First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Rapid Cyberattack Assessment Workshop (Remote)
Training

Rapid Cyberattack Assessment Workshop (Remote) — Ransomware Risk Assessment & Security Roadmap

Rapid Cyberattack Assessment Workshop (Remote) is a 2-day remote training workshop for Office 365 and Microsoft 365 customers. It helps identify potential cybersecurity risks related to rapidly spreading attacks, such as ransomware, and provides guidance on Microsoft technologies that can help mitigate those risks.

Timeline 2 daysService owner Mike MackeyOffice 365microsoft 365

What this engagement is

This remote workshop applies IT Partner's rapid cyberattack assessment methodology — originally delivered as a Microsoft partner engagement — to identify elements of your environment that make it prone to rapidly spreading, destructive attacks such as ransomware, and to map current Microsoft security capabilities to the gaps found. It fits customers who may already have been affected by an attack, are unsure about the status of defensive measures, or want a focused risk assessment. The objective is to help customers identify potential cybersecurity risks and gain knowledge about technologies that can help mitigate those risks. An on-site form of the workshop is also available.

Success criteria

01Help customers identify potential cybersecurity risks.
02Help customers gain knowledge about technologies that can help mitigate those risks.
03Identify elements in the customer's IT environment that might make it prone to rapidly spreading and potentially destructive cyberattacks.
04Provide a prioritized and actionable road map for the customer, containing proposed actions based on discovered gaps, considering user impact and implementation cost.

What you receive

Kickoff presentation. Overview of the engagement, covering vision and objectives, requirements, and next steps and actions
A questionnaire about the organization and their approach to exploit mitigation and attack surface reduction, ways of securing privileged access and providing business continuity to mitigate effects of potential cyberattacks, etc.
Assessment tool reports — a set of reports documenting the data-collection findings, reviewed and discussed by IT Partner in the workshop
Rapid cyberattack road map. Actionable road map for addressing discovered gaps, including mapping capabilities of Microsoft technologies and Partner services to assessment findings, taking into account customer's objectives and requirements

How the work unfolds

Webinar 1 -- Kickoff

Kickoff meeting; introduction to the engagement: objectives, flow, responsibilities, and governance; provide and explain preassessment questionnaire to the customer.

Webinar 2

Ensure availability of necessary resources; review the assessment tooling results; begin road map planning; confirmation on the completeness of the questionnaire or tooling output; definition of rapid cyberattacks; review, explain, and discuss questionnaire and tool findings; identify opportunities to leverage already deployed entitlements; perform gap analysis; finalize road map.

Webinar 3

Road map delivery workshop; solution(s) briefing and Technical Readiness presentations; engagement close-out.

Prerequisites

IT Partner's assessment questionnaire and agreed data-collection tooling are prepared and configured before the webinars

Who does what

IT Partner

  • Understand the customer's status vs cyberattacks. Help the customer identify elements in their IT environment that might make it prone to rapidly spreading and potentially destructive cyberattacks (e.g., ransomware attacks).
  • Cyberattacks technical security readiness. Provide guidance, recommendations, and best practices on how to successfully use Microsoft technologies to mitigate security threats that are associated with rapid cyberattacks.
  • Create rapid cyberattack road map. Provide prioritized and actionable road map for the customer, containing proposed actions based on discovered gaps, considering user impact and implementation cost.
  • Map Microsoft technology capabilities and Partner services to assessment findings, taking into account the customer's objectives and requirements.

Your team

  • Information: This includes accurate, timely (within three business days or as mutually agreed upon), and complete information
  • Access to people. This includes access to knowledgeable customer personnel, including business user representatives, and access to funding if additional budget is needed to deliver project scope
  • Support preparation of the agreed data-collection tooling before the webinars

What's not included

Emergency incident response, active threat containment, malware eradication, ransomware negotiation, forensic investigation, or breach notification services are not included in this fixed workshop unless separately scoped.
Hands-on remediation or implementation of roadmap recommendations, such as configuring Microsoft Defender, Conditional Access, identity controls, endpoint hardening, backup changes, or mail security policies, is not included unless purchased as a follow-on project.
Microsoft licensing, third-party security tools, backup products, infrastructure, cloud consumption, or subscription costs are not included.
Penetration testing, red-team exercises, vulnerability scanning beyond the assessment tooling output, phishing simulations, and adversary emulation are not included.
Formal compliance certification, audit attestation, legal advice, regulatory filings, cyber insurance representation, or guarantee of compliance with any specific framework is not included.
Onsite delivery, after-hours work, executive tabletop exercises, custom application security review, network redesign, and managed security monitoring are outside the standard remote workshop scope unless separately agreed.

