Annual Security Posture Review

Once a year, a deliberate look across the systems we manage for you: who has access and whether they still need it, what is behind on patches, whether the backups actually restore, and whether anyone would know what to do at two in the morning. It is the review that never happens on its own, because nothing is broken and nobody in particular owns it.

What you get

  • An access review across the managed estate — every account, key and role, with the ones nobody can account for flagged for removal
  • Patch currency per host, and what the gaps would let through
  • A restore actually attempted from backup, rather than a backup job confirmed as green
  • An incident readiness check: contacts, runbooks, and who can reach what outside office hours
  • A written report with findings in the order we would fix them, and a comparison against last year

What this does not cover

  • Anything we do not manage and cannot reach: staff laptops, your office network, SaaS accounts, and third-party systems we have no access to
  • Breaking in. This reads configuration, records and practice; it does not attack anything, which is External Penetration Test
  • An audit, a certification or an attestation — nothing produced here stands in place of a formal assessment by a qualified assessor
  • Your payment environment: card details are captured in your payment provider's environment and never reach systems we run, so that environment sits outside both this review and our scope
  • The twelve months in between. A yearly review is a point in time; continuous checking is Monthly Vulnerability Scan

Who it fits

An estate we already manage, where somebody has started asking when it was last checked and by whom. If what you need is evidence that a competent person actually tried to get in, that is External Penetration Test rather than this.