IT infrastructure health assessment
A structured review of the ICT estate — hardware, software, configuration, access and security risk — ending in a remedial plan your team can work through and your auditors can follow.
What the assessment covers
We analyse your ICT infrastructure to uncover the weaknesses that lead to service disruption, unauthorised access and data loss. The assessment is a health check, not a scan: the finding matters less than what it lets an attacker or a failure do next.
Depending on what we find, we set out a remedial course of action — closing unauthorised access paths, hardening the security systems, locking down sensitive data, and getting more out of the infrastructure you already own.
Five areas, assessed in every engagement
- Hardware
- Servers, workstations, printers and devices outside directory control such as switches and routers. Retired computers still joined to the domain and never removed.
- Software
- Systems missing patches, service packs or security updates. Per-system local accounts with weak passwords. Systems with no anti-virus or anti-spyware, and firewall misconfiguration.
- Configuration
- Security policy that is inconsistent across servers and computers. Outbound access that should be blocked. Absent content filtering.
- Accessibility
- Misconfigured user access to network shares, and a detailed breakdown of directory security group membership.
- Security risks
- Old accounts that still hold access and were never disabled. Internal systems with open ports. External exposures that put the network at risk of business disruption or data loss.
What you receive
A report of what was found, what it exposes, and the order in which to fix it. Findings are written so that an engineer can reproduce them and a risk committee can act on them without translation.
Work that usually runs alongside this
Penetration and vulnerability testing
Every live network carries weaknesses. Testing finds them, proves what they expose, and produces an improvement path that can be measured rather than asserted.
Read moreStandards certification and empowerment
Cross-border business runs on standing in a recognised standard. We take an organisation to certification and keep it in good standing afterwards.
Read moreInsider threat detection
The people already inside hold legitimate access, and the traditional tools log almost none of what they do with it. Behavioural analytics close that gap.
Read moreFind out what is sitting undetected
We will scope a health assessment against your estate and agree the reporting format before any work begins.