CinchOps managed IT services and cybersecurity Houston Texas
  • Services
    • Managed IT Services
    • Cybersecurity
    • Business Continuity & Disaster Recovery (BCDR)
    • Virtual CTO & CIO Services
    • Cloud Services
    • Software Defined Wide Area Networks (SD-WAN)
    • Voice Over IP (VoIP)
    • Business Process Automation
  • Industries
    • By Company Size
      • Small & Midsize Businesses
      • Enterprise IT Services & Support in Houston, TX
    • Construction
    • CPA Firms
    • Energy Services & Utilities
    • Engineering
    • Law Firms
    • Manufacturing
    • Oil & Gas Services
    • Wealth Management
  • Local to You
    • Brookshire
    • Cypress
    • Fulshear
    • Houston
    • Katy
    • Missouri City
    • Richmond
    • Rosenberg
    • Sealy
    • Sugar Land
    • The Woodlands
    • Tomball
  • Reviews
  • Resources
    • IT Scorecards
    • IT Outage Calculator
    • Blog
    • News & Updates
    • Videos
    • FAQs
    • CinchOps CyberJeopardy
  • Research
    • Houston Area Security Index
    • Houston Area Patch Index
    • Houston MSP Review Index
    • Houston Growth Index
    • Houston Vulnerability Index
    • Cybersecurity by the Numbers
  • About Us
    • Our Story
    • Your Story
    • My Story
  • Contact
I Need IT Support Now
Managed IT Support Houston Cybersecurity
Shane
Shane July 15th, 2025

Microsoft 365 Security: The Hidden Gap Between Perception and Reality

Understanding Microsoft 365 Security Gaps: Insights from Industry Research – Privileged Access in Microsoft 365: Balancing Security and Operational Efficiency

2025 Report
68% of Organizations Were Attacked Last Year. Most Still Rate Their Microsoft 365 Security "Advanced."

CoreView surveyed 250+ IT and security leaders for its 2025 State of Microsoft 365 Security report. The gap between what companies believe and what is actually protecting them is where Houston small businesses get hurt.

TL;DR
CoreView's 2025 State of Microsoft 365 Security survey of 250+ leaders found 68% of organizations were attacked, yet 60% rate their M365 security "established" or "advanced." Meanwhile 90% run some MFA but only 41% enforce it, 63% fail least-privilege, and nearly half wrongly think Microsoft backs up their configuration. For Houston SMBs, the takeaway is blunt: owning security controls and enforcing them are two different things, and attackers exploit the difference.
🎭 The Confidence Gap ⚠️ Six Exposures 🔐 The MFA Enforcement Trap 🚀 How CinchOps Helps

The most dangerous finding in CoreView's 2025 report is not a single number. It is the distance between the two: 68% of organizations were attacked, and 60% still call their Microsoft 365 security "established" or "advanced."

CoreView's 2025 State of Microsoft 365 Security survey pulled answers from more than 250 IT and security leaders across enterprise and mid-market companies. The picture it paints is uncomfortable. Organizations that rate themselves "advanced" get their accounts compromised at nearly the same rate as those with basic setups. That is not a maturity problem. It is a false-confidence problem, and it is exactly the kind of blind spot that costs a Houston business a weekend and a wire transfer.

Why this matters for Microsoft 365 security: almost every SMB in the Houston metro runs on Microsoft 365 for email, files, and identity. When the platform that holds everything is protected by controls nobody enforces, one phished login is all it takes.

Why Does "Advanced" Security Still Get Breached?

Rating yourself highly does not lower your compromise rate.

CoreView found organizations that describe their Microsoft 365 security as "advanced" show account-compromise rates nearly identical to those with basic implementations. Self-assessment and actual protection have almost nothing to do with each other.

This is the survey's core finding, and it should stop every business owner cold. Sixty percent of respondents rate themselves "established" or "advanced." Sixty-eight percent got attacked. The two groups overlap heavily. Feeling secure and being secure are different states, and the report shows most companies cannot tell which one they are in.

In 35 years around IT, this is the pattern we see most with Houston companies: the tools got bought, the project got marked done, and nobody ever checked whether the settings held. Security is not a purchase. It is a state you have to keep verifying.

MICROSOFT 365 SECURITY, BY THE NUMBERS 68% of organizations were attacked 60% rate themselves "established"+ 90% / 41% use MFA vs. actually enforce it 63% fail to enforce least privilege The gap between owning a control and enforcing it is where breaches live. CinchOps · cinchops.com · Source: CoreView 2025 State of Microsoft 365 Security
The Microsoft 365 security perception gap, by the numbers. Source: CoreView 2025 State of Microsoft 365 Security.

What Are the Six Exposures CoreView Found?

Six vulnerabilities that compound into real risk across Microsoft 365.

CoreView identified six weaknesses that turn a normal Microsoft 365 tenant into an attack surface: tenant sprawl, over-privileged apps, backup misconceptions, weak configuration control, failed least privilege, and undetected configuration tampering.