Limitations & technical notes

!This workshop is a point-in-time assessment and roadmap engagement. Findings depend on the completeness and accuracy of the questionnaire responses, assessment tooling data, and information provided by customer stakeholders.
!The engagement provides guidance and prioritization, but it does not guarantee prevention of ransomware, malware, account compromise, data loss, or other cyberattacks.
!Some recommended mitigations may require additional Microsoft licensing, configuration changes, business approvals, change management, user communications, or follow-on implementation services.
!If the customer is experiencing an active security incident, a dedicated incident response engagement should be initiated in parallel or before this workshop.

Frequently asked questions

What is the Rapid Cyberattack Assessment Workshop (Remote)?

The Rapid Cyberattack Assessment Workshop (Remote) is a 2-day remote training and assessment workshop for Office 365 and Microsoft 365 customers. It helps identify cybersecurity risks related to rapidly spreading attacks such as ransomware and provides guidance on Microsoft technologies that can help mitigate those risks.

Who is this workshop designed for?

This workshop is designed for Office 365 and Microsoft 365 customers who want to assess their exposure to rapid cyberattacks. It is relevant if an organization may already have been affected by an attack, is unsure whether its current defenses are adequate, or wants a structured risk assessment focused on threats such as ransomware.

How long does the Rapid Cyberattack Assessment Workshop take?

The Rapid Cyberattack Assessment Workshop (Remote) is delivered over 2 days. The engagement is structured around remote webinar sessions that include kickoff, assessment review, road map planning, and final road map delivery.

What is included in the workshop?

The workshop includes a kickoff presentation, a preassessment questionnaire, review and discussion of assessment tooling reports, and a rapid cyberattack road map. The road map is intended to be prioritized and actionable, with proposed actions based on discovered gaps and consideration of user impact and implementation cost.

What deliverables will we receive?

Customers receive a kickoff presentation, an organizational questionnaire covering exploit mitigation, attack surface reduction, privileged access, and business continuity practices, assessment tooling reports, and a rapid cyberattack road map. The road map maps Microsoft technology capabilities and Partner services to the assessment findings based on the customer’s objectives and requirements.

What happens during the kickoff webinar?

The kickoff webinar introduces the engagement objectives, flow, responsibilities, and governance. IT Partner also provides and explains the preassessment questionnaire so the customer can supply information needed for the assessment.

What are the prerequisites for the workshop?

IT Partner's assessment questionnaire and agreed data-collection tooling are prepared and configured before the webinars. The customer is also expected to provide accurate and complete information, timely responses, and access to knowledgeable personnel, including business user representatives where needed.

Does the workshop include remediation or implementation of security controls?

The stated scope focuses on assessment, guidance, report review, and road map creation. Implementation of Microsoft security technologies or remediation of discovered gaps is not listed as included, so any hands-on implementation should be confirmed and scoped separately with IT Partner.

Will the workshop stop an active ransomware attack or provide incident response?

No. The workshop helps assess risks and identify mitigation opportunities — including for customers who may already have been affected by a rapid cyberattack — but it is not an emergency incident response service: containment, forensic investigation, and attack recovery are separately scoped engagements. If you are dealing with an active incident, contact IT Partner directly before booking the workshop.

Does the workshop use our existing Microsoft 365 or Office 365 entitlements?

The workshop includes identifying opportunities to leverage already deployed entitlements. IT Partner maps Microsoft technology capabilities to the assessment findings so the customer can understand which Microsoft capabilities may help mitigate identified risks.

Is an onsite version of the workshop available?

Yes — an on-site version of the Rapid Cyberattack Assessment Workshop (4 consulting days, 3 days on-site) is available; see the linked on-site workshop page for details.

Are there any exclusions or out-of-scope items?

Yes. Emergency incident response, active threat containment, malware eradication, forensic investigation, and breach notification are not included, and neither is hands-on remediation or implementation of the roadmap recommendations (Defender configuration, Conditional Access, identity controls, endpoint hardening, backup or mail security changes) — those are separate follow-on projects scoped after the workshop.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$990
2 days
Book a meeting