Rapid Cyberattack Assessment Workshop (Remote) — Ransomware Risk Assessment & Security Roadmap
Rapid Cyberattack Assessment Workshop (Remote) is a 2-day remote training workshop for Office 365 and Microsoft 365 customers. It helps identify potential cybersecurity risks related to rapidly spreading attacks, such as ransomware, and provides guidance on Microsoft technologies that can help mitigate those risks.
What this engagement is
This remote workshop applies IT Partner's rapid cyberattack assessment methodology — originally delivered as a Microsoft partner engagement — to identify elements of your environment that make it prone to rapidly spreading, destructive attacks such as ransomware, and to map current Microsoft security capabilities to the gaps found. It fits customers who may already have been affected by an attack, are unsure about the status of defensive measures, or want a focused risk assessment. The objective is to help customers identify potential cybersecurity risks and gain knowledge about technologies that can help mitigate those risks. An on-site form of the workshop is also available.
Success criteria
What you receive
How the work unfolds
Kickoff meeting; introduction to the engagement: objectives, flow, responsibilities, and governance; provide and explain preassessment questionnaire to the customer.
Ensure availability of necessary resources; review the assessment tooling results; begin road map planning; confirmation on the completeness of the questionnaire or tooling output; definition of rapid cyberattacks; review, explain, and discuss questionnaire and tool findings; identify opportunities to leverage already deployed entitlements; perform gap analysis; finalize road map.
Road map delivery workshop; solution(s) briefing and Technical Readiness presentations; engagement close-out.
Prerequisites
Who does what
IT Partner
- Understand the customer's status vs cyberattacks. Help the customer identify elements in their IT environment that might make it prone to rapidly spreading and potentially destructive cyberattacks (e.g., ransomware attacks).
- Cyberattacks technical security readiness. Provide guidance, recommendations, and best practices on how to successfully use Microsoft technologies to mitigate security threats that are associated with rapid cyberattacks.
- Create rapid cyberattack road map. Provide prioritized and actionable road map for the customer, containing proposed actions based on discovered gaps, considering user impact and implementation cost.
- Map Microsoft technology capabilities and Partner services to assessment findings, taking into account the customer's objectives and requirements.
Your team
- Information: This includes accurate, timely (within three business days or as mutually agreed upon), and complete information
- Access to people. This includes access to knowledgeable customer personnel, including business user representatives, and access to funding if additional budget is needed to deliver project scope
- Support preparation of the agreed data-collection tooling before the webinars
What's not included
Limitations & technical notes
Frequently asked questions
What is the Rapid Cyberattack Assessment Workshop (Remote)?
The Rapid Cyberattack Assessment Workshop (Remote) is a 2-day remote training and assessment workshop for Office 365 and Microsoft 365 customers. It helps identify cybersecurity risks related to rapidly spreading attacks such as ransomware and provides guidance on Microsoft technologies that can help mitigate those risks.
Who is this workshop designed for?
This workshop is designed for Office 365 and Microsoft 365 customers who want to assess their exposure to rapid cyberattacks. It is relevant if an organization may already have been affected by an attack, is unsure whether its current defenses are adequate, or wants a structured risk assessment focused on threats such as ransomware.
How long does the Rapid Cyberattack Assessment Workshop take?
The Rapid Cyberattack Assessment Workshop (Remote) is delivered over 2 days. The engagement is structured around remote webinar sessions that include kickoff, assessment review, road map planning, and final road map delivery.
What is included in the workshop?
The workshop includes a kickoff presentation, a preassessment questionnaire, review and discussion of assessment tooling reports, and a rapid cyberattack road map. The road map is intended to be prioritized and actionable, with proposed actions based on discovered gaps and consideration of user impact and implementation cost.
What deliverables will we receive?
Customers receive a kickoff presentation, an organizational questionnaire covering exploit mitigation, attack surface reduction, privileged access, and business continuity practices, assessment tooling reports, and a rapid cyberattack road map. The road map maps Microsoft technology capabilities and Partner services to the assessment findings based on the customer’s objectives and requirements.
What happens during the kickoff webinar?
The kickoff webinar introduces the engagement objectives, flow, responsibilities, and governance. IT Partner also provides and explains the preassessment questionnaire so the customer can supply information needed for the assessment.
What are the prerequisites for the workshop?
IT Partner's assessment questionnaire and agreed data-collection tooling are prepared and configured before the webinars. The customer is also expected to provide accurate and complete information, timely responses, and access to knowledgeable personnel, including business user representatives where needed.
Does the workshop include remediation or implementation of security controls?
The stated scope focuses on assessment, guidance, report review, and road map creation. Implementation of Microsoft security technologies or remediation of discovered gaps is not listed as included, so any hands-on implementation should be confirmed and scoped separately with IT Partner.
Will the workshop stop an active ransomware attack or provide incident response?
No. The workshop helps assess risks and identify mitigation opportunities — including for customers who may already have been affected by a rapid cyberattack — but it is not an emergency incident response service: containment, forensic investigation, and attack recovery are separately scoped engagements. If you are dealing with an active incident, contact IT Partner directly before booking the workshop.
Does the workshop use our existing Microsoft 365 or Office 365 entitlements?
The workshop includes identifying opportunities to leverage already deployed entitlements. IT Partner maps Microsoft technology capabilities to the assessment findings so the customer can understand which Microsoft capabilities may help mitigate identified risks.
Is an onsite version of the workshop available?
Yes — an on-site version of the Rapid Cyberattack Assessment Workshop (4 consulting days, 3 days on-site) is available; see the linked on-site workshop page for details.
Are there any exclusions or out-of-scope items?
Yes. Emergency incident response, active threat containment, malware eradication, forensic investigation, and breach notification are not included, and neither is hands-on remediation or implementation of the roadmap recommendations (Defender configuration, Conditional Access, identity controls, endpoint hardening, backup or mail security changes) — those are separate follow-on projects scoped after the workshop.