Get a quote

Environment & People — Pillar 1

Know your environment. Know yourself. Everything else in security depends on both.

786 Cyber builds one current picture of what your organisation runs and who works in it — assets, networks, people, departments, MFA coverage and credential exposure — from data your systems already hold, rather than from a spreadsheet someone has to remember to update.

Applies to: All UK & EU businesses · Microsoft 365 and Google Workspace users · Organisations preparing for Cyber Essentials or ISO 27001

Over 80% of breaches involve compromised credentials or misused access — and almost all of them start with an account or a system nobody was tracking.

Firewalls protect a perimeter that has moved. An attacker holding a valid username and password walks past every technical control, because as far as your systems are concerned they are a legitimate user. The defence is unglamorous: know which accounts exist, know which of them are protected, know what they can reach, and close the ones that should not be open. That is what this pillar does — both halves of it, people and environment, from one set of data.

The gap most organisations live with
Nobody owns the list: Most organisations have three partial inventories — a spreadsheet from the last audit, whatever the IT team remembers, and the truth. None of them agree, and none is current enough to act on.
Dormant accounts: Accounts that were never disabled when someone left. Each one is an unlocked door, and the credentials may have been shared, phished or exposed in a breach without anyone knowing.
No MFA on the accounts that matter: Password-only access to email, cloud storage and admin consoles remains the single most exploited weakness in UK businesses. One leaked password is enough for a full account takeover.
No joiners, movers and leavers process: Without a documented process for onboarding, role changes and offboarding, access accumulates inconsistently and is rarely cleaned up — a shadow access map nobody has sight of.
What knowing actually delivers
One inventory, kept current: Assets, people, departments and the connections between them in a single view that updates from your directory rather than from someone remembering to edit a spreadsheet.
A smaller attack surface: Removing dormant accounts and closing MFA gaps shuts the access-based attack paths that attackers routinely use — the cheapest security work available to most organisations.
Evidence you already have: Access control is mandatory in Cyber Essentials, ISO 27001 (A.5.15–A.5.18), UK & EU GDPR (Art. 32), NIS2 and DORA. Synced directory data is evidence for all of them, gathered once.
Answers when it matters: When an incident or an audit starts, the first question is always who had access to what. A current directory and org chart answer it in minutes rather than days.

"You cannot protect what you cannot see, and you cannot see what you have never written down. Identity governance isn't an enterprise feature — it's the foundation, and it starts with a list."

Identity risk is created by events, not by systems.

Every person who joins, moves within or leaves your organisation creates an identity event with security consequences. Who gets access? When is it revoked? Who approved it? Those questions have answers on the day they happen and no answer at all six months later, which is precisely when someone asks.

Onboarding

New staff need the right access from day one — no more, no less. Consistent provisioning reduces both security risk and the friction of a first week spent waiting for permissions.

Role changes

Promotions and team moves add access and rarely remove any. Periodic review is what stops privilege creep — the gradual accumulation nobody intended to grant permanently.

Offboarding

The most dangerous identity event is a departure handled loosely. Accounts left active, access not revoked, shared credentials not rotated — each one is an incident waiting for an opportunity.

An incident or audit

The first question is always who had access. A current directory and org chart answer it while it still matters, instead of starting a week of reconstruction.

1

People Directory

Live

One current list of everyone in your organisation — and what each of them can reach.

Why we built it

Identity work stalls at the same place every time: no one can produce a list of people that IT, HR and security all agree on. The security team works from an export that was accurate last quarter, HR has the joiners nobody told IT about, and the accounts of people who left are still there because no process closed them.

What it does

A single directory of every person in your organisation — name, role, department, manager, contact details, the devices assigned to them and their MFA status. It populates from Microsoft 365 or Google Workspace and stays current as your team changes, so the list reflects the day you are looking at it rather than the day someone last maintained it.

The technology, named

This is the identity inventory the rest of the pillar is computed from. Nothing here is a manual re-declaration of what your directory already knows — the platform reads it, and everything downstream (MFA coverage, breach exposure, the org chart) is derived from the same source rather than separately maintained.

What it maps to

  • Cyber Essentials (user access control)
  • ISO 27001 (A.5.16 identity management)
  • UK & EU GDPR (Art. 32)
  • NIS2
2

Departments & the Org Chart

Live

See the shape of your organisation — because reporting lines are access decisions.

