CyberProva transparency

How CyberProva assesses security

Understand CyberProva's automated observations, evidence review, scoring and assessment limitations.

Define the scope

A CyberProva assessment combines selected technical observations with business controls requiring evidence. A connected Microsoft 365 tenant, verified website and uploaded documents each cover a different part of that scope.

  • Check the organisation, connected tenant and domains before interpreting results.
  • Review exclusions, licensing requirements, permission gaps and the assessment date.

Automated checks

CyberProva reads configuration and available activity information through Microsoft Graph and selected public technical sources. Each finding identifies the check, method and available result.

  • Some observations establish a specific configuration; others identify something your IT team needs to review.
  • A failed read, missing permission, missing licence or incomplete data is reported as unavailable or requiring review, rather than inferred to pass.
  • A result describes the available information at the assessment time; it does not establish continuous protection.

Evidence-based controls

Your organisation or IT provider supplies supporting documents for controls that cannot be established from Microsoft 365 alone. An authorised workspace reviewer decides whether to accept the evidence.

  • Use dated evidence that identifies its scope, owner and outcome.
  • CyberProva distinguishes supplied evidence, reviewer acceptance and automatic observations.
  • CyberProva does not independently certify the authenticity or underlying facts of uploaded evidence.

Scores and priorities

Read the findings behind each score. The core assessment assigns scores to selected checks, including accepted evidence and technical observations; advanced assessments report their own evaluation and coverage.

  • A score is a summary of the selected checks, not a probability that you will avoid an attack.
  • A review result can contribute to a score while still needing human judgement.
  • Read evidence gaps and unavailable checks alongside the score, then agree owners and next actions.

What CyberProva does not do

CyberProva supports assessment, evidence collection and follow-up. It does not guarantee that an organisation is secure or that an incident has not occurred.

  • No penetration testing or incident investigation.
  • No independent certification of uploaded evidence.
  • No Cyber Essentials certification; Cyber Essentials is a UK scheme administered through its certification process.
  • No automatic changes to your Microsoft 365 configuration.
  • Scheduled monitoring is periodic and plan-dependent, rather than real-time surveillance.