Skip to main content

Find out what is actually wrong before something breaks

A read-only review of the things that most commonly turn out to be broken — backups, patching, who can log in, and what is exposed. You get a ranked findings list you can act on, with or without us.

We do this because it is also how we find out whether we can help you. If your current setup is in good shape, that is a short conversation and we will say so.

What we find, almost every time

  • A backup job that has been failing silently for weeks or months, on a system everyone assumes is protected.
  • MFA reported as enabled, with legacy authentication still permitted — so it can be bypassed entirely.
  • Licences still assigned to people who left, sometimes a year ago, still billing.
  • SPF or DMARC misconfigured, so anyone can send invoices as your domain.

None of these reflect badly on anyone. They happen because nobody was looking, which is the entire point of looking.

What the check covers

  • Backup integrity

    Whether jobs are completing, whether the data is restorable, and whether anything important is outside the job. The most common finding, by a distance.

  • Patch state

    Which servers and workstations are behind, by how long, and whether anything is wedged and silently failing to update.

  • Identity and access

    MFA coverage including exemptions, whether legacy authentication is still permitted, who holds administrative rights, and accounts belonging to people who left.

  • Email authentication

    Whether SPF, DKIM and DMARC are correct, or whether anyone on the internet can currently send mail as your domain.

  • Endpoint protection

    What is deployed, whether it is reporting, and whether any machines have quietly dropped off.

  • Network and exposure

    What is reachable from the internet, firewall firmware currency, and whether the network is segmented or flat.

  • Licensing

    What you are paying for against what is being used, including seats still assigned to departed staff.

  • Documentation

    Whether your environment is documented anywhere, or whether it exists only in one person's memory.

What it is not

  • A penetration test — that is a separate, specialist engagement
  • Application-level testing of your line-of-business software
  • Any change to your environment; the assessment is read-only
  • A commitment to switch providers

What you get at the end

A findings list ranked by actual risk rather than by severity label, separated into things that are free to fix, things that need a few hours, and things that are genuine projects. Plus a walkthrough so you understand what each item means rather than receiving a PDF and a quote.

It is written so your existing provider could act on it. That is deliberate — a report only actionable by the company that wrote it is a sales document wearing an assessment's clothes, and you would be right to distrust it.

If we find something genuinely urgent during the review — an exposed service, a live compromise indicator, a backup that has not worked in six months — we tell you that day rather than saving it for the report.

Questions

What does the IT health check cost?
For most businesses in our service area the initial assessment is provided at no cost, because it is also how we work out whether we can help you. Larger or more complex environments — multiple sites, unusual infrastructure — are scoped and quoted first. Either way you are told before anything starts.
Are we obligated to switch providers?
No. You get the findings whether or not you engage us, and they are written so your current provider could act on them. A report that is only useful if you buy something is a sales document, not an assessment.
How long does it take?
Typically a few days of elapsed time and very little of yours. Most of the work is automated discovery and configuration review, plus a short conversation about how the business actually runs. You get the report and a walkthrough of what it found.
Will it disrupt anything?
No. It is read-only — we look at configuration, patch state, backup status and access, and we do not change anything or test anything by attacking it. If we find something genuinely urgent, we tell you immediately rather than waiting for the report.
Is this a penetration test?
No, and the distinction matters. A health check reviews configuration, patching, backup integrity, identity and access — the things most commonly wrong. A penetration test is a specialist attempting to gain access. Most businesses that have never had an assessment should do this first, because paying a tester to discover you have not patched is an expensive way to learn it.

Book the health check

A few days, almost none of your time, and a findings list you can act on regardless of what you decide about us.

Call Get a quote