Home/Pricing/Security assessment

Assessment

Security and systems assessment

A fixed-price look at your identity, devices, Microsoft 365, backups and exposure, written up as a report you keep. It stands alone. You are not obliged to buy anything afterwards.

Who it is for

Anyone who wants to know what state things are actually in before committing to a monthly agreement, with us or with anybody else.

It is also the honest way to buy managed technology. You should know what state you are in before anyone quotes you a monthly figure to maintain it.

Price$1,500 to $3,000 depending on size
PaymentHalf to schedule, half on delivery of the report
DurationOne to two weeks
ObligationNone. The report is yours either way.
What we look at

Six areas.

  • Identity

    Who can sign in, from where, with what. Whether multi-factor covers administrators as well as staff.

  • Devices

    What is enrolled, encrypted, patched and monitored, and what has quietly fallen off the list.

  • Microsoft 365

    Licences against actual usage, mail protection, sharing, and whether the configuration is backed up anywhere.

  • Backup and restore

    What is backed up, how far back, and whether a restore has ever been completed.

  • Exposure

    What of yours is reachable from the internet, and what known-exploited vulnerabilities are sitting unpatched.

  • People and process

    Joiner and leaver handling, shared accounts, where knowledge lives, and what happens when the key person is away.

Evidence

Why an assessment is worth its price.

Finding things late is the expensive option, and small businesses are measurably going backwards on this.

21%

of small businesses have a formal incident response plan.

UK Government Cyber Security Breaches Survey, 2026

$1.14m

is the penalty for finding a breach late: $5.01m average when the lifecycle runs past two hundred days against $3.87m under it.

IBM Cost of a Data Breach, 2025

41%

of small businesses ran a cyber risk assessment in the last year, down from 48%, while 46% suffered a breach or attack.

UK Government Cyber Security Breaches Survey, 2026

What you get

A report, not a sales document.

  • A written summary a non-technical owner can read
  • Findings in priority order, with the reason for the order
  • What it would cost to fix each one, including doing it yourself
  • The evidence, so another provider could verify our work
  • A ninety-minute session to walk through it with your team
Next step

Start with the assessment.

Thirty minutes to scope it and confirm the price. Then one to two weeks of our work and a report you keep.

What happens on the call

  1. You talk, we listen

    Ten minutes on what is actually going wrong and what you have already tried.

  2. We name the first move

    One recommendation, in order of priority, with the reason behind it.

  3. You get a number

    A real price range before you leave the call. No proposal cycle, no chasing.

No sales script. No obligation. If we are not the right fit we will say so and point you somewhere better.

Visual directionThe Ledger