IT Assessment & Audit

IT Assessment & Audit

Know exactly where you stand, in writing. A vendor-neutral audit of your IT and security, with risk-ranked findings and a prioritised roadmap of what to fix first.

Overview

You can't fix what you can't see. An IT assessment gives you an independent, vendor-neutral picture of exactly where your technology and security stand — what's solid, what's exposed, and what to fix first — in plain writing you can take to your board, your investors or the SFC.

It's deeper than our free assessment. We examine eight control domains against recognised standards, run tool-based scans and interviews, and hand you a risk-ranked report with an executive summary and a prioritised roadmap. You keep the report and the roadmap whether or not you engage us to act on them.

What's included

Where you stand, in writing.

What the audit covers

Accounts, access & MFA

We review every user and admin account, your joiners-movers-leavers process, privileged access and MFA enforcement. Least-privilege is checked across Microsoft 365, file shares and applications — dormant and over-privileged accounts are a common, avoidable risk.

Endpoints & patching

EDR deployment and configuration, device-compliance policies, and patch and vulnerability status across every machine. We find the unmanaged laptop and the unpatched server before an attacker does.

Assets & software control

A full inventory of devices, servers and licences, plus shadow-IT discovery and application control. You can't secure or budget for what you don't know you have.

Backup & ransomware resilience

Backup coverage across servers, endpoints, cloud and email; restore testing; and ransomware-specific protections such as immutability and air-gapping. We test whether you could actually recover, not just whether backups exist.

Mobile & cloud posture

MDM and BYOD controls via Intune, and cloud-security posture including Microsoft 365 Secure Score. Phones and cloud apps are where a lot of data now lives — and where a lot of gaps hide.

Your deliverable

A risk-ranked written report with an executive summary, a prioritised remediation roadmap (quick wins plus strategic investments), and a debrief with your leadership. Optional add-ons include email security, logging/SIEM, incident-response review and PDPO / ISO 27001 / GDPR gap analysis.

Who it's for

Firms that suspect gaps but can't see them clearly

Firms preparing for an SFC review, ISO 27001 or investor ODD

New management or owners inheriting an unknown IT estate

Firms considering an acquisition and needing IT due diligence

Common questions

What the audit covers

How is this different from the free assessment?
The free assessment is a focused, SFC-oriented health check with a RAG report. The full audit goes much deeper — eight control domains, tool-based scans, interviews and a detailed remediation roadmap — and is a paid, fixed-scope engagement.
Do we have to use you to fix what you find?
No. The report and roadmap are yours to keep and act on however you like — with your own team, another provider, or us. Independent findings are more useful precisely because they're not a sales pitch.
Why it matters

What you receive

A risk-ranked written report with an executive summary, a roadmap of quick wins plus strategic investments, and a debrief with your leadership. Our free assessment is the SFC-focused starting point; the full audit goes deeper.

← All services

Start with a free assessment

A remote scan and a short on-site visit across the 10 SFC areas — a written findings report you keep, no obligation.

Book a free assessment
Explore more

Related services

One partner for your whole workplace.

IT, security and the rooms you run the business in — under one SLA and one invoice.

Book your free assessment