You May Already Own Cybersecurity Tools – Are They Properly Configured?

Sep 2, 2026 | Audit and Accounting, Advisory and Business

You May Already Own Cybersecurity Tools - Are They Properly Configured?

Security value is not created by licensing alone.

Many organisations already pay for security capabilities through existing platforms such as Microsoft 365, cloud services, endpoint protection tools or firewall subscriptions. However, these capabilities are often not fully configured, monitored or aligned to the organisation’s risk profile.

This creates a dangerous gap between perceived protection and actual protection. Management may assume that security is covered because the organisation owns a tool, while critical features such as multi-factor authentication, conditional access, audit logging, alert monitoring or secure sharing controls are not properly enabled.

Why this matters

Before investing in additional tools, organisations should understand whether they are using existing capabilities effectively. Proper configuration, ownership and monitoring can often produce immediate improvement without significant new spend.

What management should consider

  • Review multi-factor authentication and conditional access coverage.
  • Check external sharing settings and data exposure risks.
  • Confirm audit logging, alerting and retention settings.
  • Review mailbox forwarding rules and suspicious email configurations.
  • Assess endpoint protection deployment and monitoring.
  • Compare configuration settings against a recognised baseline.
  • Assign responsibility for ongoing review of security settings and alerts.

Common pitfalls to avoid

Assuming a licence means a control is active.; Enabling features without monitoring alerts or exceptions.; Not assigning ownership for configuration drift..

Key takeaway

Licensing does not equal security. Organisations should validate whether existing tools are configured, monitored and governed effectively.

Practical first step

Review existing Microsoft 365 or cloud security settings before procuring additional tools. Configuration uplift often creates immediate value.

How Nexia SAB&T can assist

Nexia SAB&T can assist with Microsoft 365 security reviews, cloud security posture reviews, identity and access reviews and email security configuration assessments.

Author details: Rob Galetti | IT Audit and Cybersecurity | Nexia SAB&T

Date: 2 September 2026

Recent Articles

Cyber Resilience Is Becoming a Regulatory Expectation

Cyber Resilience Is Becoming a Regulatory Expectation

Regulators increasingly expect organisations to prevent, withstand, respond to and recover from cyber incidents. Cybersecurity has shifted from being a technical best practice to a governance and regulatory expectation, especially in sectors that provide critical...

Read More 9
Five Cyber Questions Every Audit Committee Should Ask

Five Cyber Questions Every Audit Committee Should Ask

Good cyber oversight starts with clear questions about risk, resilience and accountability. Cybersecurity reporting is often too technical for audit committees and boards. Dashboards may show alerts, vulnerabilities or system activity, but still fail to answer the...

Read More 9
You Can Outsource IT, But Not Cyber Accountability

You Can Outsource IT, But Not Cyber Accountability

Service providers may operate controls, but management remains accountable for understanding the risk. Many organisations rely on managed service providers, cloud providers, software vendors, payroll providers and outsourced IT support. Outsourcing can provide...

Read More 9
Your Tax Deadlines for August 2026

Your Tax Deadlines for August 2026

07 August: PAYE submissions and payments 25 August: VAT manual submissions and payments 28 August: Excise duty payments 31 August: VAT electronic submissions and payments PIT Provisional Tax payments (first provisional tax payment) CIT Provisional Tax payments where...

Read More 9