Home » IT & Security Assessment

Assessment

IT and security assessment for New York businesses

A scoped review of how your environment actually stands — identity, endpoints, network, backups, and compliance posture. Nothing runs without written authorization, and the findings are yours whatever you decide.

What the assessment covers

The assessment answers one question: if something went wrong tomorrow — an account takeover, a ransomware event, a regulator’s questionnaire — where would your environment hold, and where would it give? We look at five areas:

  • Identity. MFA coverage and method strength, administrative accounts, stale and orphaned access, sign-in policies in Microsoft 365 and Entra ID.
  • Endpoints. Patch state, disk encryption, endpoint detection coverage, local administrator sprawl.
  • Network. Firewall rules and their history, remote access paths, segmentation, wireless configuration.
  • Backup and recovery. What is protected, whether copies are immutable and offsite, and — the question that decides everything — whether a restore has been observed to succeed.
  • Compliance posture. Your controls mapped against what governs you: NYDFS Part 500, HIPAA, the FTC Safeguards Rule, CMMC / NIST 800-171, or SOC 2 expectations.

Ground rules

Nothing runs on your systems without written authorization. Before we begin, you receive a scope document naming every tool we intend to use, the accounts and access involved, and the window in which the work happens. Where a question can be answered by reading configuration rather than running something, we read.

The findings are yours. You receive a prioritized, plain-language findings document ranked by risk and effort — written so that whoever does the remediation can execute it, including a team that is not us.

One honest boundary: this is engineering work, not an audit or a legal opinion. We help you prepare and operate controls; where you need an auditor or counsel, we will say so.

How it runs

Three steps, each ending in a document you hold.

  1. Scope call

    Thirty minutes with an engineer to agree what is in scope, what access is required, and what the written authorization covers. You receive the scope document before anything else happens.

  2. Review

    We examine identity, endpoints, network, backup, and compliance posture within the authorized scope — configuration review and evidence collection first, active tooling only where agreed.

  3. Findings walkthrough

    A working session through the findings: what we found, why it matters, and a remediation sequence ordered by risk and effort. The document stays with you either way.

Common questions

Will you run tools in our environment without asking?

No. The written authorization names each tool, each account, and each window before anything executes. If a question can be answered by reading configuration instead of running something, we read.

Are we obligated to engage you afterward?

No. The findings document is complete on its own and usable by any competent team. If remediation with us makes sense, that conversation starts with managed IT or managed cybersecurity — but the assessment is not a teaser with the useful parts withheld.