Comply or Cry

Microsoft 365 video series

With compliance frameworks multiplying, regulatory pressure has never been higher. Comply or Cry goes framework by framework through what actually matters: what you're required to do, why the framework exists, and what it means in practice for MSPs managing clients at scale. 

Comply or Cry - Episode 1: Why Everyone's Crying

In this first episode, Microsoft 365 Solutions Architects Dakota McElligott and Tim Oelkers map the landscape: why frameworks exist, what they want, and the critical difference between what you're required to do versus what's merely recommended.

Comply or Cry - Episode 2: DORA

DORA is law, not guidance. In this episode, Tim Oelkers tells you exactly what's required - incident reporting timelines, ICT risk management, third-party oversight - and which M365 controls satisfy it. Plus: where M365 stops and your wider programme must take over.

 

Episode 3: CIS Controls v8
Comply or Cry - Episode 3: CIS Controls v8

Not legally required, but one of the most practical frameworks available. This session maps CIS Controls v8 directly to M365 configuration - identity, endpoints, logging, data protection - and explains why 'configured' and 'enforced' are not the same thing across multi-tenant environments.

 

Register now

 

Group 47862
Comply or Cry - Episode 4: Cyber Essentials

Cyber Essentials is a condition of many UK public sector contracts - and assessors will find gaps if you're not ready. This episode covers what the certification actually requires inside M365, what sits outside it, and how to stay audit-ready between renewals without the last-minute scramble.

 

Register now

 

Group 47863
Comply or Cry - Episode 5: NIS2 - Driving Pain

NIS2 expanded scope, tightened timelines, and put board-level accountability on the table. If your clients are in energy, health, transport, or digital infrastructure across the EU, this session covers what they must demonstrate - and where M365 controls either deliver or fall short.

 

Register now

 

Group 47864
Comply or Cry - Episode 6: NIST CSF 2.0 & 800-171

NIST is the common language of enterprise security - and 800-171 is mandatory for anyone in the US defence supply chain. This episode maps the Identify–Protect–Detect–Respond–Recover functions directly to M365, and shows what auditors, insurers, and procurement teams will want to see.

 

Register now

 

Episode 7: Making it Real at Scale
Comply or Cry - Episode 7: Making it Real at Scale

NIST is the common language of enterprise security - and 800-171 is mandatory for anyone in the US defence supply chain. This episode maps the Identify–Protect–Detect–Respond–Recover functions directly to M365, and shows what auditors, insurers, and procurement teams will want to see.

 

Register now

 

Episode 1: Why Everyone's Crying
Episode 1: Why Everyone's Crying

Episode 2
Episode 2: DORA

Episode 3: CIS Controls v8
Episode 3: CIS Controls v8

Group 47862
Episode 4: Cyber Essentials

Group 47863
Episode 5: NIS2 - Driving Pain

Group 47864
Episode 6: NIST CSF 2.0 & 800-171

Episode 7: Making it Real at Scale
Episode 7: Making it Real at Scale