Compromised email accounts
A weak, reused or stolen password can give an attacker access to years of correspondence, invoices and client details.
A short, practical security review for independent estate and letting agencies — focused on the everyday weaknesses that can contribute to compromised accounts, email fraud and payment fraud.
Free initial health check · read-only review · no obligation
Estate and letting agencies handle sensitive correspondence, client information, deposits and payment instructions through email every day. Many useful security improvements come down to ordinary configuration and account hygiene rather than anything exotic.
A weak, reused or stolen password can give an attacker access to years of correspondence, invoices and client details.
An attacker with access to a mailbox may monitor a transaction and intervene when payment instructions are being exchanged.
Hidden mailbox rules can redirect or hide correspondence without being obvious to the person using the account.
Where multi-factor authentication is not consistently enforced, a leaked password may be enough to access an inbox.
Accounts sometimes have more administrative access than their role requires, increasing the potential impact of compromise.
Sharing and access settings can sometimes make documents, sites or information available more widely than intended.
A focused, read-only review of your Microsoft 365 tenant, designed specifically for small independent agencies. It is intended to be useful on its own, whether or not you work with Uriel Security afterwards.
A focused set of checks aimed at common, actionable Microsoft 365 weaknesses in smaller organisations. The assessment is practical rather than exhaustive.
Whether multi-factor authentication is enabled and consistently enforced across staff and administrative accounts.
Who holds administrative access, and whether that access is broader than the role requires.
Baseline Microsoft 365 security settings compared with sensible small-business expectations.
Mailbox and transport rules that could silently redirect, hide or alter correspondence.
Sign-in activity, legacy authentication and other indicators of weaker account hygiene where available.
How documents, sites and other resources can be shared outside the organisation.
Whether Microsoft security defaults or Conditional Access are in place and sensible for the available licence.
A general view of configuration health, with anything unusual or unnecessarily exposed called out.
Additional checks relevant to how a small agency actually uses Microsoft 365 day to day.
This is a focused review, not a penetration test or exhaustive audit. It is designed to surface practical issues worth addressing, not to claim that every possible weakness has been found.
No raw technical export and no wall of jargon. The aim is to give an owner or director a clear view of what matters and what to do next.
Uriel Security is a one-person consultancy. That is deliberate: the person you speak to is the person carrying out the assessment.
No account manager between you and the assessment.
Recommendations are sized to what a small agency can realistically act on.
Findings are written for business owners and directors, not just technical teams.
The free health check is intended to be useful in its own right.
Uriel Security is run by a single practitioner with a background spanning cybersecurity and incident management. Replace the placeholders below with the exact wording you want published before launch.
Replace: exact certification title and date achieved.
Microsoft Certified: Azure Fundamentals. Replace: date achieved.
Replace: degree title, institution and year.
Replace: brief, accurate description of relevant experience.
Designed to take as little of your time as possible.
Fill in the short form. We will get back to arrange access and answer any questions.
A read-only review is carried out against the checks described above.
You receive a plain-English report with findings, impact and recommended actions.
Yes. There is no charge for the initial Microsoft 365 Security Health Check and no obligation to purchase anything afterwards.
Yes, temporary read-only access is needed to review the configuration properly. Access should be limited to what is required for the assessment and can be revoked by you.
Yes. The health check is a review only. No settings, permissions or configuration are changed as part of the assessment.
Arranging access and providing context typically takes around 15–20 minutes. The review itself is carried out separately and you will be told roughly when to expect the report.
No. Any recommended changes are left for you or your IT provider to action, unless you separately ask Uriel Security to help with implementation.
You receive the written report and can act on it yourself, through your existing IT provider, or with further help from Uriel Security if you choose.
No. The health check is designed to be useful on its own. There is no expectation to engage Uriel Security for further work.
Tell us a little about your agency and we will be in touch to arrange the review.
Uriel Security works remotely with independent agencies across the UK.