Joint Organizational Understanding of Systems and Technology. One thousand dollars, flat. Fifteen areas of the business examined. A written report you keep, and a list of what to fix in what order. Partner with us within twelve months and the fee comes back off your account.
A free audit is a sales call with a spreadsheet attached
Every provider in this market will assess your environment for nothing, and the finding is always the same: you need what they sell. We charge for this because a paid piece of work has to stand on its own. You can take the report to your board, to your carrier, or to a competitor of ours. It has to hold up in all three rooms.
Findings you can act on
Every conclusion says what we found and why it matters, in language you can put in front of a board or a carrier. A vague assurance gets you nowhere in either room.
An order, and a price
A list of gaps helps nobody. This one comes back as a sequence, with a cost against each step and a reason it sits where it does.
The paperwork counts too
Policies, insurance answers, vendor contracts, and who holds the passwords if a key person leaves. None of that is a technical question, and almost no technical review goes near it. All of it gets read in an audit or a claim.
The scope
Thirteen conversations, and two we go and find out ourselves
Thirteen of these are worked through with you and whoever currently looks after your technology. The last two we do on our own and bring back, because the answer is more useful when nobody has tidied up first.
1 · Governance and risk
Decision rights and spending authority. What the business has written down about acceptable use and personal devices, and whether anybody has read it since. We also record the risks leadership already knows about and has chosen to live with. That is a legitimate position, and putting it on paper protects the person who took it.
2 · Access and identity
Where multifactor is on and where it quietly is not. Who holds administrator rights and why. How passwords get shared between people, and whether anyone who left last year can still sign in. Most incidents start here, so this section usually runs long.
3 · Endpoints and servers
Every machine gets counted and aged. We check encryption and where the recovery keys live, flag anything running an operating system that stopped getting patches, and mark the equipment that has passed the point where a repair is worth paying for.
4 · Network and perimeter
Firewalls, their firmware age, and what is reachable from outside. Some of that exposure is deliberate and some of it nobody remembers opening. We also look at guest wireless, and at whether the equipment running the building shares a network with the people running the business.
5 · Email and collaboration
Whether your domain is authenticated so other people cannot send mail as you. How sharing works in Microsoft 365 or Google Workspace, and what an external guest can reach once invited to a single file. We also go looking for company documents sitting outside both.
6 · Backup and recovery
Coverage first, then the gaps. Whether a copy exists that an intruder holding your administrator password cannot delete, and how long a full restore would take on your own equipment. The recovery page covers what a good answer looks like.
7 · Incident response and logging
Whether a plan exists with names and phone numbers in it, and who is authorized to take the network offline at 11 PM without calling a meeting first. We also check how long your logs are kept, since a week of retention leaves nothing to investigate with.
8 · Vendors and contracts
Who holds a login to your systems from outside the company, and what their contract obliges them to do when something goes wrong. Renewal dates get collected in one place. So do the subscriptions still billing for people or projects that ended.
9 · Compliance and data privacy
Which obligations apply to your business, from client contract clauses through to whatever your industry regulator expects. Then where the evidence for each one would come from if somebody asked tomorrow. We name the gap; your counsel rules on it.
10 · Awareness and training
Whether anyone has been taught what a wire fraud attempt looks like at your firm specifically, and what happens when somebody clicks. An annual video nobody finished still counts as an answer. It is worth knowing that is the answer before a carrier asks for it.
11 · Cyber liability insurance
We read your policy and your last application side by side with what we found, and flag anything you have attested to that is no longer true. That is the answer a carrier cares about at renewal, and the cyber insurance page goes through the control list they verify.
12 · HR and technology policy
What a new hire signs, and what a departing one is required to hand back. Who removes their access, and how quickly. Whether anything is written down about staff putting company documents into consumer AI tools. The AI policy page has a template for that last one.
13 · Technology succession
What happens if the one person who understands your systems takes another job. Where the passwords are. Who owns the domain name, and whose personal account the certificate quietly renews on. How much of the operation lives in one person's head. Nobody enjoys this section and everybody needs it.
14 · What the internet already knows about you
An outside look, done the way somebody targeting you would do it: which of your addresses and passwords are sitting in public breach data. What your domain records give away, and what is answering on your public addresses. Who on your staff would be easy to impersonate from their own posts.