None of these is exotic. Each is the quiet result of a platform that grew faster than anyone documented. For a Houston CPA practice or engineering firm running lean, they stack up fast.

  • Multi-tenant complexity. 78% of organizations run more than one tenant and 45% run more than five, which makes unified governance nearly impossible.
  • Over-privileged applications. 51% have 250+ Entra applications with read-write permissions, each one as dangerous as a global admin account.
  • Backup misconceptions. Nearly half wrongly assume Microsoft backs up their configuration, so they are defenseless when settings get wiped.
  • Poor configuration management. 65% manage Microsoft 365 configuration without following best practices, inviting avoidable outages.
  • Failed least privilege. 63% of tenants do not enforce least privilege, even though proper privileged-access management cuts incidents by 64%.
  • Configuration tampering. Microsoft logged 176,000 tampering instances in May 2024 alone, a 79% jump since 2023, yet 48% of organizations report seeing little of it.

The tampering number is the one to sit with. If Microsoft is recording 176,000 tampering events in a single month and half of companies say it is not happening to them, the honest read is that they cannot see it. You do not get to report on what you never detect.

Chart of how many Entra or integrated apps use read-write permissions, from the CoreView 2025 survey
How many of your Entra or integrated apps use read-write permissions? Source: CoreView 2025 State of Microsoft 365 Security survey.

Is Your MFA Actually Protecting You, or Just Installed?

Turning MFA on is not the same as enforcing it.

CoreView found 90% of organizations have some form of MFA, but only 41% have automated detection and enforcement. That leaves 59% with no real assurance the control they bought is doing anything.

Here is the part that should change how you think about it. Microsoft's own data shows 99.9% of account compromises hit accounts without MFA. So you would expect the 90% who deployed MFA to be nearly bulletproof. They are not. The report found environments that have MFA but no enforcement get compromised at rates close to environments with no MFA at all.

Read that twice. MFA you set up once and never enforced protects you about as well as MFA you never set up. The organizations that automated detection and enforcement saw 53% fewer account-compromise incidents. Enforcement is the whole difference.

We see this twice a month with Houston businesses. MFA shows as "on" in the admin center, but there is a legacy protocol left open, a break-glass account with no second factor, or a conditional-access policy in report-only mode that never got switched to enforce. The control exists. Nobody is watching whether it holds.

Chart of MFA and Zero Trust implementation for Microsoft 365 user and admin access, from the CoreView 2025 survey
Do you have MFA / Zero Trust implemented for Microsoft 365 user and admin access? Source: CoreView 2025 State of Microsoft 365 Security survey.
Chart of which Microsoft services organizations use, from the CoreView 2025 survey
Which of the following Microsoft services are you using? Source: CoreView 2025 State of Microsoft 365 Security survey.

The service chart matters here because the more of the Microsoft stack you run, the more places enforcement can quietly fail. CoreView also found mid-market companies sit further behind: 72% of enterprises have privileged-access management versus just 43% of mid-market. Smaller Houston firms carry the same threat exposure with fewer of the controls that stop it.

100% Free

Know Your Business Security Score

Get a FREE comprehensive security assessment for your Houston area business. Understand vulnerabilities across your network, applications, DNS, and more.

Get Your Free Assessment

Every owner tells me their MFA is on. Then we look, and there is a legacy protocol wide open or a policy stuck in report-only. The report proves it: unenforced MFA gets you breached at the same rate as no MFA. The control is not the point. Enforcing it is the point.
Shane Stevens, CEO, CinchOps - LinkedIn

Close the Microsoft 365 Enforcement Gap

CinchOps gives Houston-area businesses the configuration control, MFA enforcement, and privileged-access management the CoreView 2025 report shows most companies only assume they have. It is the core of our cybersecurity and managed IT services.

Explore CinchOps cybersecurity →

How CinchOps Closes the Microsoft 365 Gap

CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area, focused on turning Microsoft 365 controls that only look active into controls that are actually enforced.

CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees. The CoreView report's central problem, controls that exist but nobody enforces, is exactly what a managed partner exists to fix:

  • Microsoft 365 security assessments. We find the misconfigurations, privilege sprawl, and open legacy protocols the survey shows most companies miss.
  • MFA enforcement, not just deployment. Automated detection and conditional-access enforcement so your MFA earns the 53% incident reduction the report ties to enforcement.
  • Configuration backup and change control. Because Microsoft does not back up your tenant configuration, and nearly half of companies find that out the hard way.
  • Least-privilege and privileged-access management. The control 63% of tenants skip, which the report links to a 64% drop in incidents when done right.

Owning a Microsoft 365 tenant does not make it secure, and a mid-market Houston business should not carry enterprise-level exposure with mid-market controls. If your MFA is "on" but nobody has confirmed it holds, that is the gap CoreView measured, and it is fixable. Run a Houston or Katy business on Microsoft 365? Talk to CinchOps and we will show you where your controls are not actually enforced.