Why we built it

Who approves an access request, who owns a system, who needs to be told when a control changes — every one of those questions is answered by the org chart, and most organisations only have it in a slide deck. When it exists only as a drawing, it is nobody’s job to keep it right.

What it does

An interactive org chart built from the same directory data as the People Directory — departments, reporting lines and the people in them, rendered as a graph you can expand, filter and open full-screen. Departments are matched as data comes in, so an import that says "IT" and one that says "I.T." land in the same department instead of quietly forking into two.

The "Know yourself" department view — colour-coded departments with the headcount in each.
The "Know yourself" department view — colour-coded departments with the headcount in each.

The technology, named

The chart is one of two graph views on the platform’s Environment & People dashboard, which frames the pillar as two questions: know your environment (what you run) and know yourself (who you are). Both halves are graphs over the same underlying data rather than separate inventories that can disagree.

What it maps to

  • ISO 27001 (A.5.2 roles & responsibilities)
  • Cyber Essentials
  • NIS2 (governance)
3

Directory Sync & CSV Import

Live

Connect Microsoft 365 or Google Workspace once — the directory maintains itself after that.

Why we built it

A directory that has to be maintained by hand is a directory that goes stale, and a stale directory is worse than none: it produces confident answers that are wrong. The only inventory worth acting on is one that updates itself.

What it does

Connect Microsoft 365 (Entra ID) or Google Workspace and 786 Cyber syncs your users, their MFA status and their managed devices, keeping all three current as people join, move and leave. If your identity data lives somewhere else, CSV import covers it — with field mapping, validation before anything is written, automatic department matching, and a 24-hour rollback if an import turns out to be wrong.

The technology, named

Microsoft 365 and Google Workspace are both live integrations today. On-premise Active Directory and Okta are not — they are on the integrations roadmap, and CSV import is the honest answer for those environments in the meantime. The Microsoft 365 user and MFA sync works on the free Entra tier; only Exchange mail data requires a paid plan.

What it maps to

  • Cyber Essentials (asset & user scope)
  • ISO 27001 (A.5.16)
  • NIS2
4

MFA Coverage

Live

Know exactly how many people are without MFA — not a percentage that hides them.

Why we built it

MFA coverage is usually reported as a percentage, and a percentage is where accounts go to hide. "94% coverage" sounds like a finished job; it is six people whose password is the only thing between an attacker and your email, and the percentage will not tell you which six.

What it does

MFA status is tracked per person and reported as a count — how many people have it, how many do not, and how many the platform cannot yet determine. Unknown counts as not protected, deliberately: an account whose MFA state has never been established is not evidence of anything, and treating it as a pass would be the single easiest way to make this number flattering and useless.

The technology, named

Status is tri-state — enabled, disabled, or unknown — set at sync or import. Reporting it as counts rather than a percentage is a deliberate product rule carried through the platform: "6 people without MFA", never "87% coverage". The same rule is why there is no single blended organisation-wide security number anywhere in 786 Cyber.

What it maps to

  • Cyber Essentials (MFA is mandatory)
  • ISO 27001 (A.5.17)
  • UK & EU GDPR (Art. 32)
  • PCI-DSS 4.0.1 (Req. 8)
5

Credential & Breach Exposure

Live

Find out that a colleague’s credentials are circulating before someone else uses them.

Why we built it

Credentials from breaches at other companies are reused against yours for years afterwards. The account holder rarely knows, the breach is rarely one of yours, and the first sign of a problem is usually a successful login that looks entirely legitimate.

What it does

The platform checks your people against known credential-breach data and reports which accounts appear in it, so you can force a reset on the accounts that need one rather than a password reset for everybody.

The technology, named

Breach exposure is kept as a separate indicator and deliberately not folded into a single identity number. A leaked credential is a discrete event that needs a discrete response — averaging it into a score is how an urgent finding gets quietly diluted by good news elsewhere.

What it maps to

  • Cyber Essentials
  • ISO 27001 (A.5.17)
  • UK & EU GDPR (Art. 32)
  • NIS2 (incident handling)
6

Identity Posture Score

Live · honesty-gated

One identity number — that refuses to appear until it has something real to say.

