A structured assessment of cybersecurity posture, operational resilience, and business continuity readiness.
The evaluation is scaled to the size, complexity, technology footprint, and operational dependencies of the business. The assessment areas stay consistent, while the depth of review is adjusted to the environment.
Small and medium-sized businesses that want an independent picture of their technology risk, recovery capability, and operational readiness before making security or technology investments.
Implementation and remediation are not included in the Initial Evaluation unless specifically defined in scope. Corrective work is handled separately.
Request EvaluationUser accounts, MFA, passwords, administrative separation, onboarding and offboarding, shared accounts, least privilege, account recovery, and ownership of critical business services.
Workstations, laptops, mobile devices, operating-system support, patching, endpoint protection, encryption, authentication, inventory, management, and lost-device exposure.
Backup strategy and retention, off-site protection, restore testing, cloud-data recoverability, critical-account recovery, recovery expectations, device dependencies, and single points of failure.
Firewall and router configuration, wireless security, guest separation, remote access, VPN, segmentation, internet exposure, equipment support, documentation, and physical access.
Microsoft 365 or Google Workspace, email, cloud storage, file sharing, administrative roles, external sharing, account recovery, business social media, website and domain administration, and other critical cloud services.
POS and payment platforms, accounting, payroll, banking, e-commerce, ordering, scheduling, ERP and industry applications, hosting, vendor support, licensing, backups, administrative access, dependencies, and recovery options.
Security policies, employee awareness, AI usage, technology documentation, disaster recovery readiness, business continuity, incident response readiness, vendor management, emergency contacts, critical dependencies, access continuity, and key-person risk.
Deliverables are appropriate to the scope and complexity of the environment.
As applicable, technical supporting material may include network discovery, device inventory, account and platform inventory, vulnerability findings, and supporting evidence.
For qualifying small-business engagements, concise recovery or emergency action instructions may also be included when specifically defined in scope.