Environment & People — Pillar 1
Know your environment. Know yourself. Everything else in security depends on both.
786 Cyber builds one current picture of what your organisation runs and who works in it — assets, networks, people, departments, MFA coverage and credential exposure — from data your systems already hold, rather than from a spreadsheet someone has to remember to update.
Why this comes first
Over 80% of breaches involve compromised credentials or misused access — and almost all of them start with an account or a system nobody was tracking.
Firewalls protect a perimeter that has moved. An attacker holding a valid username and password walks past every technical control, because as far as your systems are concerned they are a legitimate user. The defence is unglamorous: know which accounts exist, know which of them are protected, know what they can reach, and close the ones that should not be open. That is what this pillar does — both halves of it, people and environment, from one set of data.
"You cannot protect what you cannot see, and you cannot see what you have never written down. Identity governance isn't an enterprise feature — it's the foundation, and it starts with a list."
The four moments that matter
Identity risk is created by events, not by systems.
Every person who joins, moves within or leaves your organisation creates an identity event with security consequences. Who gets access? When is it revoked? Who approved it? Those questions have answers on the day they happen and no answer at all six months later, which is precisely when someone asks.
Onboarding
New staff need the right access from day one — no more, no less. Consistent provisioning reduces both security risk and the friction of a first week spent waiting for permissions.
Role changes
Promotions and team moves add access and rarely remove any. Periodic review is what stops privilege creep — the gradual accumulation nobody intended to grant permanently.
Offboarding
The most dangerous identity event is a departure handled loosely. Accounts left active, access not revoked, shared credentials not rotated — each one is an incident waiting for an opportunity.
An incident or audit
The first question is always who had access. A current directory and org chart answer it while it still matters, instead of starting a week of reconstruction.
People Directory
LiveOne current list of everyone in your organisation — and what each of them can reach.
Why we built it
Identity work stalls at the same place every time: no one can produce a list of people that IT, HR and security all agree on. The security team works from an export that was accurate last quarter, HR has the joiners nobody told IT about, and the accounts of people who left are still there because no process closed them.
What it does
A single directory of every person in your organisation — name, role, department, manager, contact details, the devices assigned to them and their MFA status. It populates from Microsoft 365 or Google Workspace and stays current as your team changes, so the list reflects the day you are looking at it rather than the day someone last maintained it.
The technology, named
This is the identity inventory the rest of the pillar is computed from. Nothing here is a manual re-declaration of what your directory already knows — the platform reads it, and everything downstream (MFA coverage, breach exposure, the org chart) is derived from the same source rather than separately maintained.
What it maps to
- Cyber Essentials (user access control)
- ISO 27001 (A.5.16 identity management)
- UK & EU GDPR (Art. 32)
- NIS2
Departments & the Org Chart
LiveSee the shape of your organisation — because reporting lines are access decisions.
Why we built it
Who approves an access request, who owns a system, who needs to be told when a control changes — every one of those questions is answered by the org chart, and most organisations only have it in a slide deck. When it exists only as a drawing, it is nobody’s job to keep it right.
What it does
An interactive org chart built from the same directory data as the People Directory — departments, reporting lines and the people in them, rendered as a graph you can expand, filter and open full-screen. Departments are matched as data comes in, so an import that says "IT" and one that says "I.T." land in the same department instead of quietly forking into two.
The technology, named
The chart is one of two graph views on the platform’s Environment & People dashboard, which frames the pillar as two questions: know your environment (what you run) and know yourself (who you are). Both halves are graphs over the same underlying data rather than separate inventories that can disagree.
What it maps to
- ISO 27001 (A.5.2 roles & responsibilities)
- Cyber Essentials
- NIS2 (governance)
Directory Sync & CSV Import
LiveConnect Microsoft 365 or Google Workspace once — the directory maintains itself after that.
Why we built it
A directory that has to be maintained by hand is a directory that goes stale, and a stale directory is worse than none: it produces confident answers that are wrong. The only inventory worth acting on is one that updates itself.
What it does
Connect Microsoft 365 (Entra ID) or Google Workspace and 786 Cyber syncs your users, their MFA status and their managed devices, keeping all three current as people join, move and leave. If your identity data lives somewhere else, CSV import covers it — with field mapping, validation before anything is written, automatic department matching, and a 24-hour rollback if an import turns out to be wrong.
The technology, named
Microsoft 365 and Google Workspace are both live integrations today. On-premise Active Directory and Okta are not — they are on the integrations roadmap, and CSV import is the honest answer for those environments in the meantime. The Microsoft 365 user and MFA sync works on the free Entra tier; only Exchange mail data requires a paid plan.
What it maps to
- Cyber Essentials (asset & user scope)
- ISO 27001 (A.5.16)
- NIS2
MFA Coverage
LiveKnow exactly how many people are without MFA — not a percentage that hides them.
Why we built it
MFA coverage is usually reported as a percentage, and a percentage is where accounts go to hide. "94% coverage" sounds like a finished job; it is six people whose password is the only thing between an attacker and your email, and the percentage will not tell you which six.
What it does
MFA status is tracked per person and reported as a count — how many people have it, how many do not, and how many the platform cannot yet determine. Unknown counts as not protected, deliberately: an account whose MFA state has never been established is not evidence of anything, and treating it as a pass would be the single easiest way to make this number flattering and useless.
The technology, named
Status is tri-state — enabled, disabled, or unknown — set at sync or import. Reporting it as counts rather than a percentage is a deliberate product rule carried through the platform: "6 people without MFA", never "87% coverage". The same rule is why there is no single blended organisation-wide security number anywhere in 786 Cyber.
