ONE-TIME REVIEW · CLEAR FIX LIST

Cybersecurity Health Check for Your Business

A one-time, structured review of your security — what an attacker sees, where your accounts are weak, whether backups would save you — ending in a ranked 90-day fix list.

Get a Free Assessment See pricing →

A cybersecurity health check is a fixed-scope review of where your business actually stands: what’s exposed to the internet, which accounts lack MFA, whether your backups would survive a ransomware hit. Every finding is severity-ranked, so you know what’s urgent and what can wait.

It’s for businesses with 1–50 employees that suspect there are gaps but don’t know which ones matter. No contract, no upsell pressure — you get a 90-day fix list you can hand to any IT provider, including one that isn’t us. Fix it yourself or have us do it.

What the health check covers

🌐

External Attack Surface Scan

We look at your business the way an attacker does: exposed logins, forgotten subdomains, open ports, and services that shouldn’t be reachable from the internet.

🔑

MFA & Account Audit

Every account checked for multi-factor authentication, stale users, shared passwords, and admin rights nobody remembers granting. The quiet gaps breaches walk through.

💾

Backup Integrity Check

We verify backups exist, actually ran recently, and can be restored — because a backup you’ve never tested is a hope, not a plan.

📋

Prioritized Findings Report

Everything ranked by severity with a 90-day fix list in plain English. You’ll know exactly what to do first and what it should cost.

What a health check actually examines

A cybersecurity health check is a structured inventory of the ways your business could be broken into, not a sales exercise for a bigger contract. For a typical 5–40 person firm we look at eight areas:

  • External attack surface — everything reachable from the internet under your domain and public IPs: web servers, VPN endpoints, forgotten subdomains, exposed management interfaces. If it answers a connection from outside, it gets examined.
  • Open ports and remote access — especially RDP (port 3389), SMB (445), and vendor remote-support tools. RDP exposed directly to the internet remains one of the top two ransomware entry points, alongside phishing.
  • Microsoft 365 or Google Workspace tenant configuration — legacy authentication status, admin role sprawl, external sharing defaults, mail forwarding rules, OAuth app grants, audit logging enabled.
  • MFA coverage — not “do you have MFA” but exactly which accounts lack it, with admin and finance accounts checked first. The gap is usually service accounts and one executive who opted out.
  • Patch levels — operating system versions and pending updates on every workstation and server, plus third-party software (browsers, PDF readers, remote tools) and firmware on firewalls and NAS devices.
  • Backup integrity — what is backed up, where copies live, whether anything is offline or immutable, and when a restore was last actually tested.
  • Password hygiene — shared logins, credentials in spreadsheets, domain accounts in known breach dumps, whether a password manager is in real use.
  • Firewall and network rules — any-any rules, port forwards nobody remembers creating, default admin passwords on network gear, guest Wi-Fi sharing a network with the office file server.

Vulnerability scan versus penetration test

These get conflated constantly, and the price difference is an order of magnitude. A vulnerability scan is automated: tools probe your systems, match what they find against a database of known weaknesses (CVEs), and produce a prioritized list. It costs hundreds of dollars, can be repeated monthly, and finds the unlocked doors. A penetration test is a human ethically attacking you — chaining findings, writing exploits, phishing staff — and typically runs $5,000–$25,000+ for even a small scope.

Most small firms should not buy a pen test first. Paying a professional $10,000 to confirm that RDP is open and MFA is missing is a waste of both the money and the tester. The sequence that makes sense: health check and vulnerability scan, fix the findings, and consider a pen test later if a customer contract, insurer, or compliance framework (SOC 2, CMMC) actually demands one.

What the findings report looks like

Every finding gets a severity rating in the style of CVSS (the Common Vulnerability Scoring System, 0–10): critical, high, medium, or low, based on how exploitable it is and what an attacker gets. The report leads with a one-page summary an owner can read, followed by per-finding detail: what we found, evidence, business impact in plain English, and the specific fix. Representative examples by severity:

SeverityExample findingWhy it rates that highFix window
CriticalRDP open to the internet on the accounting PC, no MFADirectly exploitable today by automated brute-force; leads straight to ransomware24–48 hours
HighGlobal admin account without MFA; Windows Server 2012 R2 still in productionOne phished password compromises the whole tenant; EOL software receives no security patches1–2 weeks
MediumBackups running but never test-restored; SMBv1 enabled on the file serverFailure is discovered only during a disaster; deprecated protocol widens ransomware spread30 days
LowDirectory listing on the marketing site; verbose server version bannersInformation leakage that aids an attacker but is not directly exploitableNext maintenance cycle

The findings we see over and over

After enough health checks the same five problems appear at most small businesses, regardless of industry:

  • RDP or a remote tool exposed to the internet, usually set up during 2020 remote-work scrambling and never revisited.
  • MFA everywhere except where it matters — enforced for staff, skipped for the admin account, the shared “info@” mailbox, or the owner.
  • End-of-life Windows machines — Windows 10 stopped receiving free security updates in October 2025, and we still find it (and older) running payroll.
  • Backups that have never been test-restored, or that sync to a folder the same ransomware would encrypt.
  • Shared admin passwords — one password for the firewall, the server, and the Wi-Fi, known to current and former staff alike, sometimes taped inside a drawer.

Remediation: fixing in the right order

A 30-finding report is useless if it produces paralysis, so the deliverable includes a sequenced plan, not just a list. Prioritization weighs three things: exploitability from the internet, what the attacker gains, and cost to fix. That ordering routinely puts cheap fixes first — closing an RDP port and enforcing admin MFA are an afternoon’s work and eliminate more real-world risk than a $15,000 firewall replacement. Criticals get fixed inside 48 hours (often during the engagement itself), highs inside two weeks, and the mediums become a checklist for the following month. Each item gets an owner and a date, because “we should fix that sometime” is how the same finding shows up in next year’s report.

How often to re-check

Annually as a floor, and additionally after any major change: an office move, a new line-of-business application, a merger, a switch of email platforms, or staff turnover in whoever held the admin passwords. Firms under a compliance framework or holding cyber insurance should align the re-check with renewal, since applications ask point-in-time questions the assessment answers with evidence. Between full checks, an ongoing vulnerability scan keeps the external picture current at low cost.

Frequently asked questions

Will the assessment disrupt our work or take systems offline?

No. Scanning is read-only probing scheduled around your hours, and configuration review happens through admin consoles, not on users’ machines. The only thing staff might notice is a short interview about how they actually share files and passwords — which is often where the best findings come from.

How long does it take and what do we need to provide?

For a typical small firm: about a week from kickoff to report, with a findings walkthrough call at the end. We need temporary read access to your Microsoft 365 or Google Workspace admin center, your public domain names and IPs, and a list of devices — plus fifteen minutes with whoever knows where the backups go.

We passed our cyber insurance application. Doesn’t that mean we’re fine?

An insurance application is self-attested checkboxes; nobody verified the answers. That cuts both ways — gaps go unnoticed until a claim, and a claim can be denied if an answer (say, “MFA on all accounts”) turns out to have been wrong. A health check verifies what was attested, which protects the coverage as much as the network.

Can you fix what you find, or just report it?

Both. Critical items we typically remediate during the engagement with your approval — closing exposed ports, enforcing MFA, killing stale admin accounts. The rest can be handled as a one-off remediation project or folded into an ongoing management plan; the report is written so any competent provider could execute it, including one that isn’t us.

Talk to a real technician today

Free IT assessment for US small businesses. Flat monthly rate, no contracts, same-day remote response.

Get a Free Assessment +1 (202) 960-2022