Assess
A written picture of what you actually have, before anybody proposes anything.
We start with a fixed-scope assessment rather than a contract. Two to four weeks, depending on size, spent building an evidenced picture of the environment: what is enrolled, what is patched, what is licensed, what is exposed and what nobody has owned for a while.
The output is written, and it is yours whether or not you engage us further. We would rather lose a deal at this stage than win one on a misunderstanding of the environment.
What you receive
- Device, identity and infrastructure inventory
- Essential Eight maturity scoring against the ACSC model
- Risk register ranked by exploitability, not by control number
- A clear statement of what is working and should be left alone