Security and risk assessment
Where your exposure actually is: identity, endpoints, email, backups, and access. Findings ranked by risk and by how much effort each fix requires.
Home › IT Consulting & Assessments
An independent read on where your technology actually stands — findings ranked by risk and cost, written so you can act on them without needing us to explain what they mean.
A server fails, a client sends a security questionnaire, an insurer asks about controls, or someone quotes a number and nobody in the room can judge whether it's reasonable.
Decisions made that way tend to be expensive. You buy what's in front of you rather than what you need, or you delay because you can't evaluate the options and the delay costs more than either choice would have.
An assessment moves that decision earlier, when you have time. We look at what you're running, what it costs, what's exposed, and what's approaching end of life — then hand you a prioritized list. What to fix now, what to plan for, what to ignore, and roughly what each costs.
The report is yours. Take it to us, to your current provider, or to anyone else. It's more useful to you if it isn't a sales document, so we don't write it as one.
Scoped to the decision you're facing rather than a fixed checklist applied to everyone.
Where your exposure actually is: identity, endpoints, email, backups, and access. Findings ranked by risk and by how much effort each fix requires.
What needs replacing and when, what it costs, and in what order — over one to three years. Turns technology spending from reactive into planned.
An independent review of work another provider has recommended or delivered. Either confirmation they're doing well, or specific questions worth asking them.
Whether a proposed product solves your problem, whether you already own something that does, and what the real cost looks like after the first year.
Help answering security questionnaires accurately, identifying which gaps are blocking the contract and which can be addressed later.
Technology review during an acquisition or merger: what you're inheriting, what it will cost to integrate, and what liabilities come with it.
Consulting deliverables are easy to make vague. Here's specifically what arrives.
Findings in plain language, each with what we found, why it matters, and what fixing it involves. Written for an owner or operations lead, not for another engineer.
Ordered by risk against effort, so the first three items are genuinely the first three things to do. An unranked list of thirty findings is a way of avoiding a recommendation.
Order-of-magnitude figures for each recommendation, so you can build a budget rather than discovering cost only after committing.
A record of what you have — devices, licences, services, vendors, and renewal dates. Many businesses have never had this written down anywhere.
The free assessment is a familiar sales motion, and it produces predictable findings.
When an assessment is free, it's a lead generator. The findings tend to align with what the provider sells, because there's no other way for that work to be paid for. Everyone in the industry knows this, including the businesses receiving the reports.
Charging for the assessment means the report can say your current provider is doing fine, that you don't need the thing someone quoted you for, or that the right answer is to do nothing for eighteen months. Those conclusions are worth as much as any recommendation to buy.
We do offer a free initial consultation to understand your situation and decide whether an assessment is even the right step. That's different from a free assessment, and we'd rather be clear about which is which.
A written report of findings ranked by risk and effort, with rough costs and a suggested order of work. Written for a non-technical reader, and yours to take to any provider.
No. Assessments are billed separately so the findings aren't a sales document. Some things you can fix yourself, some belong to your existing provider, some aren't worth fixing. We say which.
Under 50 users, typically one to two weeks from kickoff to report. Most of that is our discovery and analysis — we usually need a few hours of your team's time.
Yes, and it's common. It either confirms they're doing good work — worth knowing — or surfaces gaps worth raising with them. A confident provider won't mind being checked.
Yes. We help you answer accurately, identify what you don't currently meet, and separate the gaps blocking the contract from the ones that can wait.
What needs replacing and when, what it costs, and in what order over one to three years — so hardware failures stop being budget surprises.
Ongoing support, if the assessment concludes that's what you need.
Implementing the security findings an assessment surfaces.
Site surveys and network review as part of a broader assessment.
Tell us what decision you're facing. The initial consultation is free, and part of its job is telling you whether a paid assessment is worth it.