- Home
- Services
- Cybersecurity
- IT Security Assessment
Cybersecurity
IT Security Assessment
We document the real security state of your infrastructure: what is exposed to the internet, who has access to what, whether backups actually restore, and what is not being patched. You receive a findings report ordered by severity, with a recommended action and a cost against each finding.
Who it is for
- Businesses with no clear picture of their current state
- Boards wanting evidence in writing before setting a budget
- Companies that changed or lost their previous IT provider
- Organisations wanting priorities rather than a list of fears
When we are NOT the right choice
- If penetration testing is the requirement, which we do not undertake
- If certification or legal compliance is the goal
- If system access for the inventory is not granted
PROCESS
The process
Indicative times from signature of the proposal, subject to hardware availability. Every project is shaped to the size and the needs of the client.
01Scope agreement
We define which systems are covered and what access is needed. The assessment is documentary, not offensive.Time: Before startingDeliverable: A defined scope and access points
02Exposure and access inventory
We record what answers from the internet, which accounts are active, where MFA is missing, and which access has been forgotten.Time: 2-5 working daysDeliverable: Exposure and permission map
03Backup and patching review
We check whether backups exist, whether they have ever been restore tested, and which systems have not received updates.Time: Alongside the inventoryDeliverable: Backup and patch status
04Findings report
We deliver a report ranked by severity, with a recommended action and a cost per finding, and no unexplained jargon.Time: 5-10 working days in totalDeliverable: Findings by severity with costs
05Presentation and plan
We present the findings to management and agree what is done now, what is scheduled, and what is accepted as risk.Time: After deliveryDeliverable: An agreed priority order
| What is included | What is not included |
|---|---|
| Inventory of internet-facing exposure | Penetration testing and offensive assessments |
| Review of accounts, permissions and MFA coverage | Certification, legal compliance and related documentation |
| Verification that backups exist and have been tested | Staff training |
| Patch status of systems and network equipment | Implementation of the fixes, which is quoted separately |
| Findings report by severity with a cost per action | |
| Presentation of findings to management |
Technology and equipment
- Microsoft 365
- Bitdefender
- MikroTik RouterOS
- Veeam
- Synology
- Windows / Windows Server
From practice
The assessment is not designed to alarm. It is designed to establish order. Almost every business has dozens of findings, but very few are genuinely urgent, and those are the ones that need to stand out.
The same three recur: a device exposed to the internet with factory credentials, accounts belonging to people who left still active, and a backup that has never been tested in a real restore.
Prerequisites
- Read access to the systems in scope
- Details of providers and contracts
- A nominated point of contact
- An agreed scope before work begins
Cost
Quoted as a standalone project with a fixed scope, so the deliverable stands on its own regardless of whether further work follows. Implementation of the fixes is quoted separately, based on the findings.
We do not publish a price list. Every proposal follows a site survey and separates hardware from labour.
What moves the cost
- Number of systems and sites in scope
- User count and permission complexity
- Whether network equipment and servers are included
- Whether documentation exists or is created from scratch
Frequently asked questions
What exactly do I receive at the end?
Is this a penetration test?
How long does it take?
Do you take on compliance projects?
Related services
- Endpoint Protection & EDRendpoint protection edrSee the service
- Email Security & Phishing Protectionemail security phishing protectionSee the service
- Business Backup Solutionsbusiness backup solutionsSee the service
- Managed IT Servicesmanaged it servicesSee the service
Also connects with
NEXT STEP
Request an infrastructure security assessment
In 5 to 10 working days you receive a written findings report by severity, with a recommended action and cost per finding.
GET IN TOUCH
Tell us what you need
Four fields. An engineer replies, not a sales desk.