Frequently Asked Questions

What is the CoreView 2025 State of Microsoft 365 Security survey?

It is an annual report from CoreView based on responses from more than 250 IT and security leaders across enterprise and mid-market organizations. The 2025 edition measures Microsoft 365 security maturity, MFA enforcement, privileged access, and configuration risk, and highlights the gap between how secure companies feel and how secure they actually are.

What is the Microsoft 365 security perception gap?

It is the distance between self-rated security and real protection. CoreView found 60% of organizations rate their Microsoft 365 security "established" or "advanced," yet 68% were attacked, and "advanced" organizations get compromised at rates close to basic ones. Feeling secure and being secure are not the same thing.

Why is MFA not enough on its own?

CoreView found 90% of organizations use some MFA but only 41% enforce it with automated detection. Environments with MFA but no enforcement get compromised at rates near those with no MFA. Organizations that automate enforcement see 53% fewer account-compromise incidents, so enforcement, not deployment, is what protects you.

Does Microsoft back up my Microsoft 365 configuration?

No. Nearly half of organizations in the CoreView survey wrongly believe Microsoft backs up their tenant configuration. Microsoft protects its platform, not your specific settings, policies, and configuration. If those are wiped or tampered with, you need your own backup and change-control process to restore them.

What should a Houston small business do about these findings?

Verify enforcement, not just deployment. Confirm MFA is enforced everywhere, close legacy protocols, apply least privilege, back up your tenant configuration, and monitor for tampering. Mid-market firms lag enterprises on these controls, so a managed IT provider can deliver enforcement-grade Microsoft 365 security without an in-house team.

Discover More

CinchOps Cybersecurity Services
CinchOps Managed IT Services
Inside Microsoft's Secure Future Initiative
What Is Identity and Access Management?
Houston Businesses: Building a Human Firewall
2025 Cybersecurity Threats Demand Immediate Action

Sources

  • CoreView, 2025 State of Microsoft 365 Security
  • BusinessWire, 68% of Organizations Under Attack: CoreView Reveals Microsoft 365 Security Risks
Shane Stevens, founder and CEO of CinchOps
About the Author

Shane Stevens

Shane Stevens is the founder and CEO of CinchOps, a managed IT and cybersecurity provider for small and mid-sized businesses across the Greater Houston area, including Katy. He brings more than 35 years of IT experience, including director, VP, and CTO roles at Tidal Software, Cisco, ABB, Delinea, Digital.ai, and NinjaOne, to keeping local businesses secure, efficient, and productive.

Read Shane’s story·Connect on LinkedIn

BLOG

Latest News & Articles

July 14th, 2026
Managed IT Pricing Houston
Managed IT Pricing in Houston: What SMBs Actually Pay in 2026

Managed IT Pricing In Houston, Finally Out In The Open – No Sales Call Required To Learn A Number

February 19th, 2026
Law Firm Cybersecurity
Cybersecurity for Law Firms in Sugar Land TX

Cybersecurity Built Around the Confidentiality Obligations Law Firms Actually Have – Local Cybersecurity Support for Law Firms Across Houston and Sugar Land

June 15th, 2026
Cybersecurity Housotn
Your Update Button Is Lying to You About Houston Cybersecurity

Patch Management vs Automatic Updates: What Houston Businesses Need to Know – Why MSP Patch Management Beats Turning On Automatic Updates

June 10th, 2025
Managed Services Provider Houston Cybersecurity
Google Account Vulnerability Exposed Users’ Phone Numbers Through Legacy Recovery System

Google Patches Vulnerability That Could Expose Private Phone Numbers in Minutes – Google Updates Account Recovery System Following Responsible Security Disclosure

March 12th, 2026
Texas Medical Devices
Texas Orders Cybersecurity Audit of Chinese-Made Medical Devices

What Houston Healthcare Businesses Should Know About the Texas Device Directive – State Prohibited Technology List Expands to Include Chinese Patient Monitors

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

BOOK A FREE CONSULTATION
281-269-6506
CinchOps managed IT services and cybersecurity Houston Texas
  • Home
  • Our Story
  • Reviews
  • FAQs
  • Contact
  • Sitemap
Contact info
  • 281-269-6506
  • info@cinchops.com
  • 2717 Commercial Center Blvd.
    Suite E200
    Katy, Texas, 77494

Services
  • Managed IT Services
  • Cybersecurity
  • Virtual CTO & CIO
  • Business Continuity & Disaster Recovery for Houston Businesses
  • Cloud Services
  • Business Process Automation for Houston Businesses
Service Areas
  • Brookshire
  • Cypress
  • Fulshear
  • Houston
  • Katy
  • Missouri City
  • Richmond
  • Rosenberg
  • Sealy
  • Sugar Land
  • The Woodlands
  • Tomball
©2026 CinchOps, LLC. All Rights Reserved.  | Privacy Policy