Skip to content

Cybersecurity

IT Security Assessment

We document the real security state of your infrastructure: what is exposed to the internet, who has access to what, whether backups actually restore, and what is not being patched. You receive a findings report ordered by severity, with a recommended action and a cost against each finding.

Who it is for

  • Businesses with no clear picture of their current state
  • Boards wanting evidence in writing before setting a budget
  • Companies that changed or lost their previous IT provider
  • Organisations wanting priorities rather than a list of fears

When we are NOT the right choice

  • If penetration testing is the requirement, which we do not undertake
  • If certification or legal compliance is the goal
  • If system access for the inventory is not granted

PROCESS

The process

Indicative times from signature of the proposal, subject to hardware availability. Every project is shaped to the size and the needs of the client.

  1. 01Scope agreement

    We define which systems are covered and what access is needed. The assessment is documentary, not offensive.Time: Before startingDeliverable: A defined scope and access points

  2. 02Exposure and access inventory

    We record what answers from the internet, which accounts are active, where MFA is missing, and which access has been forgotten.Time: 2-5 working daysDeliverable: Exposure and permission map

  3. 03Backup and patching review

    We check whether backups exist, whether they have ever been restore tested, and which systems have not received updates.Time: Alongside the inventoryDeliverable: Backup and patch status

  4. 04Findings report

    We deliver a report ranked by severity, with a recommended action and a cost per finding, and no unexplained jargon.Time: 5-10 working days in totalDeliverable: Findings by severity with costs

  5. 05Presentation and plan

    We present the findings to management and agree what is done now, what is scheduled, and what is accepted as risk.Time: After deliveryDeliverable: An agreed priority order

What is includedWhat is not included
Inventory of internet-facing exposurePenetration testing and offensive assessments
Review of accounts, permissions and MFA coverageCertification, legal compliance and related documentation
Verification that backups exist and have been testedStaff training
Patch status of systems and network equipmentImplementation of the fixes, which is quoted separately
Findings report by severity with a cost per action
Presentation of findings to management

Technology and equipment

  • Microsoft 365
  • Bitdefender
  • MikroTik RouterOS
  • Veeam
  • Synology
  • Windows / Windows Server

From practice

The assessment is not designed to alarm. It is designed to establish order. Almost every business has dozens of findings, but very few are genuinely urgent, and those are the ones that need to stand out.

The same three recur: a device exposed to the internet with factory credentials, accounts belonging to people who left still active, and a backup that has never been tested in a real restore.

Prerequisites

  • Read access to the systems in scope
  • Details of providers and contracts
  • A nominated point of contact
  • An agreed scope before work begins

Cost

Quoted as a standalone project with a fixed scope, so the deliverable stands on its own regardless of whether further work follows. Implementation of the fixes is quoted separately, based on the findings.

We do not publish a price list. Every proposal follows a site survey and separates hardware from labour.

What moves the cost

  • Number of systems and sites in scope
  • User count and permission complexity
  • Whether network equipment and servers are included
  • Whether documentation exists or is created from scratch

Frequently asked questions

What exactly do I receive at the end?

A written findings report ranked by severity, with a recommended action and a cost for each. The deliverable is yours and remains useful even if someone else carries out the fixes.

Is this a penetration test?

No. We do not attack your systems. We document the actual state: what is exposed, who has access, what is unpatched, and whether the backups restore.

How long does it take?

Typically 5 to 10 working days to delivery of the report, depending on scope. Time on the systems themselves is the smaller part of that.

Do you take on compliance projects?

No. We do not undertake certification or legal compliance work. We work on the technical measures and their operation, and we say so at the outset to avoid any misunderstanding.

NEXT STEP

Request an infrastructure security assessment

In 5 to 10 working days you receive a written findings report by severity, with a recommended action and cost per finding.

GET IN TOUCH

Tell us what you need

Four fields. An engineer replies, not a sales desk.

Fields marked * are required.

By sending this form you accept the processing of your details under our Privacy Policy.