Offboarding staff from Microsoft 365 or Google Workspace
Offboarding staff from Microsoft 365 or Google Workspace, step by step: cut access, revoke devices, keep mail and files, and stop paying for the licence.
·
4 min read
Cyber Essentials for small businesses is a UK government-backed certificate that shows you have five basic security controls in place. If a client or a tender has asked for it, the controls aren't complicated, but a few details catch people out.
The scheme belongs to the National Cyber Security Centre (NCSC), with IASME as its delivery partner. The current standard is Requirements for IT Infrastructure v3.3. If you buy an assessment from 27 April 2026, you answer a question set called Danzell. The requirements sit under five technical controls.
Firewalls filter traffic between the internet and your devices. Your office router counts. You must change its default admin password and block incoming connections nobody asked for.
Secure configuration means tidying devices after they come out of the box. Remove accounts and software you don't use, change default passwords and put a PIN or password on laptops and phones.
Security update management means all software must be licensed and still supported by its maker. Fixes rated critical or high risk must go on within 14 days of release.
User access control means only the right people have accounts, with only the access they need. Logins to cloud services such as Microsoft 365 or Google Workspace must always use multi-factor authentication (MFA). That's a second check, like a code on your phone, on top of the password.
Malware protection means something must stop harmful software from running on each device. The antivirus built into Windows and macOS can meet this if it's switched on and kept up to date.
When people talk about Cyber Essentials for small businesses, they can mean either level. Both check the same five controls. The difference is how much someone else checks your work.
IASME's own FAQ is blunt on one point. If you use unsupported software anywhere in scope, you fail. That can be one old laptop on an operating system its maker no longer patches, or an ageing copy of accounting software.
Patching is next. The 14-day rule applies to fixes rated critical or high risk, and to updates where the vendor doesn't say how serious the flaw is. Turn on automatic updates where you can, and remember phones and routers count too.
Admin rights trip people up. The standard says admin work must be done from a separate account, never used for email or browsing. So if your staff log in as administrators day to day, that needs to change.
Then there's MFA on cloud services. Since v3.3, cloud services can't be left out of scope. I'd fix this first, because it's quick and costs little. Leavers matter here too. Accounts must be removed or disabled when someone leaves, which is why offboarding staff from Microsoft 365 or Google Workspace properly pays off.
The Cabinet Office's PPN 014 covers central government departments, their agencies, non-departmental public bodies and NHS bodies. For certain contracts, suppliers must show Cyber Essentials or Plus, or equivalent controls, before the contract is awarded.
Those contracts include ones where you'd handle citizens' personal details, such as home addresses or bank details. They also include work on government staff data like payroll, and ICT systems that store or process data at the OFFICIAL classification. The certificate must then be renewed each year for the life of the contract.
Outside government, the NCSC says a growing number of organisations ask suppliers to be certified before they can bid. So it can be worth having before a large client asks.
IASME prices the basic level by staff numbers. At the time of writing, it's £320 + VAT for 0 to 9 employees and £440 + VAT for 10 to 49. It's £500 + VAT for 50 to 249 and £600 + VAT above that. Check IASME's FAQ for current figures. Certificates at both levels expire after 12 months, so it's a yearly cost.
Eight Mile isn't a certification body, and we don't issue certificates. Our security audit covers ground that overlaps with the five controls, including leaver access, lost devices, remote access and router configuration. You get a plain-English report with evidence for each finding and a prioritised fix list. We retest once the fixes are in. If you're weighing that up against a penetration test (a simulated attack), read our comparison of a security audit vs penetration test.
If a tender is coming up and you're not sure where you stand, talk to an engineer and we'll agree what to check first.
Offboarding staff from Microsoft 365 or Google Workspace, step by step: cut access, revoke devices, keep mail and files, and stop paying for the licence.
·
4 min read
What changes when a trades business moves from paper job sheets to a phone app, including how the app copes with no signal.
·
4 min read
Why your quotes land in spam: SPF, DKIM and DMARC explained for business owners, and how to check your own domain with free tools.
·
3 min read
Office move IT checklist for London SMEs: internet lead times, surveys, cabling, network design, servers and security before and after moving.
·
4 min read
Multi-site office network design for London SMEs: site-to-site links, consistent segmentation, accounts you keep.
·
3 min read
Security audit vs penetration test: when to review config first, when a buyer needs a pentest, and usual order for SaaS.
·
3 min read
Secrets in git repository history outlive a deleted file. Rotate first, then stop the next temporary commit.
·
3 min read
Multi-tenant SaaS mistakes that show up after launch: isolation, roles, files, billing, and when to stop and fix.
·
3 min read
Security audit checklist before you go live: access, secrets, backups, auth, deps, alerting, and when to bring in an auditor.
·
3 min read