Independent and assessment-first.
Four ways to engage, and one place to start: a fixed-price, read-only assessment of where you actually stand. From there, Mount Xion fixes the findings, governs the AI rollout, and trains your people. Every engagement ends with something your board can read.
Microsoft 365 Identity Security Assessment
Know exactly where you stand, with evidence, not vendor fear.
Most Microsoft 365 breaches start with identity: a sign-in that should have been challenged, an account with more access than it needs, a setting nobody has looked at since the tenant was created. Account takeover, business email compromise, and the payment fraud that follows usually begin there. This assessment reviews those controls setting by setting, with evidence for every finding, never a vendor's opinion.
The review is read-only, with access you can revoke at any time and no software installed on your devices. When collection is complete, our principal leads one 90-minute readout with your team, or your IT provider, against the prepared deliverables. Fixed price, and you know it before work begins.
The 34 controls reviewed map to the CISA SCuBA baseline for Microsoft Entra ID and the derived NIST SP 800-53 Rev. 5 controls, so the evidence does double duty for cyber-insurance renewals, auditors, and customer security questionnaires.
Best for
- A board or auditor asking "how secure are we?"
- Cyber-insurance renewals with new requirements
- Customer security questionnaires
- Post-incident "make sure this never happens again"
- A second opinion on your current configuration
The review covers
- Administrator roles and standing privileged access
- How far multifactor really reaches
- Sign-in and access policies, setting by setting
- Guest accounts, shared logins, and what happens when someone leaves
- Standing vendor and third-party app access
- Whether emergency access, audit logging, and security alerts are set up
You receive
- A triaged findings report in plain English, with the evidence behind each finding
- A remediation runbook your staff, your MSP, or Mount Xion can execute, every change with its own rollback and verification step
- An executive scorecard written for an owner or a board
- One 90-minute readout, walking your team through all three
Also available, separately scoped
- Endpoint Posture Assessment. The devices your people work on, scored on their own: enrolled and inventoried, kept compliant, encrypted, actively managed with update policies, and covered by endpoint protection with fresh risk signals. Read-only evidence, with its own scorecard and findings.
- PCI DSS Readiness Check. For businesses that take card payments and face the annual self-assessment questionnaire. Which questionnaire applies to each way you take cards, every applicable requirement reviewed with evidence, and an executive readiness summary plus a gap register your team can work from. Readiness against PCI DSS v4.0.1: the attestation to your acquirer stays yours, and a merchant whose setup calls for a Qualified Security Assessor gets a straight referral.
- CMMC readiness (NIST SP 800-171 Rev. 2) for defense suppliers, described under Government & teaming.
Security Remediation
The findings, fixed, so your team's capacity stays on the business instead of chasing security fixes.
Every assessment ends with a remediation runbook. Some organizations execute it themselves; many simply don't have the hands or the hours. This engagement is Mount Xion doing the fixing: hands-on, in your tenant, task by task, working alongside your internal team or your MSP.
The work is sequenced the way risk actually falls: identity and admin access first, then devices and email, then data protection and recovery. Each completed task is evidenced, so the after-state is something you can hand to an insurer, an auditor, or a customer rather than assert.
Fixed scope, shaped with you and built directly from the runbook you already hold. When it's done, the finding count is lower, and provably so.
Best for
- Assessment findings with no one free to fix them
- Insurance renewals with conditions attached
- Fixes that need to be evidenced, not asserted
- Working alongside your internal team or MSP
Governed AI Adoption
Responsible AI rollouts that actually stick.
Staff are already using AI. The only question is whether it's governed. This practice takes an organization from "people pasting into free chatbots" to a measured, policy-backed rollout: tool selection, acceptable-use policy, staff training, and adoption you can measure.
Governance comes first: data access and oversharing cleaned up before AI can surface it, sensitivity labels and retention on the content it can read, and policy written before licenses are bought. Donor and client data never trains someone else's model.
The playbook is proven: in a rollout our principal led before founding Mount Xion, 100% of staff were onboarded to enterprise AI with guardrails in place from day one, reaching 98% daily active use and 4.0/5 staff satisfaction.
Best for
- An AI mandate from the board with no plan behind it
- Staff already using unsanctioned AI tools
- Copilot or Claude licenses bought but unused
- Writing an acceptable-use policy that people follow
Staff AI Training
One training practice, two tailored tracks: AI fluency and security awareness, built around your tools, your policies, and your people.
