can report a policy as applied when the device says otherwise. I check the device itself, not just the dashboard.
Device securityFor one client, a fake site outranked the real business in search and harvested customer payment details. I traced it, built the evidence and got it taken down.
Brand impersonation · client caseWho you'll work with
I'm a Microsoft security and identity consultant based in Christchurch, working with organisations across New Zealand. I spend my days inside Microsoft 365, Entra ID, Intune and Defender, finding what's been missed and fixing it properly.
Earlier in my career I delivered enterprise HR, payroll and ERP systems for large organisations in Australia, New Zealand and the UK, including Telstra, Air New Zealand, British Telecom, Sky TV in Scotland and the University of Sydney, where I designed the access-control framework for the HR and payroll system. I then took time out to raise my family, and returned in 2024 through formal cybersecurity retraining, founding PureLayer in 2025. Today I work hands-on in Microsoft 365, Entra ID, Intune and Defender for NZ nonprofits and small businesses that don't have a security team of their own. Everything I do is documented, and the documentation is yours to keep.
Client reviews
"Absolutely outstanding service. Lee went above and beyond to help us resolve a serious issue, and did it quickly, professionally, and without any fuss. What really stood out was the level of care and attention to detail and genuinely wanted the best outcome for us. Communication was clear the whole way through, and handled everything with confidence and expertise, which gave us a lot of peace of mind during a stressful situation. It's rare to come across someone this reliable, I wouldn't hesitate to recommend Lee to anyone needing help in this space."
"Outstanding service from Lee and she's very knowledgeable on how to protect businesses from cyber threats, definitely recommended!"
"Lee is amazing and very knowledgeable. Highly recommend."
Share your name and email to begin. Nothing changes without your approval.
No obligation. Lee responds within 24 hours.
No obligation. Lee responds within 24 hours.