21 September 2026

Microsoft 365 Security: Are Your Existing Controls Really Protecting Your Organisation

A Microsoft 365 security feature can be switched on and still fail to protect your organisation. Your environment holds identities, email, files and collaboration data that attackers may target, so settings need to work as intended, not just appear in a portal.

Those settings can fall out of date as staff, devices, apps and business needs change. IBM’s 2024 Cost of a Data Breach Report put the global average cost of a breach at US$4.88 million. That figure covers breaches across sectors and technologies; it is not specific to Microsoft 365.

The key question is whether your controls can spot and contain common attacks, limit access to sensitive information and show that protection works. A focused review can reveal where to act first.

Understand the threats Microsoft 365 security must stop

An effective review starts with likely attack paths, not a checklist of enabled features. Map each risk to the identity, email or data controls that should reduce its impact. Then check whether those controls work across your actual users and services.

Trace a compromised account to business data

A stolen password or session token could give an attacker access to a user’s email, Teams chats, SharePoint sites and OneDrive files. The exposure depends on the account’s permissions, sign-in conditions and the sensitivity of the data it can reach.

Follow a sample account through its access. Check which sites it can open, whether it can share files externally and what an attacker could do with its mailbox.

Learn from a documented Microsoft 365 attack

In its January 2024 disclosure, Microsoft reported that Midnight Blizzard used password spraying to access a legacy, non-production test account. The actor then accessed some corporate email accounts.

The incident does not show that every Microsoft 365 environment has the same weakness. It does show why organisations should review old accounts, monitor unusual sign-ins and limit the paths from test systems to business data.

Map threats to your own environment

Consider phishing, password attacks, malicious inbox rules, unsafe OAuth app grants and accidental external sharing. Which risks matter most will depend on your users, data and work processes.

Check incident records and relevant threat reports to test your assumptions. A generic risk list cannot tell you whether your own staff face targeted invoice fraud or whether teams often share files with outside partners.

Test Microsoft 365 security identity controls

Identity controls should cover staff, administrators, guests and service accounts. For each one, confirm whether the control is licensed, set up and enforced. A policy that excludes key users may offer less protection than its name suggests.

Verify MFA coverage and strength

Review who has enrolled in multifactor authentication, which methods they can use and whether any accounts or sign-in cases are exempt. Pay close attention to older accounts and service accounts, which may not follow standard sign-in rules.

Where it fits your risk and support needs, consider phishing-resistant options such as passkeys or FIDO2 security keys. Check enrolment and sign-in records to confirm people use the methods your policy allows.

Check Conditional Access and legacy authentication

Conditional Access can weigh factors such as user risk, device status, location and app sensitivity. Review exclusions and overlapping rules, then check whether older authentication methods can bypass the protections you expect.

Test policy changes with a small group before wider use. This helps catch accidental lockouts while confirming that the rules block unsafe access.

Restrict and monitor privileged accounts

Reduce standing administrator roles and protect privileged sign-ins with strong authentication and tighter access rules. Where available, Privileged Identity Management can grant time-limited access when someone needs it.

Emergency access accounts need strict storage, monitoring and regular tests. Confirm that alerts reach a team that can act if one of these accounts is used.

Close gaps across email, devices and apps

Attackers may target weak points after sign-in, including deceptive messages, unmanaged devices and third-party app access. Review these areas together: email filters cannot stop every stolen session, and device controls cannot limit an app that has broad data permissions.

Strengthen email protection and response

Review anti-phishing, anti-spam and anti-malware policies in Microsoft Defender for Office 365 where your licence includes them. Check impersonation protection, Safe Links and Safe Attachments settings, along with any policy exceptions.

Make sure staff know how to report suspicious messages and that someone investigates them. Include checks for unexpected inbox rules, which can hide replies or send copies of mail to an attacker.

Apply consistent protection to devices and sessions

Check that devices with access to organisational data meet your security requirements. Review endpoint detection and response coverage, including devices used for email and file access.

Set clear rules for unmanaged devices and mobile access. Session controls can help limit what users do in a browser, but available options depend on licensing and setup.

Review OAuth apps and third-party access

Inventory enterprise apps, consent grants and the data each app can reach. Remove apps that are unused or have wider permissions than their purpose requires.

