IT ASSESSMENT · KNOW WHAT YOU HAVE

IT Assessment: A Full Picture of Your Setup

A complete inventory of your hardware, security, and backups — every aging machine and single point of failure found, ranked by risk, with a 90-day action plan.

Get a Free Assessment See pricing →

An IT assessment answers the question most small businesses can’t: what do we actually have, and what’s about to break? We inventory every device and account, check the age and health of your hardware, review your security and backups, and hunt for the single points of failure — the one server, one person, or one password everything secretly depends on.

It’s for businesses with 1–50 employees inheriting a setup nobody documented — new owners, new office managers, or anyone who just fired their IT guy. Fixed fee, done remotely, and the risk-ranked report is yours to act on with anyone.

What the assessment covers

📋

Complete Asset Inventory

Every computer, server, printer, account, and subscription documented — with age, warranty status, and who uses it. Most owners are surprised by what turns up.

⚠️

Single-Point-of-Failure Hunt

We find the one server, one internet line, or one person’s head your whole operation depends on — before it fails on a payroll Friday.

🔒

Security & Backup Review

MFA coverage, patch status, admin access, and whether your backups actually restore — checked and graded honestly, without scare tactics.

📅

90-Day Action Plan

Findings ranked by risk with a concrete 90-day plan: what to fix first, roughly what it costs, and what can safely wait a year.

What a baseline IT assessment actually inventories

An assessment is a structured census of everything your business runs on, scored against what could hurt you. For a 5–40 person firm it covers eight areas, and none of them are optional:

  • Hardware age and warranty. Every laptop, desktop, switch, firewall, and printer with purchase date, warranty status, and expected replacement year. A fleet where 40% of machines are past year five is a budget event waiting to happen all at once.
  • OS versions and end-of-life exposure. Machines still on Windows 10 after its October 2025 end of support receive no security patches; the same clock runs on old macOS versions, Server 2012 R2 boxes, and the firmware in that 2016 firewall. EOL software is the single most common critical finding.
  • License compliance. What’s installed versus what’s actually licensed — the “borrowed” Office key, the single-user QuickBooks on four machines. Audit letters from vendors are rare but expensive.
  • Network topology. What connects to what, which ISP circuit and modem, whether the Wi-Fi has a separate guest network, and whether the diagram exists anywhere outside one person’s memory.
  • Backup state. Not “do backups exist” but: what’s covered, where copies live (the 3-2-1 rule — three copies, two media, one offsite), and the date of the last successful restore test. Untested backups are hypotheses.
  • Security posture. MFA coverage, admin account count, endpoint protection versus a consumer antivirus from 2019, email authentication records (SPF, DKIM, DMARC), password practices.
  • SaaS sprawl. Every subscription the company pays for — usually discovered via the credit card statement, not any list — with owner, cost, and last-used data.
  • Single points of failure. Covered below, because it deserves its own hunt.

The single-point-of-failure hunt

Every small business has at least three of these, and almost none can name them before an assessment. The classics: the one aging PC that runs the accounting software or the license dongle, with no image and no spare; the router installed by an ISP tech in 2019 that nobody has credentials for, meaning any change requires a factory reset; the company domain registered under an ex-employee’s personal Gmail, which means that person — not you — controls your website and email at the registrar level; the sole “computer person” on staff whose head contains the entire configuration; the single ISP line with no failover for a business that stops dead without internet. The domain-ownership one deserves special emphasis: we check WHOIS and registrar access on every assessment, because recovering a domain from a departed employee’s abandoned inbox can take weeks of registrar dispute process — while your email depends on it.

How scoring works

Raw findings are a list; scoring turns them into decisions. Each domain gets a simple grade — green (fine), yellow (plan a fix), red (fix now) — so an owner can absorb the state of their IT in one glance and argue about priorities instead of jargon.