Tailored, not templated. Every program starts with a short needs assessment: the tools you already pay for, what your teams actually do all day, and where training can genuinely help. From there the curriculum is built around your organization, with tracks that meet people where they are and sessions shaped for leadership, everyday users, and the in-house champions who will carry it forward.
The AI track, hands-on and on real work. No hype, no jargon, no canned demos. Sessions cover what today's leading AI tools do brilliantly and where they fail, then put people to work on their own drafting, summarizing, and analysis, with plain rules for what never goes into a chatbot. Your team leaves able to use it the very next day. Proven at organization scale: a rollout our principal taught before founding Mount Xion reached 100% staff usage, with 98% using AI daily.
The security awareness track, same discipline. Sessions built around the scams your staff actually see: phishing, payment fraud, AI-voice and deepfake impersonation, with simple rules people remember under pressure and a cadence that keeps it alive without nagging. Delivered standalone, or folded into the AI program as one curriculum.
Formats
- Half-day essentials workshop
- Full-day deep dive
- Multi-week program with tracks
- Security awareness sessions, standalone or paired
- Onsite, virtual, or hybrid
Built around
- The AI tools your organization approves, in the stack you already run
- Leadership briefings and staff sessions
- An AI-champions track for your power users, up to building their own agents
- Your acceptable-use policy, or one written with you
- Delivery from a half-day workshop to a multi-week program, onsite, virtual, or hybrid, closing with a simple measurement plan
Fractional CISO
Ongoing security leadership after the assessment, without adding a full-time salary.
Most organizations under a few hundred staff can't justify a full-time IT Director or CISO, so nobody truly owns technology risk: tickets get executed, finance signs renewals, and decisions happen by default. This retainer closes that gap, and it is where an assessment often leads once leadership has seen the whole picture.
On a monthly retainer, our principal functions as your technology executive: setting strategy, owning the budget, directing vendors with no reseller commissions ever, and reporting to leadership and the board in plain language. We work alongside your internal team or your MSP; we don't replace either one.
A typical month: a leadership working session, vendor and project direction, a posture review tracked against last month, and a written executive report your board can read in five minutes. Underneath it runs ITIL 4 service-management discipline: change controlled rather than improvised, and every service with a named owner.
The retainer carries
- Strategy and board reporting: a roadmap tied to your strategic plan, a defensible budget, and the policy set auditors and cyber insurers ask for by name
- Vendor and third-party oversight: contracts and SLAs reviewed, licensing right-sized, overlapping tools consolidated
- Incident advisory: a clear head through business email compromise and payment fraud; for a large-scale breach, Mount Xion helps you engage a specialist firm, direct it, and translate its work for leadership
Best for
- An assessment done, and leadership wanting an owner
- Boards asking security questions no one can answer
- Leaders signing technology contracts on faith
- A first named owner for technology risk, right-sized
Sources you can look up.
The assessment's 34 controls map to the CISA SCuBA baseline for Microsoft Entra ID and the derived NIST SP 800-53 Rev. 5 controls. Every finding names the specific setting, cites the published Microsoft guidance behind it, and is captured as evidence at review time. Nothing rests on Mount Xion's say-so.
A career of technology governed under federal inspection, where a control was either evidenced or it did not exist.
What carries over is the habit of proving a control rather than asserting it.
Worked in daily
Entra ID, Intune, Defender, Purview, SharePoint and OneDrive, Exchange Online, Power Platform, and Copilot, administered and secured in production, not read about.
Built to team.
For primes and Texas DIR contract holders carrying small business and veteran subcontracting goals.
Mount Xion delivers Microsoft 365 security assessment and hardening, CMMC readiness (NIST SP 800-171 Rev. 2), and AI governance as a subcontractor or teaming partner, from San Antonio, minutes from JBSA and the VA's South Texas market.
CMMC Level 2 readiness covers all 110 NIST SP 800-171 Rev. 2 controls, with five prepared deliverables and a self-assessment score computed under the CMMC scoring methodology in 32 CFR 170.24. Readiness support only: your designated official submits the score to SPRS and completes the affirmation, and Mount Xion is not a C3PAO.
Veteran-owned Texas LLC. Active SAM.gov registration: CAGE 23T24, UEI HFK5Q7AF1ZN8. Capability statement available on request.
Teaming scope
- Microsoft 365 security assessment and hardening
- CMMC readiness (NIST SP 800-171 Rev. 2)
- AI governance and staff enablement
- Veteran-owned · San Antonio, minutes from JBSA
- SAM.gov Active · CAGE 23T24 · UEI HFK5Q7AF1ZN8