The IT & Security Assessment
A working engineer spends time inside your environment and delivers a written assessment: where your security actually stands, what your real exposure is, what it will cost to fix, and what it will cost you not to.
You get
- Full network and endpoint security review
- Microsoft 365 tenant and identity configuration audit
- Backup verification, we test whether your backups actually restore
- Compliance gap analysis against your industry's requirements
- Written findings with prioritized remediation and real costs
This is a paid, fixed-fee engagement, quoted before we schedule the work. You keep the report whether you hire us or not, and if you become a managed client the full assessment fee is credited toward onboarding.
Why we charge for it
Free assessments are sales calls with a checklist attached. This is real senior engineering time and a real deliverable. Charging for it means we can afford to do it properly, and it means the businesses who book it are serious.
Payment: ACH, credit card, or business check, invoiced after we confirm scope on a short intake call. Talk to a real engineer, not a sales rep.
Request the Assessment
What the engagement actually looks like
The assessment starts with a short intake call to confirm scope: how many users and devices you have, what your servers and network look like, whether any part of your business is regulated, and what problem prompted the call. Scope drives the fixed fee, and we quote it before any work begins so there are no change orders in the middle.
From there an engineer works inside your environment, not around it. We inventory endpoints and servers, review Microsoft 365 identity and conditional access, look at how administrative access is granted and removed, examine firewall and network segmentation, and check whether your backups are running and whether a restore has ever been tested. Where relevant, we look at the plant floor and operational technology separately from the office network, because those systems cannot be patched on the same cycle.
What you receive
The deliverable is a written report, not a slide deck. It states what we found, what the practical risk is in business terms, and what remediation costs. Findings are prioritized: what should be fixed this month, what belongs in a project over the next quarter, and what is acceptable to leave alone for now. Where a gap has a compliance implementation under CMMC, NIST 800-171, HIPAA, or PCI DSS, we say which control it maps to.
The report is yours regardless of what you do next. Some clients hand it to their internal team, some use it to hold an existing provider accountable, and some use it as the scope document for managed IT services or co-managed IT with us. If you become a managed client, the full assessment fee is credited toward onboarding.
Who this is for
This fits businesses that have outgrown informal IT, companies preparing for a cyber insurance application or a customer security questionnaire, manufacturers facing defense-supply-chain requirements, and organizations that suspect their current provider is not doing what the invoice implies. It is not a good fit if you want a free sales call with a checklist attached, and it is not a penetration test.
Timeline
Most assessments are scheduled within one to two weeks of the intake call, fieldwork takes a few days depending on size, and the written report follows shortly after. We review it with you line by line so nothing in it is a surprise.