Most organisations have never had anybody independent look at the whole estate at once.
Systems accumulate: one bought by finance, one inherited from a departed manager, one
written years ago by somebody's nephew. An assessment puts all of it on a single page
and tells you, in order, what deserves your attention.
What we examine
- Applications in genuine daily use, and the ones being paid for but quietly abandoned.
- Hosting, servers, domains and where each one is actually registered.
- Licence counts against real headcount, and renewal dates that arrive without warning.
- Integrations and the manual re-keying that exists because an integration does not.
- Backups, and whether anyone has tried restoring from one.
- Support arrangements — who is contracted to fix what, and by when.
- Key-person risk: the systems only one person understands.
What it excludes
An assessment is a review, not a repair. We do not remediate what we find, we do not
configure or install anything, and we do not perform penetration testing — where a
genuine security test is warranted, we say so and help you scope it for a specialist
testing firm. We also stop short of auditing your finances; if a licence looks
over-purchased we will say so, but the numbers remain yours to verify.
What you receive
- A current-state map of systems, hosting and the data moving between them.
- A findings register, each item scored for cost, risk and urgency.
- A recommendation list separated into fix now, plan for, and leave alone.
- A walkthrough session where you are invited to argue with all of it.
What we need from you
An hour each with three or four people who use the systems daily, read-only access where
an interface tells us more than a description would, a list of what you currently pay
for, and one person empowered to answer questions between sessions.