Limit who can approve new apps and set a regular review process for third-party access. A trusted app can still create risk if it keeps access after a project or supplier relationship ends.

Protect sensitive data in Microsoft 365

A valid sign-in does not prevent data exposure. Clear labels, sharing rules and user guidance can reduce the chance that staff disclose information by mistake or give it to the wrong people.

Find and classify important data

Identify sensitive information across Exchange, SharePoint, OneDrive and Teams. Apply sensitivity labels and handling rules that match clear business terms, such as public, internal or confidential.

Keep the label scheme manageable. If staff cannot tell which label fits a file, they are less likely to apply it correctly.

Reduce oversharing in Teams, SharePoint and OneDrive

Review anonymous links, guest access, external sharing settings, site permissions and site ownership. Look for sites that are broadly open and links that are no longer needed.

Set defaults that limit exposure, then allow business units to request exceptions with a clear reason. This keeps routine sharing useful without leaving sensitive sites open by default.

Use DLP and retention controls with clear ownership

Microsoft Purview data loss prevention policies can detect or limit risky sharing, depending on licensing and configuration. Test policies before enforcing them, explain alerts to staff and assign owners to manage exceptions.

Retention rules help meet records and compliance needs, but they do not prevent every form of data loss. Keep retention decisions separate from controls designed to stop unauthorised sharing.

Prove that Microsoft 365 security controls work

A settings review is only a start. You also need evidence that controls cover the right accounts and data, that alerts reach the right people and that response plans work under pressure.

Use Secure Score as a guide, not a guarantee

Microsoft Secure Score can point to improvement opportunities, but it does not certify an environment as secure. Weigh each recommendation against business impact, existing safeguards, licensing and the effort needed to maintain it.

A high score cannot replace tests of real attack paths. Prioritise gaps that could expose valuable accounts or sensitive data.

Check audit coverage, alerts and response plans

Confirm that relevant audit logs are enabled and retained for the period your organisation needs. Check that alerts go to a team with the access and time to investigate them.

Test response steps for a compromised account, a malicious email and suspected data exposure. Record who makes decisions, who contacts affected users and how access is contained.

Set a recurring review

Set a regular schedule to check identity exclusions, administrator roles, external sharing, app consent, device coverage and policy changes. Assign an owner to each control and document accepted exceptions.

Retest after major changes, such as a new app or policy update. This keeps a one-off review from becoming an outdated snapshot.

Conclusion

Microsoft 365 security depends on controls that are correctly set up, consistently enforced and checked over time. Secure identities, limit unnecessary access, protect sensitive data and make sure someone can act on alerts.

Start with the gaps that pose the greatest risk, assign an owner and track each fix to completion. Then test the change. That is how you turn a list of settings into measurable protection.

7 September 2026

IoT Security Risks: How Connected Cameras Can Become Attack Vectors

A camera can send a motion alert to your phone while you’re miles away. That convenience comes with a hidden cost: each connected camera is a computer with software, online accounts and access to your home or workplace network. Weak passwords, old firmware or open remote-access settings can expose more than video. Learn how camera attacks happen and which steps help reduce the risk.

 

Why IoT Security Risks Extend Beyond Camera Privacy

A connected camera relies on several parts working together. Each can create a security gap if it’s poorly set up or no longer maintained.

A camera is a small computer on your network

A camera runs firmware, connects to Wi-Fi and often relies on a mobile app and cloud service. Remote viewing, alerts and file storage may each involve a separate connection or account. Attackers can target the camera itself, its online service or the account you use to manage it.

Video exposure is only one possible consequence

An intruder might view a live feed, access stored clips or change camera settings. They could also take over your account, disable alerts or stop the camera from working. If the device can reach other parts of your network, a breach may put computers, storage drives or smart-home equipment at risk.

Everyday setup choices can increase exposure

Default or reused passwords give attackers an easier way in, while unnecessary remote access can create openings you don’t need. An unsupported camera may have flaws that never receive a fix. The actual risk depends on the model, its settings and how well you maintain it.

How IoT Security Risks Turn Cameras Into Attack Vectors

A camera attack often combines several weaknesses. A stolen password, for instance, may expose an account whose camera also runs old software.