Why we built it

Security scores are easy to fabricate and hard to trust. Most products will show you a number on day one, before any data exists, because an empty dashboard is bad for a demo. That number is worse than no number: it gets reported upwards, and it is not measuring anything.

What it does

A single 0–100 identity posture score combining MFA coverage and credential exposure. If only one of the two inputs has a real basis, the platform shows that component on its own and flags it as partial, telling you what to do to complete it. If neither does, the score stays "in development" and no number is shown at all.

The technology, named

The score is 0.60 × MFA coverage + 0.40 × credential score, and it blends only when both inputs are genuinely computable. Privileged-account MFA and dormant/leaver detection are named Phase 2 inputs — they are not in this score, and this page does not imply they are. That refusal to render is the feature: an honest gap beats a fabricated number.

What it deliberately does not do

  • No score before there is data
  • No blended all-of-security number
  • No percentage that hides a count
7

Assets & Network Connections

Live

The other half of the pillar — what your organisation runs, and how it is wired together.

Why we built it

Knowing who your people are only answers half the question. The systems they reach — laptops, servers, domains, cloud accounts, the software installed on all of it — are the other half, and an inventory that covers people but not machines leaves you unable to answer the question every incident starts with: what could this account touch?

What it does

A full asset directory across every type your business runs — hardware, endpoints, network devices, on-premise and cloud software, domains and cloud infrastructure — each with a criticality rating and an owner, rendered as a filterable estate map. Alongside it, a network view showing how those assets connect, so the blast radius of any one of them is something you can see rather than guess.

The Asset Directory — assets grouped by type, with live counts and the visual estate map.
The Asset Directory — assets grouped by type, with live counts and the visual estate map.
The Security Map on its Network tab — assets grouped into subnets, with typed connection labels.
The Security Map on its Network tab — assets grouped into subnets, with typed connection labels.

The technology, named

This is the "know your environment" half of the pillar. The same inventory is what Technology & Threats scans, scores and prioritises — one asset list, read by both pillars, rather than a security inventory and an IT inventory that drift apart. Connection counts shown here are the ones explicitly mapped, kept separate from inferred relationships so a guess is never presented as a known link.

What it maps to

  • Cyber Essentials (asset scope)
  • ISO 27001 (A.5.9 inventory)
  • PCI-DSS 4.0.1 (CDE scoping)
  • NIS2

What isn't built yet

Four things are commonly assumed to be part of a pillar like this one, and are not part of ours today. They are listed here for the same reason the identity posture score refuses to show a number it hasn't earned: you will find out eventually, and it is better that you find out now, from us.

Joiners, movers and leavers workflows
The platform generates the policies that document your JML process today, and the directory shows you the accounts a leaver still holds. The automated workflow that drives provisioning and offboarding is designed but not built.
Access-path and permission mapping
Showing exactly how a given person came to have access to a given system — inherited from a group, granted for a project, attached to a role — is a capability we intend to build. It does not exist yet, and no screen in the platform claims it does.
On-premise Active Directory and Okta sync
Microsoft 365 and Google Workspace are live. AD and Okta are on the integrations roadmap; CSV import covers those environments in the meantime.
The multi-tenant MSP portal
Cross-client identity risk from one dashboard is on the roadmap for partners, not something you can use today. If you are an MSP evaluating 786 Cyber, ask us where it actually stands rather than taking a marketing page’s word for it.

The same access control, asked for by every framework you run

MFA, access review and least privilege are requirements in almost every framework in the catalogue. 786 Cyber maps each control to every framework that asks for it, so when you implement one you can see all of them it answers and attach the same evidence to each — the work happens once even though five frameworks want it. Seeing the overlap is the point; the platform shows you the mapping rather than quietly marking the other frameworks done.

domain:access-control control:mfa framework:cyber-essentials framework:iso27001 framework:gdpr framework:nis2 severity:critical

Start with the list. Everything else follows from it.

Free for 14 days, no card. Connect Microsoft 365 or Google Workspace and see your people, devices and MFA gaps on day one.

For MSPs: enquire about the partner programme →

Where to go next

See it priced

Environment & People is included from Essentials up; directory sync and credential monitoring are available on every paid tier.

Pricing →

Talk to us

Book a walkthrough with someone who knows the platform.

Book a walkthrough →