What it maps to
- Cyber Essentials (MFA is mandatory)
- ISO 27001 (A.5.17)
- UK & EU GDPR (Art. 32)
- PCI-DSS 4.0.1 (Req. 8)
Credential & Breach Exposure
LiveFind out that a colleague’s credentials are circulating before someone else uses them.
Why we built it
Credentials from breaches at other companies are reused against yours for years afterwards. The account holder rarely knows, the breach is rarely one of yours, and the first sign of a problem is usually a successful login that looks entirely legitimate.
What it does
The platform checks your people against known credential-breach data and reports which accounts appear in it, so you can force a reset on the accounts that need one rather than a password reset for everybody.
The technology, named
Breach exposure is kept as a separate indicator and deliberately not folded into a single identity number. A leaked credential is a discrete event that needs a discrete response — averaging it into a score is how an urgent finding gets quietly diluted by good news elsewhere.
What it maps to
- Cyber Essentials
- ISO 27001 (A.5.17)
- UK & EU GDPR (Art. 32)
- NIS2 (incident handling)
Identity Posture Score
Live · honesty-gatedOne identity number — that refuses to appear until it has something real to say.
Why we built it
Security scores are easy to fabricate and hard to trust. Most products will show you a number on day one, before any data exists, because an empty dashboard is bad for a demo. That number is worse than no number: it gets reported upwards, and it is not measuring anything.
What it does
A single 0–100 identity posture score combining MFA coverage and credential exposure. If only one of the two inputs has a real basis, the platform shows that component on its own and flags it as partial, telling you what to do to complete it. If neither does, the score stays "in development" and no number is shown at all.
The technology, named
The score is 0.60 × MFA coverage + 0.40 × credential score, and it blends only when both inputs are genuinely computable. Privileged-account MFA and dormant/leaver detection are named Phase 2 inputs — they are not in this score, and this page does not imply they are. That refusal to render is the feature: an honest gap beats a fabricated number.
What it deliberately does not do
- No score before there is data
- No blended all-of-security number
- No percentage that hides a count
Overview dashboard guide →·Why coverage percentages mislead →
Assets & Network Connections
LiveThe other half of the pillar — what your organisation runs, and how it is wired together.
Why we built it
Knowing who your people are only answers half the question. The systems they reach — laptops, servers, domains, cloud accounts, the software installed on all of it — are the other half, and an inventory that covers people but not machines leaves you unable to answer the question every incident starts with: what could this account touch?
What it does
A full asset directory across every type your business runs — hardware, endpoints, network devices, on-premise and cloud software, domains and cloud infrastructure — each with a criticality rating and an owner, rendered as a filterable estate map. Alongside it, a network view showing how those assets connect, so the blast radius of any one of them is something you can see rather than guess.
The technology, named
This is the "know your environment" half of the pillar. The same inventory is what Technology & Threats scans, scores and prioritises — one asset list, read by both pillars, rather than a security inventory and an IT inventory that drift apart. Connection counts shown here are the ones explicitly mapped, kept separate from inferred relationships so a guess is never presented as a known link.
What it maps to
- Cyber Essentials (asset scope)
- ISO 27001 (A.5.9 inventory)
- PCI-DSS 4.0.1 (CDE scoping)
- NIS2
Assets guide →·Network connections guide →·Technology & Threats pillar →
Straight answers
What isn't built yet
Four things are commonly assumed to be part of a pillar like this one, and are not part of ours today. They are listed here for the same reason the identity posture score refuses to show a number it hasn't earned: you will find out eventually, and it is better that you find out now, from us.
- Joiners, movers and leavers workflows
- The platform generates the policies that document your JML process today, and the directory shows you the accounts a leaver still holds. The automated workflow that drives provisioning and offboarding is designed but not built.
- Access-path and permission mapping
- Showing exactly how a given person came to have access to a given system — inherited from a group, granted for a project, attached to a role — is a capability we intend to build. It does not exist yet, and no screen in the platform claims it does.
- On-premise Active Directory and Okta sync
- Microsoft 365 and Google Workspace are live. AD and Okta are on the integrations roadmap; CSV import covers those environments in the meantime.
- The multi-tenant MSP portal
- Cross-client identity risk from one dashboard is on the roadmap for partners, not something you can use today. If you are an MSP evaluating 786 Cyber, ask us where it actually stands rather than taking a marketing page’s word for it.
Framework coverage
The same access control, asked for by every framework you run
MFA, access review and least privilege are requirements in almost every framework in the catalogue. 786 Cyber maps each control to every framework that asks for it, so when you implement one you can see all of them it answers and attach the same evidence to each — the work happens once even though five frameworks want it. Seeing the overlap is the point; the platform shows you the mapping rather than quietly marking the other frameworks done.
Cyber Essentials
User access control is one of the five CE categories — MFA, least privilege and account review all required.
ISO 27001
A.5.15–A.5.18 cover access control, identity management and authentication — among the most audited controls in the standard.
UK & EU GDPR
Article 32 requires access control and authentication as technical security measures.
NIS2
Documented access control policy and privileged access management are required of essential entities.
Start with the list. Everything else follows from it.
Free for 14 days, no card. Connect Microsoft 365 or Google Workspace and see your people, devices and MFA gaps on day one.
For MSPs: enquire about the partner programme →
Where to go next
Related reading
See it priced
Environment & People is included from Essentials up; directory sync and credential monitoring are available on every paid tier.
Pricing →