IT Security · Assessment & Basics
The basics, checked honestly, by someone with nothing to sell you.
Passwords, backups, updates and access. You get a clear picture of where you stand and a plain list of what to fix first.
Nobody is targeting you. That is not the reassurance it sounds like.
What reaches a company your size is almost never a person who chose you.
It is automated, indiscriminate, and it lands on whoever left something
open.
Which means the question is not whether you are interesting. It is whether the basics are in place, and for most companies nobody has checked in years.
Which means the question is not whether you are interesting. It is whether the basics are in place, and for most companies nobody has checked in years.
The uncomfortable one is backups. Almost everybody has them. Far fewer
have ever restored from one, and a backup nobody has tested is a belief,
not a backup.
None of this is exotic work. It is the maintenance that never makes it onto anyone’s week.
None of this is exotic work. It is the maintenance that never makes it onto anyone’s week.
What we look at
Four areas. They cover most of what actually goes wrong.
How passwords are handled
Where they are kept, how many people share one, and whether multi-factor
authentication is on for the accounts that matter. Email first, because
email is how the rest gets reset.
Whether backups would work
Not whether they run. Whether a restore has been tried, how long it would
take, and whether a copy exists somewhere that ransomware could not reach
along with everything else.
What is out of date
Systems, servers and the one machine in the corner running something nobody
dares touch. Usually there is exactly one, and usually it is important.
Who can see what
Including the people who left. Old accounts and shared logins are the
quietest problem on this list and the easiest one to fix once somebody
writes it down.
How it works
Three steps. You can stop after any of them, and plenty of people stop after the first.
Assessment
One to two weeks, fixed price. Conversations and read-only checks, nothing
run against production that could knock a system over. You get a written
picture of where you stand and the ordered list of what to fix. That is
a complete deliverable and you keep it either way.
The top of the list
We fix the items that are cheap and buy the most, which is normally a
handful of days. Your own IT people can do this part instead if you have
them, and we would rather hand them a clear list than bill you for it.
Keeping it that way
A restore test and a review on a schedule, because all of this drifts
back within a year if nobody looks. Small, boring, and the only part that
makes the first two steps worth anything.
Who this is for
This is for you if
- You run a company of roughly 10–200 people and nobody’s job title contains “security”.
- You have backups and you are not certain anyone has restored from them.
- A customer or insurer has started asking you questions you cannot answer.
- You want a straight answer rather than a product recommendation.
Probably not, if
- You need a formal certification audit. That is a different trade and we would point you at it.
- You are mid-incident right now. Call an incident response firm, not us.
Questions we get asked
- Is this a penetration test?
- No, and for most companies of this size a penetration test is the wrong thing to buy first. It tells you how someone could break in through a door you have not locked yet. We look at whether the locks exist at all, which is cheaper to answer and almost always where the real gap is.
- Do we need this if we are too small to be a target?
- Nobody is picking your company specifically. That is the point: most of what hits a small business is automated and indiscriminate, and it lands on whoever left the door open. Size protects you from being chosen and not at all from being caught.
- What do we actually get?
- A written picture of where you stand and a list of what to fix, in order, with an honest estimate of effort against what each one buys you. Written in language you can hand to a non-technical manager. You keep it whether or not we do any of the fixing.
- Will you tell us to buy a lot of software?
- We sell no security products and take no commissions, so there is nothing on our side pushing that way. In practice the top of the list is usually free: turn on multi-factor authentication, remove the accounts of people who left, actually test a restore.
- Can you fix the things you find?
- The technical ones, yes, and the list will say plainly which items those are. Some of what turns up is not a technical problem at all but a habit or a contract with a supplier, and we will tell you when that is the case rather than billing you to work around it.
- How long does it take and how disruptive is it?
- One to two weeks, mostly conversations and read-only checks. We are not running anything against production that could knock a system over. The heaviest demand on you is a few hours of the person who knows how the systems were set up.
When did someone last restore from your backup?
Call the office nearest you. If you know the answer, you probably don’t need us. No sales sequence.