See where you actually stand. A baseline security audit reviews what you already run and ranks what to fix first.
- Endpoints, email, cloud, identity and policy reviewed
- Findings ranked by what an attacker reaches first
- A remediation plan you could hand to anyone
We look at everything you have already paid for
What you already have
The tools in place, how they are configured, and which of them are doing nothing because nobody finished the setup.
The gaps between them
Most damage comes through the seams - an unmanaged laptop, a shared mailbox, a service account nobody owns.
What it would take to close them
Costed and ordered, so the first thing you do is the thing that removes the most risk.
What two weeks of looking actually covers
- Endpoints
- Every laptop, server and workstation we can see: what is protecting them, what it is set to do, and which of them nobody is managing at all.
- Email and collaboration
- The route most incidents still take. Filtering, authentication records, external sharing, and who can quietly read a mailbox that is not theirs.
- Identity and access
- Who can sign in, from where, with what second factor - and the accounts that outlived the person, the project or the supplier they belonged to.
- Cloud
- Permissions first, because that is where cloud incidents start: broad roles, storage open wider than intended, keys in the wrong places.
- Network and remote access
- What you expose on purpose and by accident, how the office and the VPN are segmented, and how far one compromised device would get.
- Backup and recovery
- Not whether backups run, but whether they would survive the incident and whether anyone has restored from them recently enough to be sure.
- Policy and process
- The written rules and the real ones: joiners and leavers, patching, who is called at two in the morning and what they are allowed to decide.
How it works
Look
Two weeks of review across endpoints, email, cloud, identity and the policies that govern them.
Rank
Every finding is placed by what an attacker reaches first, not by how alarming the label sounds.
Hand over
A plan written to be executed by whoever you choose, including someone who is not us.
What you get
A plan anyone could execute - including someone who is not us
Every finding with what it costs to close and what it buys you, ordered so the first thing you do removes the most risk. Hand it to your own team, your existing supplier, or us. Nothing in it can only be acted on by us. You asked where you stand, not who to hire.
Start with the audit
There is nothing to sign, and the report is yours either way.