Fixed scope · Two days · No scoping call
Most health checks run a scan and hand back a spreadsheet of red, amber and green. This one takes three controls that fail quietly in almost every organization, establishes whether each is actually working, and gives you the record of what was examined. Narrow and deep, rather than broad and glanced at.
The three controls
If you already know the answer to all three, you do not need this. That is deliberate. Most organizations know the answer to one of them.
Not whether it is switched on. Which accounts are excluded, whether legacy authentication still has a path, and who holds a break-glass account that nobody reviews. Exclusions are where this control fails, and they are invisible from a policy screenshot.
Your privileged access records reconciled against your leaver list, as a complete population rather than a sample. Every organization believes this is clean. In the ones that check, it usually is not, and the accounts that remain are the ones with the most access.
A restore attempted and timed, not a backup job report read. A backup that has never been restored from is an assumption with a schedule attached.
How it runs
We send the commands, your administrator runs them, and you see the output before it leaves your network. No agent, no credential handed over, no access granted to us. What each command reads is written down before you agree to it.
The reconciliation and the analysis, against a complete population where the scale allows. Where it does not, the sample and the basis for it are recorded rather than assumed.
Thirty minutes on what was found and what it means. No slide deck, because there is nothing here a slide deck improves.
What you end up with
Before you book
Then buy nothing. If you reconcile privileged access against leavers on a cycle and restore from backup regularly, this will tell you what you already know.
Three controls will not answer what they are asking. Start with the assessment instead, or with the obligation itself if it is the Data Protection Act.
Establishing which system actually enforces authentication is investigative work rather than extraction, and it cannot be done honestly in two days. We will say so and quote separately.
Nothing automatic. You get the working papers and the findings, and what you do next is yours to decide, including doing it yourself or giving it to your existing provider. If you do decide to go further, the fee comes off the assessment.