Compromised email accounts
A weak, reused or stolen password can give an attacker access to years of correspondence, invoices and client details.
A focused, practical review for independent estate and letting agencies — looking at the Microsoft 365 controls that can contribute to compromised accounts, email fraud and payment fraud.
Free initial health check · read-only review · no obligation
Estate and letting agencies handle sensitive correspondence, client information, deposits and payment instructions through email every day. Many useful security improvements come down to ordinary configuration and account hygiene rather than anything exotic.
A weak, reused or stolen password can give an attacker access to years of correspondence, invoices and client details.
An attacker with access to a mailbox may monitor a transaction and intervene when payment instructions are being exchanged.
Attackers who gain access often quietly change how mail behaves in ways that are hard to notice without a proper review.
Where multi-factor authentication is not consistently enforced, a leaked password may be enough to access an inbox.
Accounts sometimes have more administrative access than their role requires, increasing the potential impact of compromise.
Sharing and access settings can sometimes make documents, sites or information available more widely than intended.
A focused, read-only review of your Microsoft 365 tenant, designed specifically for small independent agencies. It is intended to be useful on its own, whether or not you work with Uriel Cyber afterwards.
A focused set of checks aimed at common, actionable Microsoft 365 weaknesses in smaller organisations. The assessment is practical rather than exhaustive.
Whether multi-factor authentication is enabled and consistently enforced across staff and administrative accounts.
Who holds administrative access, and whether that access is broader than the role requires.
Baseline Microsoft 365 security settings compared with sensible small-business expectations.
Mailbox and transport rules that could silently redirect, hide or alter correspondence.
Sign-in activity, legacy authentication and other indicators of weaker account hygiene where available.
How documents, sites and other resources can be shared outside the organisation.
Whether Microsoft security defaults or Conditional Access are in place and sensible for the available licence.
A general view of configuration health, with anything unusual or unnecessarily exposed called out.
Additional checks relevant to how a small agency actually uses Microsoft 365 day to day.
This is a focused review, not a penetration test or exhaustive audit. It is designed to surface practical issues worth addressing, not to claim that every possible weakness has been found.
No raw technical export and no wall of jargon. The aim is to give an owner or director a clear view of what matters and what to do next.
You can take the findings to your existing IT provider, address them internally, or discuss next steps with Uriel. The report is yours to use.
The health check itself is free and stands on its own. If it turns up something worth fixing, work is quoted as a fixed fee agreed up front — never open-ended hourly billing.
Enforce multi-factor authentication across staff and admin accounts, with sensible Conditional Access (or Security Defaults on smaller licences).
From £250Review and remove suspicious forwarding or transport rules, and tighten external sharing defaults.
From £200Right-size administrative access so accounts hold no more privilege than their role needs.
From £150Every finding from your health check addressed as one bundled engagement, at a lower combined rate than booking each fix separately.
From £550Exact pricing depends on what the health check finds and your licence tier — you will always see the fixed fee before any work begins. An optional low-cost quarterly check-in is also available once fixes are in place, to confirm nothing has drifted back.
Uriel Cyber is a specialist consultancy run by an experienced cybersecurity professional. You deal directly with the person carrying out the assessment.
You deal directly with the person carrying out the assessment.
Recommendations are sized to what a small agency can realistically act on.
Findings are written for business owners and directors, not just technical teams.
The free health check is intended to be useful in its own right.
Uriel Cyber is run by Agbalagbi, a cybersecurity professional with a background spanning cybersecurity and incident management across financial services, government organisations, SMEs, operational technology, aviation and housing.
Postgraduate cybersecurity qualification.
Professional cloud infrastructure security certification.
You deal directly with Agbalagbi — the person carrying out your security review.
Experience includes work with organisations such as Arhag Housing, Gateway Housing, River Clyde Homes, Cartrefi Conwy and Hawkins\Brown.
The breadth comes from working in an MSP environment, supporting different clients and operating environments across security, infrastructure and incident response.
With a background in cybersecurity and incident management, gained through working in an MSP as an engineer, I’ve supported organisations across a wide range of sectors — giving me the breadth of experience to understand different risks, pressures and operational environments.
Designed to take as little of your time as possible.
Fill in the short form. We will get back to arrange access and answer any questions.
A read-only review is carried out against the checks described above.
You receive a plain-English report with findings, impact and recommended actions.
Yes. There is no charge for the initial Microsoft 365 Security Health Check and no obligation to purchase anything afterwards.
Yes, temporary read-only access is needed to review the configuration properly. Access should be limited to what is required for the assessment and can be revoked by you.
Yes. The health check is a review only. No settings, permissions or configuration are changed as part of the assessment.
Arranging access and providing context typically takes around 15–20 minutes. The review itself is carried out separately and you will be told roughly when to expect the report.
No. Any recommended changes are left for you or your IT provider to action, unless you separately ask Uriel Cyber to help with implementation.
You receive the written report and can act on it yourself, through your existing IT provider, or with further help from Uriel Cyber if you choose.
Yes. The report is written so that you can take the findings to your existing IT provider. Uriel can also discuss the recommendations with you if that is useful.
No. The health check is designed to be useful on its own. There is no expectation to engage Uriel Cyber for further work.
You will get a fixed-fee quote before any work begins — see pricing for typical ranges. You are always free to take the findings to your existing IT provider instead.
Tell us a little about your agency and we will be in touch to arrange the review.
Uriel Cyber works remotely with independent agencies across the UK.