Southport Compass – Phase 1 Risk Snapshot
Southport Compass
Slide 1 of 5
Phase 1 Findings → Phase 2 Remediation
A simple view of what we found and what we'll do next
1
Discover2
Analyze3
Protect4
Monitor5
Report6
ImprovePhase 1 – Key Findings
- •DMARC enforcement not enabled (monitoring only)
- •Mailbox structure needs shared vs licensed alignment
- •BYOD usage requires device and access controls
- •Password hygiene inconsistent; confirm MFA enforcement
- •License counts exceed active users → identity sprawl risk
Phase 2 – Next Steps
- •Enforce MFA and tighten sign-in policies
- •Move DMARC → quarantine, validate, then reject
- •Convert generic mailboxes to shared; audit permissions
- •Clean up unused identities and licensing
- •Baseline device security + conditional access for BYOD
