Assessments

Independent reviews of your environment, with prioritized recommendations and no obligation to buy anything else from us. We look at your security posture, network health, software licensing, backup status, and risk exposure, then deliver a written report in plain English that your leadership team can actually act on.

Common reasons clients commission an assessment: due diligence before an acquisition, switching MSPs, preparing for an audit or insurance renewal, or just getting an outside opinion on whether their current provider is doing a good job. Most assessments take 1-2 weeks and pay for themselves in the cost optimizations alone.

When an independent set of eyes is worth more than another vendor

There are moments in a business's life when you need an unbiased look at your IT before making a major decision, and your current IT provider is the worst person to ask. Are they doing a good job? Are you paying market rate? Is the architecture they built actually appropriate for where you're heading? An IT assessment from an independent provider gives you that view, with no obligation to switch vendors and no upsell at the end.

The most common reasons businesses ask us for an IT assessment:

  • Pre-acquisition IT due diligence: When you're buying a business, the IT environment is often the most opaque part of the deal. An independent assessment in the 30 days before closing tells you what you're inheriting, license obligations, end-of-life equipment, unpatched security gaps, capacity constraints, contract terms that auto-renew the day after close. This is the lowest-cost piece of due diligence by far, and one of the highest-stakes.
  • Considering switching MSPs: If you've been with the same provider for years, you genuinely don't know if the service you're getting is good. An assessment benchmarks your environment against current best practice and tells you, in plain English, what's well-managed and what's been left to drift.
  • Cyber-insurance renewal: Insurance carriers ask increasingly detailed questions. An assessment gives you the documentation you need to answer honestly, plus a remediation plan for any "no" boxes that should be "yes" boxes.
  • Annual board reporting: Leadership teams who want a real risk picture, not their existing IT vendor's marketing report.

What our IT assessment actually covers: a security posture review (vulnerability scan, patch status, identity controls), a network and infrastructure audit (firewall config, segmentation, backup health, equipment lifecycle), software licensing review (you're almost certainly paying for licenses you no longer use, or under-licensing in places that would fail an audit), risk register (the top issues, prioritized by likelihood and impact), and a written executive summary that your leadership team can actually read.

Engagement length is typically 1–2 weeks of active work, then a delivered report with a follow-up session to walk through findings. Most clients tell us the cost is recovered just from the licensing optimization recommendations, never mind the risks that get caught.

What's included

The essentials, without the upsell

Security posture review

Network & infrastructure audit

Licensing optimization

Written report you can share

FAQ

Common questions

How is an IT assessment different from a security audit?

A security audit is narrower, it's focused on whether specific controls are in place and effective, often against a defined framework (NIST, CIS, SOC 2). An IT assessment is broader, it covers security, but also infrastructure, licensing, vendor relationships, technical debt, and overall risk. Audits answer "are we secure?" Assessments answer "is our IT in good shape?"

Will my current IT provider find out I commissioned an assessment?

Not unless you tell them. We conduct the assessment without direct contact with your existing provider, we work with the access and documentation you give us, plus a network-based scan. Many clients prefer to share the findings with their current provider afterward as a constructive conversation; others use the assessment to decide it's time to make a change.

What about IT due diligence for an acquisition?

Pre-acquisition IT due diligence is one of our most common engagements. We typically scope it tighter (1 week, intense) and focus on integration risks: license transfers, contract auto-renewals, end-of-life systems, data retention obligations, security gaps that would block a Day 1 integration. The deliverable goes into your overall deal package alongside the financial and legal due diligence.

Do you make recommendations or just identify problems?

Recommendations always. Each finding has a recommended remediation, a rough cost or effort estimate, and a priority. The leadership team should be able to read the executive summary and walk away with a clear action plan, not a list of complaints they don't know how to act on.

Are you going to try to sell me more services at the end?

No. The whole point of an independent assessment is that you can take the report and act on it, with us, with your current provider, or with anyone else. Most clients do choose to engage us on remediation, but it's their call, and we deliberately do not condition the assessment fee on what follows.

Want to talk about IT Assessments?

A no-pressure conversation with a senior engineer, not a sales script.