Microsoft Cloud Security & Independent Technical Assurance

Independent validation of Microsoft 365 and Azure security controls, with penetration testing available as part of a complete engagement.

Metis Security is an independent UK cybersecurity consultancy focused on determining whether your Microsoft cloud security controls genuinely work, not just whether they exist.

Many organisations invest heavily in Microsoft security capabilities. Fewer have independent technical assurance that those controls are properly enforced and operating as intended. We specialise in validating control effectiveness across Microsoft 365 and Azure environments, providing evidence-based clarity on configuration reality and risk exposure.

Alongside Microsoft cloud security assessments, we deliver penetration testing and targeted remediation support to ensure identified weaknesses are properly addressed.

Engage directly with experienced technical leadership for precise, defensible answers about your real security posture.

Our Difference

Why Customers Choose Us

DIRECT SENIOR TECHNICAL DELIVERY

Engage directly with an experienced security professional with over two decades of senior consultancy experience. You work with the person performing the assessment — not a layered delivery structure involving sales, scoping and separate technical teams.

END-TO-END ENGAGEMENT

From initial discovery through assessment, reporting and implementation support, engagements are structured to deliver clear outcomes — not standalone reports that leave you to interpret or action findings alone.

FIXED SCOPE. CLEAR OUTCOME.

Where appropriate, engagements are defined with fixed scope and agreed outcomes. The focus is on delivering measurable improvements and defensible conclusions — not open-ended consultancy hours. 

MICROSOFT CLOUD SPECIALIST FOCUS

Focused expertise across Microsoft 365, Entra and Azure ensures depth rather than breadth. Engagements are grounded in real-world control validation and practical understanding of Microsoft security architecture.

CLEAR, PRACTICAL COMMUNICATION

Findings are delivered in precise, plain English — technically rigorous yet concise. The objective is clarity and actionability, not lengthy reports filled with unnecessary jargon.

PROFESSIONAL AND CONSTRUCTIVE ENGAGEMENT

Security assessments can be challenging. Engagements are conducted with respect for both technical and business realities, ensuring findings are delivered constructively and collaboratively.

DIRECT SENIOR TECHNICAL DELIVERY

Engage directly with an experienced security professional with over two decades of senior consultancy experience. You work with the person performing the assessment — not a layered delivery structure involving sales, scoping and separate technical teams.

END-TO-END ENGAGEMENT

From initial discovery through assessment, reporting and implementation support, engagements are structured to deliver clear outcomes — not standalone reports that leave you to interpret or action findings alone.

FIXED SCOPE. CLEAR OUTCOME.

Where appropriate, engagements are defined with fixed scope and agreed outcomes. The focus is on delivering measurable improvements and defensible conclusions — not open-ended consultancy hours. 

MICROSOFT CLOUD SPECIALIST FOCUS

Focused expertise across Microsoft 365, Entra and Azure ensures depth rather than breadth. Engagements are grounded in real-world control validation and practical understanding of Microsoft security architecture.

CLEAR, PRACTICAL COMMUNICATION

Findings are delivered in precise, plain English — technically rigorous yet concise. The objective is clarity and actionability, not lengthy reports filled with unnecessary jargon.

PROFESSIONAL AND CONSTRUCTIVE ENGAGEMENT

Security assessments can be challenging. Engagements are conducted with respect for both technical and business realities, ensuring findings are delivered constructively and collaboratively.

Our Expertise

Solutions For Business Challenges

Microsoft 365 Security Assessment

Independent validation of identity, access, data protection and monitoring controls across your Microsoft 365 tenant. We confirm what is working, identify where controls fall short, and provide clear, prioritised guidance on what to address first.

Learn More

Azure Security Assessment

Evidence-led review of your Azure security architecture, covering identity boundaries, network exposure, governance enforcement and detection readiness. The focus is whether your controls operate as intended under real-world conditions.

Learn More

Penetration Testing

Structured adversarial testing of Internet-facing infrastructure and applications, using real-world attack techniques to identify genuine exploitability rather than theoretical risk. Delivered as a standalone engagement or alongside a cloud security assessment.

Learn More

Understand Your Real Microsoft Cloud Risk

An independent, practical discussion about whether your security controls are genuinely effective — and where your highest exposure may lie.
What clients and colleagues say

Testimonial

  • Joel S
    Global Business Unit Head, NCC Group
  • David is one of the rare few, he is highly technical yet has the ability to relay technical risk fluently in language that C level can comprehend. He has a fantastic understanding of risk and this is demonstrated in the way he provides sensible risk ratings as part of his deliverables.

    He is a very professional individual, understands tactical and strategic drivers, someone it was a pleasure to work alongside as a client.

    Steven K
    Senior Cyber RIsk Manager, Deloitte
  • Dave S
    Global Practice Lead Full Spectrum Attack Simulation, NCC Group
  • Stefan S
    Head of Security Assurance
  • David is the consummate professional, he is passionate about pen testing. Over the past two years David has not only been our CHECK team leader delivering numerous complex health checks but has also provided advice and consultancy on a regular basis to me, my team and the project.
    I would have no hesitation in recommending David as a CHECK Team leader

    Denis S
    Head of Security Services
  • Simon M
    Internal Client, BT
  • Dan H
    Director, Secure Source
  • David has the ability to turn complex plans and documentation into easy-to-follow instructions within relatively short timescales. He remains professional and approachable throughout each engagement and I feel safe in the knowledge that David knows exactly what he is doing.

    His communications are always clear, timely and thorough which makes working with him a pleasure. I too have no reservations whatsoever in recommending David should he ever decide to make tracks elsewhere. He is an asset to be proud of and a force to be reckoned with!

    Andy C
    Account Director, Secureworks
  • David was retained to provide expert advice to myself and the Head of Security on all Penetration Testing matters. This included scoping, organisation, interpretation of results and recommendations for the appropriate countermeasure or remediation.

    David’s level of skill is very high and he is able to take the sometimes complex results and reinterpret them into a more user-friendly format for non-technical management.

    I would have no hesitation in hiring David for any CHECK or Penetration Testing work that needed doing and is a considerable asset to his current employer.

    Phil T
    CLAS Consultant
  • Kenneth DS
    Manager Security Assessment Services, IBM Internet Security Systems
Case Studies

How We Helped Customers

Our endorsed skills

Qualifications & Certifications

We believe in constant training and the maintenance of both our technical and consultative skills and this can be best presented to our clients through formal qualifications, a selection of which are presented below.

Blog Posts & Industry Insights

Recent News

Discuss Your Microsoft Security Posture

If you are responsible for security decisions and want an independent view of whether your Microsoft environment is genuinely secure, a direct conversation with David is the most practical starting point.