foundry

What a cyber security assessment actually looks at

A good security assessment isn't a mystery survey. Here's what we examine, what we measure it against, and what you get at the end.

Foundry Team

"Security assessment" can mean anything from a glossy PDF to a genuine deep-dive. Here's what a proper one covers — the same structure we use when we assess a new client's environment from scratch.

1. Identity and access

The first question is always: who can log in to what? We review accounts, admin rights, MFA coverage, leavers whose access is still live, and guest access nobody remembers granting. Stale access is the quietest way breaches happen.

2. Devices and patching

Every laptop and server is checked against current patch level, disk encryption, endpoint protection status and supported operating systems. One unpatched machine is all an attacker needs.

A quick example of the kind of check we run on every Windows device:

# OS builds older than 6 months are a finding
Get-CimInstance Win32_OperatingSystem |
  Select-Object Caption, BuildNumber,
    @{ Name = "LastBoot"; Expression = { $_.LastBootUpTime } }

3. Email and web exposure

We test what an attacker's automated tooling already knows: exposed email addresses, lookalike domains, mail-flow rules that auto-forward outside the business, and phishing-filter coverage.

4. Backups and recovery

Not "do you have backups" but: are jobs monitored, are copies isolated or immutable, and when was a restore last performed end-to-end? Recovery speed is measured, not assumed.

5. People and process

The final layer is human: who has been trained, what happens when someone spots something suspicious, and is there a written incident plan? If the plan is "call Dave", there's no plan.

What you get at the end

A findings list is useless without priorities. Our assessments end with a colour-rated report — quick wins this month, investments this quarter, strategy this year — and plain-language explanations your leadership can act on, not a fear document.

Curious where your environment stands? A free intro call is the fastest way to find out.

Want help with this in your business?

Book a free intro call — we’ll talk through your situation, no obligation.

Why small businesses keep getting breached — and the 5 controls that stop most attacks

Most small-business breaches follow the same five attack paths. These five controls close them — and they're neither exotic nor expensive.
Foundry Team

Five signs your business has outgrown break-fix IT

If IT only gets attention when something breaks, you pay for it in downtime. Here are five signs break-fix is costing you more than managed IT would.
Foundry Team

Let’s talk about your IT.

Book a free, no-obligation introductory call and find out whether we’re the right fit for your business, or request a personalised quote straight away.