Cybersecurity assessment
A review of how your firewalls, endpoint protection, backups and access control are actually configured and used, with findings in writing and in priority order.
Who it is for
Companies that have grown their IT without a review, that are asked security questions by customers or auditors, or that want to know where to spend first.
What is in scope
Network perimeter
- Firewall configuration and rules
- Remote-access arrangements
- Separation between networks, as built
Devices
- Endpoint protection coverage and status
- Patch status of operating systems
- Administrator rights on devices
Backups
- What is backed up and where the copies are kept
- Whether copies are separate from the live systems
- Whether a restore has been tested
Access control
- User and administrator accounts
- Multi-factor authentication, where it is available
- How leavers are removed, and shared accounts
What you receive
- A written report with findings in priority order and the evidence for each
- A remediation list with the effort and the order
- A walk-through of the findings with your team
What we need from you
- Read-only access to configurations, or screen-shares
- A contact in IT, or whoever knows the history of the set-up
- The list of critical systems and where they run
- Any framework you are held to, so findings can be written against it
How it is quoted
Custom and itemised by what is in scope.
What shapes the quote
- Number of sites
- Firewalls and network equipment
- Number of endpoints and servers
- Systems and accounts in scope
Questions about the assessment
Will you fix what you find?
The findings come first. Fixing is scoped separately, and you can use us or your own team.
Do you test our systems from the internet?
Not as part of this assessment, which reviews configuration and practice. If you need external testing, tell us, and the proposal says whether we do it or whether you need a specialist.
Can you assess against a framework we are held to?
Tell us which one before scoping, for example the National Cybersecurity Authority’s Essential Cybersecurity Controls. The proposal says how far findings can be written against it.
Will you need administrator access?
We ask for read-only access, or a screen-share with someone who has it. We do not change anything during the assessment.
What do we get at the end?
A written report in priority order, a remediation list and a walk-through with your team.
Related pages
Find out where you stand.
Tell us roughly how many sites, devices and servers you have. We reply with next steps and what we would review.