DomainWhat’s checkedRed-flag example
Identity & accessMFA coverage, admin count, offboarding historyActive accounts for two employees who left last year
EndpointsOS currency, patch state, disk encryption, protection agentUnencrypted laptops carrying client financial data
NetworkFirewall firmware, Wi-Fi segmentation, credential custodyGuest Wi-Fi on the same VLAN as the accounting PC
Backup & recoveryCoverage, offsite copy, last restore testUSB drive backup, plugged in permanently, never test-restored
Email & collaborationSPF/DKIM/DMARC, forwarding rules, sharing defaultsNo DMARC record; anyone can spoof the owner’s address
Vendors & ownershipDomain/tenant registration, SaaS list, contract termsDomain registered to a former manager’s personal email

Assessment versus security audit — and what you receive

The terms get used interchangeably; they aren’t. An IT assessment is broad and operational: everything above, security included but alongside hardware, licensing, backup, and cost. A security audit is narrow and deep: testing controls against a specific framework (CIS Controls, NIST CSF, HIPAA’s Security Rule), often with vulnerability scanning, and producing evidence for an auditor or insurer. If a client contract or cyber-insurance application demands proof of specific controls, you need the audit; if you want to know what you own, what’s fragile, and what it should cost to fix, you need the assessment. Most firms need the assessment first — auditing an environment nobody has inventoried wastes the auditor’s hours on discovery you could have done cheaper.

The deliverable from a proper assessment has four parts, and you should refuse anything less:

  1. Findings — the full inventory and every issue observed, in plain language with evidence.
  2. Risk ranking — each issue scored by likelihood and business impact, so a missing DMARC record and a dying accounting PC aren’t presented as equals.
  3. A prioritized 90-day fix list — the red items sequenced into something a business can actually execute: what gets done in week one (MFA, domain custody), month one (backup coverage and a restore test), and quarter one (EOL replacements, network cleanup).
  4. A budget estimate — real numbers for the fixes, separated into one-time and recurring, so the report converts directly into a plan rather than a shelf document.

Why assess before signing with any MSP

Including us. An assessment done before a support contract does two things a sales quote cannot. It establishes a baseline: documented proof of what state the environment was in on day one, which protects both sides when something surfaces in month three (“was this broken before you took over?” becomes checkable, not arguable). And it produces an honest scope: per-user pricing only means something when the user count, device count, and problem inventory are real. MSPs that quote without assessing are guessing — and guesses get corrected later, in their favor. In firms that have never had structured IT management, the same findings appear so reliably we could pre-print them: no MFA on email, backups that exist but have never been restored, three to five active accounts belonging to former employees, a firewall on factory firmware, at least one EOL operating system in daily use, and roughly 15–20% of software spend going to subscriptions nobody uses. None of this reflects badly on the business — it’s the natural state of IT that grew by accretion. The assessment’s job is to make it visible, rank it, and price the way out.

Frequently asked questions

How long does an IT assessment take for a small business?

For 5–40 employees, typically one to two weeks: a discovery session with the owner, remote inventory of devices and cloud tenants, credential and ownership checks, then report preparation. Staff disruption is minimal — most data collection runs remotely, plus a few ten-minute conversations about who uses what.

Is an assessment the same as a vulnerability scan?

No. A vulnerability scan is one instrument — automated probing for known software flaws — and it says nothing about warranty cliffs, license exposure, untested backups, or who owns your domain. An assessment may include a scan, but its scope is the whole operational picture, ranked by business impact rather than CVE count.

What should we gather before an assessment starts?

Four things speed it up enormously: admin access to your email/cloud tenant, the last three months of credit card statements (the real SaaS inventory), any credentials for the router/firewall if they exist, and the name of whoever registered your domain. Missing items are themselves findings — not knowing who holds the firewall password is exactly the kind of risk the report exists to surface.

We’re small and nothing seems broken — why bother?

Because the expensive failures are the invisible ones: the backup that silently stopped in March, the domain controlled by someone who left, the one PC whose death takes payroll with it. An assessment converts unknown risks into a ranked list with prices attached. Firms that skip it don’t avoid the findings — they meet them one outage at a time.

Talk to a real technician today

Free IT assessment for US small businesses. Flat monthly rate, no contracts, same-day remote response.

Get a Free Assessment +1 (202) 960-2022