Skip to content

Independent security review

Is your IT provider or team delivering the security you pay for?

Know what is protecting your business, and what is giving you a false sense of security.

The Security Reality Check is an independent, fixed-fee review of the controls and contracts behind your IT and security services. We report what is missing, what is covered, and who needs to act.

See the full scope and deliverables

When an independent review helps

When the business changes, check what still protects it.

AI is helping attackers work faster and giving staff new ways to access data and automate work. Before connecting another tool or renewing another provider, know who can act, who must approve, and what evidence shows the controls work.

Read the NCSC assessment of AI-enabled threats and its guidance on delegated access and actions.

  • Before you renew a provider

    Compare the service you were sold with the evidence that it is being delivered.

  • Before the next wire or trust-account instruction

    Check what the records show about mailbox compromise and unwatched forwarding rules.

  • Before connecting AI to company data

    Identify what it can access, what it can change, and which actions require approval.

  • Before an insurance or client review

    Know which security statements you can support with records and which still need checking.

A useful first step

Not sure what to ask your provider? Start with the checklist.

The free Security Reality Snapshot is a 15-question checklist covering responsibilities, access, and recovery. Use it to identify what you know, what you need to ask, and where to start.

No email is required. Read it online or print it to work through with your provider.

What you receive

Evidence, ownership, and next steps.

You receive one written report, walked through with leadership. These are its three main parts (the full report has five sections):

See the gaps clearly

Executive findings summary

It shows what the evidence supports, what it does not, and which decisions are yours.

Know who owns the next step

Security confidence scorecard

Each domain is rated, with its control owner (or a flag where no one owns it) and an immediate action.

Leave with a workable plan

30/60/90-day roadmap

It lists actions in order, each with an owner and a way to confirm it is done.

From the sample report

One line of the scorecard, and the finding behind it.

Where the evidence supports a rating, the status is the finding. Illustrative example, not a client finding.

See this finding in the sample report
Domain
Backup & Recovery
Status
Critical Gap
Control owner
Shared (firm and provider)

The backups ran. Could anyone get the data back?

Backups ran every night. But the same login that runs the systems could also delete the backups. No record was supplied showing that anyone had tested getting the data back.

Responsible
The IT provider
Approves closure
The managing partner
Closed by
A configuration review and a recovery record with the owner's approval

Status key Defensible At Risk Critical Gap

Find out what is actually protecting your business

Tell us about the concern or decision that prompted your interest. We reply within two business days to arrange a free 30-minute scoping call, or to scope by email if you prefer. You get a written fixed-fee quote before any work starts.

Ask for our credentials in your first email. We send a mutual NDA and share them before you agree to any scope or fee.

Contact us