IT & Security Assessment
Fixed fee. Quoted before we start. Yours to keep either way.
Most security failures don't come from a sophisticated attacker. They come from a misconfigured admin account, a backup nobody ever tested, or a compliance gap that stayed invisible until it mattered. This assessment finds those gaps before they find you.
This isn't a "free network assessment" with a sales pitch attached. It's a paid, fixed-fee engagement performed by the same engineers who'd be running your environment if you became a client — because that's exactly what we're evaluating.
What we do:
- Full network and endpoint security review. Firewall configuration, endpoint protection coverage, patch and vulnerability status, unauthorized devices on your network, wireless security, and remote access configuration.
- Microsoft 365 tenant and identity audit. MFA enforcement across every account, conditional access policies, admin role sprawl, legacy authentication protocols, external sharing and guest access, and mailbox rule review — the single most common vector we see in business email compromise cases.
- Backup verification. We don't take "the job completed successfully" at face value. We run an actual test restore and measure it against what your business actually needs to recover in a real incident.
- Compliance gap analysis. Mapped against whichever framework applies to you — HIPAA, CMMC/NIST 800-171, PCI-DSS, cyber insurance application requirements, or state breach notification law.
- Written findings with real numbers. A prioritized remediation roadmap ranked by actual risk, with real costs attached to each item — not a vague "improve your security posture" summary.
How it works:
You get a fixed fee, quoted after a short scoping call: never an hourly estimate, never a surprise invoice. We do the work, deliver the report, and walk you through it in person. The report is yours whether you hire us or not.
If you become a managed client afterward, the full assessment fee is credited toward onboarding. Net cost of finding out where you actually stand: zero.
Who this is for
- Leadership that will actually act on findings — not file the PDF and move on
- Businesses under compliance pressure: client contracts, cyber insurance renewal, or a regulatory requirement (HIPAA, CMMC, PCI)
- Businesses evaluating a new MSP who want an honest baseline before committing to anything
Who this isn't for
- Anyone using this as a free-quote fishing expedition with no intent to act on it
- Anyone expecting a "quick call" to substitute for the paid engagement — that's not what this is
Scope of work
1. Network & Endpoint Security Review
- Firewall rule and configuration review
- Endpoint protection / EDR coverage audit across all devices
- Patch and OS update status across servers and workstations
- Vulnerability scan of internal and external attack surface
- Rogue / unauthorized device detection on the network
- Wireless network security configuration
- VPN and remote access configuration review
2. Microsoft 365 Tenant & Identity Audit
- MFA enforcement status across all accounts, including service accounts
- Conditional access policy review
- Global admin and privileged role assignment audit
- Legacy authentication protocol status (should be disabled)
- External sharing and guest access configuration
- Mailbox rule and forwarding audit — the most common BEC vector
- Mobile device management / enrollment status
3. Backup Verification
- Backup job configuration and schedule review
- Actual test restore performed — not a "job succeeded" log check
- RTO/RPO measured against the client's stated recovery requirements
- Immutability / ransomware-resistant configuration check
- Retention policy and 3-2-1 backup rule compliance
4. Compliance Gap Analysis
- Framework mapping based on the client's applicable regulatory or contractual requirement (HIPAA, CMMC/NIST 800-171, PCI-DSS, state breach notification, cyber insurance application requirements)
- Gap list against the applicable framework
- Policy and documentation gap review — flags required written policies that don't exist yet
5. Written Findings Report
- Executive summary for ownership
- Detailed technical findings
- Risk-ranked prioritization — ranked by actual risk, not by what's cheapest or easiest to fix first
- Itemized remediation costs per finding
- Documented backup restore test results
- Compliance mapping matrix, where applicable
Process
- Scoping call (15–30 min) — sizes the fixed fee based on user count, endpoint count, site count, and regulatory profile. This is a sizing call, not a sales call.
- Data collection — remote tooling plus limited onsite time depending on scope.
- Analysis.
- Findings report delivered.
- Findings review meeting — we walk the report with leadership, in person or by video. Never an email drop.
Timeline
Typically, 10 to 15 business days from the scoping call to the findings review, depending on environment size and site count. We'll know after our scoping call.
Investment
- Fixed fee, quoted after the scoping call, never hourly, never a range
- No free consultation substitutes for this, and no discounting "just this once." A prospect who won't pay for the assessment isn't ready to be a managed client either. That's useful information, not a lost sale.
- If the prospect becomes a managed client, 100% of the fee is credited toward onboarding.
What this is not
- Not a penetration test: that's a separate, more invasive engagement, scoped on its own
- Not a remediation engagement: fixing findings is a separate SOW or becomes part of managed onboarding
- Not an ongoing monitoring service
- Not a trial period or a "get to know us" freebie