Skip to content
All-intek
Getting started

What a free IT assessment actually covers

What gets looked at during an IT assessment, what you receive at the end, and why the document is worth having even if you never hire the company that wrote it.

4 min readAll-intek

"Free IT assessment" is one of those phrases that has been used badly often enough that it now sounds like a sales call in a costume. It is worth saying plainly what one is, what it is not, and what you should expect to be holding when it finishes.

An assessment is a structured look at the technology you already own and pay for. It is not a pitch, and it does not require you to change anything. At the end of it you should have a written document describing what you have, what condition it is in, and which parts of it represent risk — ordered so that the expensive problems are at the top.

What gets looked at

The network

What connects to what, and how. Where the internet enters the building, what handles routing and firewalling, how the wireless is laid out, whether the cabling was terminated to a standard or grown organically over a decade. Multi-site businesses get the same review per location, because "the same setup everywhere" is almost never true once someone actually checks.

Endpoints

Every laptop, desktop, server, phone and tablet that touches company data. What operating system each one runs, whether it still receives security updates, whether it has protection on it, and whether anyone can say with confidence who is using it. Devices that nobody can account for are a finding in themselves.

Backup and recovery

Not "is there a backup" — nearly everyone answers yes to that. The questions that matter are when it last completed successfully, whether anyone has ever restored from it, how long a full restore would take, and how much work would be lost in the gap. A backup that has never been tested is a belief, not a control.

Identity and access

Who can log into what, whether multi-factor authentication is enforced or merely available, how many accounts belong to people who left, and whether administrator rights are handed out by default. Access sprawl is quiet, cumulative and one of the most common ways a small incident becomes a large one.

Licensing and spend

What you are paying for monthly, what is actually being used, and what is being paid for twice. This part frequently pays for the rest of the engagement on its own, and it is the section clients read first.

Documentation

Whether anything is written down. If the person who set up your systems left tomorrow, could someone else pick it up from documentation, or would they be reverse-engineering the environment from scratch? That answer changes what every other risk on the list actually costs you.

What you get at the end

A written summary, ranked by risk, with each item stating what was found, what it means in practice, and roughly what it takes to close. Plain language — if a finding cannot be explained to the person who signs the cheque, it has not been written properly.

You keep that document. It is yours whether you continue the conversation or not. That is not generosity; it is the only version of an assessment that is worth anything to you. A report you cannot take away is a sales presentation.

What it is not

It is not a penetration test. It is not a compliance audit, and it cannot certify you against HIPAA, PCI-DSS, SOC 2 or anything else — certification comes from an independent auditor, and any provider offering to certify its own work should worry you.

It is also not a commitment. Some assessments end with a list you hand to your existing IT person, and that is a perfectly good outcome.

How to judge the one you are offered

Ask three questions before you agree to any assessment:

  1. Do I keep the report? If the answer is anything other than a flat yes, it is a sales meeting.
  2. Will the findings be ranked, with what each one costs to fix? An unranked list of forty items is a way of looking thorough without being useful.
  3. Who is doing the work? An engineer who will look at the environment, or an account manager running a checklist?

The point of an assessment is to replace opinions with a document. If you finish one and still cannot answer "what is our biggest technology risk right now," it did not do its job.

Where it usually leads

Most findings land in two places: the day-to-day running of the environment, which is what managed IT services cover, and the network and security controls, which sit under network infrastructure and cybersecurity. If the next step is comparing providers, read how managed IT pricing models behave before the quotes arrive. And if you want one done on your own environment, ask for the assessment.

Let's find out what is actually wrong.

The assessment is free, takes a short site visit or remote session, and you keep the written findings whether you hire us or not.