15 · A snapshot from inside
A read-only look at the live environment, so the report rests on what the systems say and not only on what everyone believes. It runs during business hours and changes nothing. It also turns up two or three machines nobody knew were still switched on, most times we do it.
The deliverable
What lands on your desk at the end
Three documents and a meeting, about two weeks after we finish gathering. All of it is yours, with no marking that stops you sending it to somebody else.
The written report
One section per area: what we found, and what it means for the business rather than for the equipment. Written to be read by somebody who does not work in technology, with the technical detail kept in an appendix for whoever does.
A remediation list in order, with costs
Every gap, ranked by what it would cost you if it went wrong against what it costs to close. Rough figures against each line, including the ones you would pay somebody else to do, and a note on what changes if you defer it a year.
A budget you can take to a board
The next twelve to twenty-four months laid out by quarter, separating the equipment that is aging out from the work that reduces risk, so the two do not compete for the same conversation.
Ninety minutes to walk it through
A readout with whoever should be in the room. You question the rankings, and we either explain them or change them. The version you keep is the one you agreed to.
Timing
Four moments when this pays for itself
Firms rarely book an assessment out of curiosity. There is usually a date on a calendar behind it.
A renewal or a questionnaire is coming
A cyber insurance renewal, a client security questionnaire, or a prime contractor asking you to attest to controls you have never been asked about before. Signing something inaccurate is the expensive outcome, and it is worth ninety days of notice to avoid it.
You are unsure whether you are being looked after
Nothing is obviously broken and the invoices arrive. You have no way to judge whether that is good work or good luck. An outside read gives you something to hold the current arrangement against, and plenty of assessments end with us saying your provider is doing fine.
The company is going through changes
A second office, a hiring push, an acquisition, or a large project that doubles the file volume. Systems that hold together at twenty people come apart at forty, and the cheapest time to find that out is before the hiring rather than during it.
The person who knew everything is leaving
Retirement, resignation or a partner buyout. There is a short window while that person is still willing to answer questions, and an assessment run inside it converts what they know into something the business owns. Run afterwards, it becomes archaeology.
The fee
One thousand dollars, and how you get it back
$1,000
Fixed for a single site and a typical small or mid-sized business. Multiple locations or an unusually large environment are quoted before we start, never after.
Credited
Partner with us for managed services within twelve months and the full thousand comes off your account. So the assessment costs you nothing if we turn out to be the right answer, and a thousand dollars if we are not.
Yours
The report carries no restriction on what you do with it. Take it to your current provider and ask them to fix the list. That is a legitimate outcome and it has happened.
The obvious objection. We are a managed services firm assessing whether you need managed services. Two constraints keep us honest: the fee buys the time we spend getting you answers, with nothing else attached, and you can hand the findings to a competitor.
Common questions
How long does it take, and what do you need from us?
Two to three weeks end to end. From your side it is roughly four hours of somebody's time, split across a leadership conversation and a working session with whoever handles technology today, plus read-only access for the internal snapshot. We work around your calendar, and nothing needs to happen after hours.
Do we have to switch providers afterwards?
No. The engagement ends when the report is delivered and the readout is done. Some firms hand the list straight back to the provider they already have, and that is a fine result: the gaps get closed either way, and you paid a thousand dollars to find out what to ask for.
Should our current IT provider be involved?
Usually yes, and the good ones welcome it. They hold the documentation and the history, so an assessment goes faster and lands more accurately with them at the table. If you would rather they did not know, we can work from your own access instead, though expect the report to be thinner in a few places.
Will this satisfy an auditor or a carrier?
It is not a certification and we would not let anyone present it as one. It tells you truthfully where you stand before you sign an application or sit down with an auditor, which is the part firms most often get wrong. Where a formal attestation is required, the report tells you what would have to be true first.
Who is allowed to see the findings?
You decide. It goes to whoever you name and nowhere else, under a mutual confidentiality agreement signed before we begin. We keep our working notes for the term of that agreement so we can answer questions later, and destroy them on request.
We are small. Is this overkill?
Below about ten people the report gets short, and we will tell you on the first call if we think you would be paying for pages you do not need. Between roughly fifteen and two hundred people is where it earns its money, because that is the range where the technology has outgrown whoever set it up.
Book the assessment, or ask what it would find
Start with fifteen minutes about the business and what is coming this year. If an assessment is the wrong spend for where you are, we would rather say so on that call than take the fee.