Skip to main content

Sep 4, 2026

Beyond CIS: The Posture Risks Your Benchmark Doesn't Cover

CIS is the essential baseline for Microsoft 365 security, but it can't track what attackers are exploiting this quarter. See how Abnormal's threat-led postures close the gap.

Key Insights

CIS provides a strong Microsoft 365 baseline, but fixed benchmarks can lag behind emerging attack techniques.

Threat-led postures help surface active risks that traditional benchmark controls may not yet cover.

Behavioral and threat intelligence can help security teams prioritize the cloud gaps attackers are exploiting now.

Every Microsoft 365 security team should be running the CIS Benchmark. It's the industry's vetted, consensus-built baseline for secure configuration, and it belongs in every Security Posture Management program, including ours. But CIS is built by committee on a fixed release cycle.

What a benchmark can't do, by design, is track what's being exploited in a live tenant this quarter. Across the 398 Microsoft 365 tenants in Abnormal's SPM base, 85% were non-compliant on a spoofing technique called Direct Send, a misconfiguration adjacent to the forwarding controls CIS already checks, but never named directly. That's not a knock on CIS. It's a look at how long a consensus process takes to catch up to a live attack technique.

CIS_Benchmark_Product_1.png
Snapshot of some of the threat-led postures now available in Security Posture Management.

To explore how Abnormal closes the gaps CIS, NIST, and CISA benchmarks structurally can't cover, schedule a demo.

Schedule a Demo

Where the Gap Actually Shows Up

A benchmark control only ships once a working group agrees it's broadly applicable, a process that takes months. In the meantime, security teams are left asking the same question in every renewal and every board update: are we covered against what's happening right now, not what was flagged last year? That gap is the hardest one to show progress against, because a clean CIS scorecard doesn't mean much if the technique an attacker is using today was never in scope.

How the Threat-Led Postures Close It

Abnormal's threat intel team built a companion layer inside SPM specifically for this: a set of postures, branded the Abnormal Threat-Led Benchmark, that starts with an active attack pattern instead of a committee vote. Each one gets mapped to MITRE ATT&CK and shipped as an evaluation the moment it's validated, sitting next to the closest CIS control rather than replacing it.

A few postures now live in production show what that looks like:

  • Direct Send internal spoofing (85% of tenants non-compliant): CIS 6.2.1 covers mail forwarding and CIS 2.1.5 covers Safe Links, but neither catches mail spoofed to look like it originated internally.

  • Mailbox-level SMTP forwarding (95% of tenants non-compliant): CIS blocks forwarding tenant-wide at the transport-rule level. It can't alert in real time when an attacker sets forwarding on a single compromised mailbox, which is exactly how BEC actors keep reading an inbox after the initial breach.

  • Suspicious transport rule creation (24% of tenants non-compliant): CIS checks that existing rules don't whitelist malicious domains on a schedule. It has no way to catch an attacker who compromises an admin account, creates a rule, exfiltrates mail, and deletes the rule before the next review.

  • Teams phishing from trial tenants (under 1% of tenants, and rising): free, disposable Microsoft 365 trial tenants used for Teams-based phishing aren't referenced anywhere in CIS, NIST, or CISA guidance today.

The same pipeline extends past email. When Iran-aligned threat groups escalated operations earlier this year, Abnormal's threat intel team traced a pattern of email-based initial access followed by lateral movement through privileged roles and poorly managed devices, and shipped new SPM postures for privileged role escalation and Intune device management within weeks of the pattern emerging.

None of this replaces CIS, and it isn't meant to. Run the benchmark for the baseline every Microsoft 365 tenant should meet. Run the threat-led postures for the handful of techniques attackers are using in between benchmark releases, the ones a committee vote hasn't caught up to yet. If you're already running Microsoft 365 SPM, check the Evaluations page for postures tagged with threat context, and export the results as a CSV for your next audit or board update.

To see which of these gaps your own environment is exposed to, schedule a demo with Abnormal.

Schedule a Demo

Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.