Weak or reused passwords enable account takeover

Attackers may guess simple passwords or try login details stolen from another service. If you reuse a password, a breach elsewhere could give them access to your camera account as well. Set a unique password for each account, store it in a password manager and turn on multifactor authentication (MFA) when the service offers it.

Unpatched firmware leaves known weaknesses open

Firmware is the software built into a camera. When makers find a flaw, they may release an update to fix it; attackers can target devices that owners leave unpatched. Enable automatic updates if available, and check how long a maker plans to support a product before buying.

Exposed services can invite remote attacks

Some cameras offer remote management, open network ports or peer-to-peer connections for viewing footage outside the home. If these services use weak security or old protocols, they may provide a route for attackers. Turn off features you don’t need and don’t expose camera management pages directly to the public internet.

What Real Camera Incidents Reveal About IoT Security Risks

Past incidents show how poor security can affect both camera owners and people far beyond their homes. They don’t mean every camera has the same flaws.

Mirai showed how cameras and DVRs can fuel disruption

In 2016, the Mirai malware infected poorly secured internet-connected devices, including cameras and digital video recorders. It gathered them into a botnet, a group of devices that can be directed to send large volumes of traffic at a target. A major attack on DNS provider Dyn disrupted access to a number of websites and online services.

The FTC’s TRENDnet case exposed video feeds

In 2013, the US Federal Trade Commission took action over security flaws in TRENDnet internet-connected cameras. Some users’ camera feeds could be viewed online, exposing private video. The case showed why secure login controls and careful handling of footage matter.

Owners and makers both shape camera security

Camera makers affect security through product design, software updates and the length of time they support a device. Owners affect it through passwords, settings and routine maintenance. The FTC’s TRENDnet case and public reporting on Mirai offer different examples of how these responsibilities connect.

How to Secure Connected Cameras at Home or Work

A few changes can reduce the chance of a camera breach and limit the damage if one occurs. Start with account access, then check software and network settings.

Harden accounts and camera settings

Replace default login details with a unique password, enable MFA and remove accounts you no longer use. Review who can view or share footage, and check whether remote access is needed. Turn off unused features, such as public sharing or access for old devices.

Keep firmware, apps and routers updated

Install updates for the camera, its app and your router. Updates can fix security flaws, so check for them regularly if automatic updates aren’t available. If a camera no longer receives security support, replace it rather than leaving a known weakness on your network.

Limit what a compromised camera could reach

If your router allows it, place cameras on a separate guest or IoT network. This can help stop a compromised camera from reaching laptops and other devices on your main network. Use strong Wi-Fi encryption, change the router’s default login and avoid opening camera management services to the internet.

How to Choose Cameras With Security in Mind

Image quality and price matter, but so do software support and privacy controls. Check the maker’s policies before you buy.

Check update and end-of-support policies

Look for clear details on how updates arrive and how long the camera will receive them. A maker should also explain how to report a security flaw. If support information is hard to find, treat that as a reason to compare other models.

Review privacy and data-handling practices

Find out what account and video data the service collects, where it stores footage and how long it keeps it. Check whether you can turn off cloud storage or delete clips and your account. Read the privacy settings and service terms before setup, not after you’ve uploaded video.

Prefer secure defaults and clear controls

Look for MFA, access logs and simple ways to remove users or delete footage. A camera that requires a password change during setup is safer than one that keeps a shared default password. A familiar brand name or “smart” label alone doesn’t prove a product is secure.

Protect Camera Privacy Without Losing Useful Features

Security is an ongoing task, not a one-time part of installation. You can keep useful alerts and remote viewing while limiting access to people and services that need it.

Key steps that reduce risk

Use unique passwords, keep software current and switch off remote features you don’t use. Separate cameras from other devices on your network where possible, and replace models that no longer receive updates. These actions lower risk but can’t guarantee that a device will never be attacked.

Set a simple maintenance routine

Every few months, check for firmware updates and review account access, sharing settings and router security. Remove old users and devices, and look for unfamiliar logins or changes you didn’t make. If a camera moves without cause or its settings change unexpectedly, secure the account and review its connections promptly.

Conclusion

Connected cameras can protect a home or workplace, but weak accounts, old software and exposed services can put privacy and other network devices at risk. Secure the account, install updates, limit remote access and choose products with clear support policies. Check your cameras and router today, then make those checks part of your regular routine.