The Dangers of Default Settings (And Why They Won’t Get You Compliant)
When it comes to cybersecurity, the biggest risk often isn’t doing nothing, it’s assuming that what you have already is good enough. This is the exact trap many businesses fall into when they rely on default security settings in platforms like Microsoft 365 or AWS (Amazon Web Services).
These tools are powerful and widely used for a reason. They come with all the right building blocks to ensure a strong security posture: encryption, multi-factor authentication (MFA), activity logging, and access controls. But there’s a significant catch. These features don’t come pre-configured for compliance. In fact, many of them are disabled by default to improve customer experience.
This is where businesses, especially small and medium-sized ones, can unknowingly fall short. Just because a platform is technically capable of achieving compliance, or the provider themself is compliant, doesn’t mean that your environment is also automatically aligned with these standards. And if you’re relying on what came as default, it’s likely not enough, both from a compliance and security perspective.
Why Default Settings Aren’t Compliant
Let’s take Microsoft 365 as an example. Out of the box, users can access company data from any device, anywhere, with little control or monitoring. MFA might be suggested, but it’s often not enforced. Audit logging, which is crucial if you ever need to investigate an incident, is disabled by default unless you manually enable it. Even break-glass or emergency admin accounts, which are essential components in responding to security incidents, aren’t preconfigured or protected by any policies.
In AWS, it’s a similar story. A storage bucket can be accidentally opened to the public. Permissions are often overly broad, giving users far more access than they need, with accounts running around with unnecessary root access.
None of these defaults settings are intended to be malicious. They’re designed to get users up and running as quickly as possible. But speed often comes at the cost of security. And when you go for certification, an audit comes around, or you are targeted for a cyber attack, it’s not the available tools that matter, it’s whether they’re active, configured correctly, and in use across the organisation.
Compliance Requires More Than Just Features
Frameworks like Cyber Essentials are clear in what they expect. It's not enough to say you can enforce MFA, you still need to demonstrate that you actively have this in place. It’s not enough that your cloud provider offers logging, you need to show it’s switched on, regularly reviewed, and retained for an appropriate period of time. This is especially true for security standards like Cyber Essentials Plus, where an external penetration test is required to verify that you have the correct controls in place, rather than simply taking your word for it on a self-assessed questionnaire.
What’s more, it’s not just about passing a point-in-time audit. Maintaining compliance means these settings need to stay in place over time, even as new users are added, services are rolled out, or changes are made by mistake. Without visibility and ongoing checks, it's easy to drift away from compliance without realising it.
Why This Hits Smaller Teams Hardest
For large businesses, staying compliant often means dedicating people or even entire teams to configuration management and monitoring. But most smaller businesses won’t have that luxury. They rely on platforms like Microsoft 365 or AWS because they’re trusted and come with good reputations for security. It’s easy to assume that “secure by default” means “compliant by default.” Unfortunately, that’s rarely ever true.
Businesses will frequently fail their compliance renewals because they migrated to Microsoft 365 and assumed everything was already set up correctly. Others have used cloud platforms for years without realising critical logging features weren’t enabled, or that old user accounts were still active with full admin permissions.
These are all preventable problems, and often quickly fixed, but only if you know what to look for, and have the tools to stay on top of it, especially in businesses where resources are already stretched to breaking point.
How OneClickComply Helps Fixes These Issues
OneClickComply is built to help businesses move beyond default settings and actually implement the security controls that compliance frameworks demand.
Instead of just flagging issues for you to fix manually, our platform checks your environment, provides a check-list, then allows you to automatically change the necessary settings to meet the requirements of the standard. If MFA isn’t properly enforced, we apply the necessary change. If logging is turned off, we enable it. If a user has excessive access to business systems, the appropriate changes are made to remedy this and ensure it doesn’t happen again.
And we don’t stop after the first fix. OneClickComply continually monitoring your systems in the background, so if something changes, whether accidentally or as part of an update, you stay informed and compliant at the same time.
This not only takes the pressure off your team and avoids last-minute scrambles, but most importantly, it helps protect your business day-to-day.
Final Thoughts
Default settings are designed for convenience, not compliance. They’re there to make it easy to get started, not to help you meet a standard or secure sensitive data.
If you're relying on what comes out of the box, you may have gaps in your security posture that aren't obvious until they cause a problem, or until they’re brought to light by an audit or security incident.
With OneClickComply, you get visibility, effortless automation, and ongoing peace of mind. We help make sure your systems are actually secure and compliant, at a fraction of the time and cost.