What is included

The evaluation is scaled to the size, complexity, technology footprint, and operational dependencies of the business. The assessment areas stay consistent, while the depth of review is adjusted to the environment.

  • Customer interview and business dependency discovery
  • Technology, critical account, and platform inventory
  • Applicable technical, network, endpoint, backup, and cloud review
  • Business platform and transaction-system review
  • Documentation, policy, and operational resilience review
  • Risk identification and prioritized remediation planning
  • Executive review of findings and next steps

Best fit for

Small and medium-sized businesses that want an independent picture of their technology risk, recovery capability, and operational readiness before making security or technology investments.

Implementation and remediation are not included in the Initial Evaluation unless specifically defined in scope. Corrective work is handled separately.

Request Evaluation

Seven evaluation areas

1. Identity & Access Management

User accounts, MFA, passwords, administrative separation, onboarding and offboarding, shared accounts, least privilege, account recovery, and ownership of critical business services.

2. Endpoint & Device Security

Workstations, laptops, mobile devices, operating-system support, patching, endpoint protection, encryption, authentication, inventory, management, and lost-device exposure.

3. Backup & Recovery

Backup strategy and retention, off-site protection, restore testing, cloud-data recoverability, critical-account recovery, recovery expectations, device dependencies, and single points of failure.

4. Network & Infrastructure

Firewall and router configuration, wireless security, guest separation, remote access, VPN, segmentation, internet exposure, equipment support, documentation, and physical access.

5. Business Platforms & Cloud Services

Microsoft 365 or Google Workspace, email, cloud storage, file sharing, administrative roles, external sharing, account recovery, business social media, website and domain administration, and other critical cloud services.

6. Line of Business & Transaction Systems

POS and payment platforms, accounting, payroll, banking, e-commerce, ordering, scheduling, ERP and industry applications, hosting, vendor support, licensing, backups, administrative access, dependencies, and recovery options.

7. Policies & Operational Readiness

Security policies, employee awareness, AI usage, technology documentation, disaster recovery readiness, business continuity, incident response readiness, vendor management, emergency contacts, critical dependencies, access continuity, and key-person risk.

Core deliverables

Deliverables are appropriate to the scope and complexity of the environment.

Business Continuity & Cybersecurity Assessment
Executive Summary
Risk Assessment by Evaluation Area
Cybersecurity Evaluation Report
Detailed Remediation Plan
30-Day Improvement Plan
90-Day Improvement Plan
12-Month Strategic Roadmap

Supporting material

As applicable, technical supporting material may include network discovery, device inventory, account and platform inventory, vulnerability findings, and supporting evidence.

For qualifying small-business engagements, concise recovery or emergency action instructions may also be included when specifically defined in scope.