Hardware and warranties
Computers, servers, printers and network devices with model, age, OS version and warranty end date. You see at a glance what stops getting updates next year.
We examine the technology and the habits around it: who grants permissions, where passwords live, what happens when someone leaves, and whether anyone checks the backups at all.
Computers, servers, printers and network devices with model, age, OS version and warranty end date. You see at a glance what stops getting updates next year.
We set what you pay for in Microsoft 365, antivirus or accounting software against what staff really use. Idle licences and duplicate services often turn up.
We look at what the internet can see of you: open ports, an exposed remote desktop, a NAS login page or a router on ancient firmware.
Does a copy exist, what does it cover, is one held off site, and can it be read. We restore a single file to prove it.
How many admins, MFA coverage, leftover accounts of former staff and where passwords are written down, sticky notes under keyboards included.
Findings that matter for GDPR, NIS2 and the Polish KSC act are flagged, plus KRI for public bodies. It is not a certification, but it is a solid starting point for a formal audit.
How long the review takes depends on company size, and we agree it at the outset. Staff feel it about as much as an ordinary update.
An hour on Teams or Google Meet with whoever knows your IT best. We agree access and dates.
A light agent and a read-only Microsoft 365 account collect data automatically over several days.
A staff member sends a handful of pictures of the rack, router and device labels. That is enough for us to see cabling and backup power.
An online session going through the report, risk list and plan, with estimated hours against each item.
The costliest finding is rarely a technical one. More often the company domain, the Azure subscription or the registrar login turns out to be tied to the private email of a former employee or contractor. Winning that access back after the fact can take weeks, so ownership of key accounts is the first thing we check.
Very little. One contact person, an admin account to grant us read-only rights, and an hour for the kick-off call. Any existing documentation helps, even an old spreadsheet of equipment, but none is required.
We receive named read-only accounts with MFA, valid only for the review. Once the report is delivered they are removed and you get confirmation. If you wish, we sign a data processing agreement before seeing anything at all.
We do not sit on it until the report. If we spot, say, remote desktop open to the world or a backup that has been failing for months, we tell you straight away and suggest a quick fix. Whether to go ahead is your call.
No. The plan is written so your own IT person or another provider can carry it out. Each item carries an effort estimate, but the choice stays with you.
Tell us a little about the business. We will arrange the kick-off call and agree a date for the report.
Your enquiry has reached us
You will hear back within one working day, and if you have reported an outage that is holding up work, it goes to the front of the queue.
No match for that name. Try a different spelling or pick a bigger town nearby - all our support is delivered online, so your choice has no effect on the service.