A free, no-obligation exposure check, separate from my paid full assessment. I start from the outside, with no passwords and no access to your systems. Then I walk you through what I found in a 30-minute call.
Free for NZ nonprofits & small businesses. No passwords needed. Takes 60 seconds, and Lee replies within 24 hours.
Confidential. Handled under the NZ Privacy Act 2020. Privacy policy
She'll run the outside check and be in touch within 24 hours to book your call.
Using only what's publicly visible about your domain and email setup, I look for the gaps attackers look for first. You don't give me any access.
Video or phone. I show you what I found and ask a few questions about who manages your accounts, devices and backups.
Your top 3 risks in plain English, with what to do about each. Yours to keep, whether or not we work together.
Invoice fraud and fake "please pay this" emails often start with gaps that are visible from the outside. These are the first things I check.
How well SPF, DKIM and DMARC protect your domain against direct email spoofing.
Whether mail to and from you is protected in transit (TLS and MTA-STS).
Who controls your domain, when it expires, and whether old or forgotten records are left open.
What your Microsoft 365 or Google setup gives away publicly, and whether your domain appears in known breaches (with your permission).
Measured against real NZ standards. These are the same email security standards NZ government agencies are required to meet under the Secure Government Email framework. Getting them right also helps you meet your Privacy Act 2020 obligation to keep personal information secure.
On the call we also cover the inside questions: who has admin access, whether MFA is actually enforced, what happens to former staff accounts, and whether your backups have ever been tested.
These are the gaps I check first. They're easy to miss, and costly when someone else finds them before you do.
Former IT providers, ex-staff and forgotten partner accounts that still hold the keys to your Microsoft 365, often with no record of who has what.
Admin accessMany Microsoft 365 licences include MFA enforcement and Conditional Access. Paying for them doesn't mean they're on.
LicensingA portal can report a policy as applied when the device says otherwise. I check the device itself, not just the dashboard.
Device securityFor one client, a fake site outranked the real business in search and harvested customer payment details. I traced it, built the evidence and got it taken down.
Brand impersonation · client caseHolding sensitive client data on discounted Microsoft licences, with a board asking questions.
5 to 150 staff on Microsoft 365 or Google Workspace, handling payments or personal information.
Your IT provider has left or changed and nobody is sure what was handed over.
You've been asked about MFA, backups or cyber cover and need a straight answer.
I'm a Microsoft security and identity consultant based in Christchurch, working with organisations across New Zealand. I spend my days inside Microsoft 365, Entra ID, Intune and Defender, finding what's been missed and fixing it properly.
Earlier in my career I delivered enterprise HR, payroll and ERP systems for large organisations in Australia, New Zealand and the UK, including Telstra, Air New Zealand, British Telecom, Sky TV in Scotland and the University of Sydney, where I designed the access-control framework for the HR and payroll system. I then took time out to raise my family, and returned in 2024 through formal cybersecurity retraining, founding PureLayer in 2025. Today I work hands-on in Microsoft 365, Entra ID, Intune and Defender for NZ nonprofits and small businesses that don't have a security team of their own. Everything I do is documented, and the documentation is yours to keep.
"Lee went above and beyond to help us resolve a serious issue, and did it quickly, professionally, and without any fuss… I wouldn't hesitate to recommend Lee to anyone needing help in this space."
"Outstanding service from Lee and she's very knowledgeable on how to protect businesses from cyber threats, definitely recommended!"
"Lee is amazing and very knowledgeable. Highly recommend."
No. The free check uses only publicly visible information about your domain and email setup. Nothing is installed and nothing in your systems changes.
It's free, with no obligation. Most organisations don't know what they're missing until someone shows them. If the check turns up something serious, I'll explain what fixing it involves and what it would cost. If it doesn't, you keep the summary and we part as friends.
Yes. Many organisations do. This is an independent second look, not a judgement on your provider. A good IT provider and an independent check work well together, and I'm happy to work alongside yours.
Yes. The check and the call are done remotely, so I work with organisations anywhere in New Zealand.
It's treated as confidential and handled under the NZ Privacy Act 2020. I don't share findings with anyone, including your IT provider, without your say-so.
A free outside check, a 30-minute call, and a one-page summary of your top 3 risks. No passwords, no obligation.
Book my free security check →