Skip to main content
Guardian IT

Free IT & Security Assessment

Find the IT and Security Gaps Before They Become Problems.

A focused review of your technology and security, with a written summary of what we found and what we'd fix first.

No cost, no obligation, and no requirement to change providers. Most businesses we talk to have three or four gaps they didn't know about — usually in backups, offboarding or MFA coverage.

  • No cost and no obligation
  • 20–30 minute conversation to start
  • Written findings you keep either way

Prefer to talk first? That's often faster.

(385) 270-4733

Request your assessment

Tell us a little about your business

Ten fields, about two minutes. Enough for us to come to the first conversation already useful.

About you
About your business
Preferred contact method (required)

We'll reply within one business day to schedule the first conversation.

We use your details to respond to this request and nothing else. No newsletter, no reselling your information. Privacy Policy.

What we review

Ten areas, and the questions we answer in each

These are the questions most businesses can't answer with certainty. By the end of the assessment, you can.

Identity & Access

  • Is multi-factor authentication enforced for every user?
  • Who holds administrator rights, and is that still appropriate?
  • Are there accounts belonging to people who have left?
  • Are shared or generic logins still in use?

Devices

  • Is every company device centrally managed?
  • Is disk encryption on and verifiable?
  • Is endpoint protection installed, current and monitored?
  • How old is the hardware, and what's due for replacement?

Microsoft 365 / Google Workspace

  • Which security settings are available but not switched on?
  • Is audit logging enabled and retained?
  • Are file sharing and external access configured deliberately?
  • Are you paying for licenses or tiers you aren't using?

Email Security

  • Is advanced phishing and attachment filtering in place?
  • Are SPF, DKIM and DMARC configured so your domain is harder to spoof?
  • Would you be alerted to a suspicious mailbox forwarding rule?
  • Do staff have a clear way to report a suspicious message?

Backup & Recovery

  • What is actually being backed up — and what isn't?
  • Is cloud data backed up independently of the platform?
  • When was the last successful test restore?
  • How long would recovery realistically take?

Network Security

  • Is the firewall configured and its firmware current?
  • Is there a separate guest network?
  • How do remote staff connect, and is anything exposed to the internet?
  • Is the wireless network segmented from company systems?

Onboarding & Offboarding

  • Is there a documented process, or does it depend on memory?
  • How quickly is access removed when someone leaves?
  • Is company data removed from personal phones?
  • Is there a record of what was granted and revoked?

Password Practices

  • Is a business password manager in use?
  • Are credentials kept in spreadsheets, notes or browsers?
  • Are passwords reused across business services?
  • How are vendor and service-account credentials handled?

Security Awareness

  • Has the team had any practical security training?
  • Is there a verification step for payment or banking changes?
  • Would an employee know who to tell, and how quickly?
  • Are written policies in place for devices, passwords and acceptable use?

IT Documentation

  • Is the environment documented, or held in one person's head?
  • Do you have your own administrator credentials?
  • Is there a current inventory of devices, licenses and subscriptions?
  • Could a new provider pick this up without starting over?

How it works

Five steps, about a week start to finish

Most of the work is ours. Your time commitment is the first conversation and a short follow-up to go through the findings.
  1. 01

    Discovery conversation

    20–30 minutes

    We talk about how your business runs, what's been frustrating, and what you're planning. No technical knowledge needed — this part is about the business, not the servers.

  2. 02

    High-level environment review

    We do the work

    With your permission we review your Microsoft 365 or Google Workspace configuration, device and security posture, backup status and network setup. Read-only, scheduled around you, and nothing is changed.

  3. 03

    Identification of major risks and gaps

    Prioritized, not exhaustive

    We separate what genuinely matters from what's merely imperfect, and rank what's left by actual risk to your business rather than by how easy it would be to sell you.

  4. 04

    Short executive findings summary

    Written, plain English

    A document you can read in ten minutes and hand to a partner or your board. No 60-page tool export, no jargon, no inflated severity ratings.

  5. 05

    Recommended next steps

    Your decision

    A clear sequence: what to fix now, what to plan for, and what can wait. If the right answer is your existing provider or an internal hire, we'll say so.

Clear scope

Exactly what you're getting — and what you're not

Free offers earn trust by being specific about their limits. Here are ours.

What this is

  • A review of how your technology and security are configured and operated
  • A conversation with someone who does this work, not a sales script
  • A prioritized, written list of gaps with practical recommendations
  • Yours to keep and act on however you choose, including with another provider

What this is not

  • A penetration test. That's a specialist engagement and we don't offer it.
  • A formal regulatory or compliance audit, and not an attestation of any standard.
  • An exhaustive vulnerability assessment or a full technical scan of every system.
  • A sales call with an assessment attached. If nothing needs fixing, we'll tell you.

Before you ask

Questions about the assessment

Didn't find your question?

Ask it directly — you'll get a straight answer from someone who does the work.

Contact us
Why is it free?

Because we'd rather quote an environment we've actually looked at, and because an assessment is the most honest sales conversation available to us. If we find little to fix, that tells you something useful about your current setup.

There's no obligation attached. Plenty of these end with a short list of fixes and nothing else, and that's a fine outcome.

What access do you need?

Read-only visibility into your Microsoft 365 or Google Workspace admin center, plus a conversation with whoever knows the most about your current setup. For device and network review we may ask to look at a representative machine and your firewall configuration.

Nothing is changed during the assessment, and we'll agree the scope of access in writing before anything starts.

How long does it take?

The initial conversation is 20–30 minutes. The review itself typically takes a few days depending on how quickly access is arranged, and the findings review is another short call.

Your total time commitment is usually under an hour and a half.

Will you talk to our current IT provider?

Only if you want us to. Most businesses prefer to keep an assessment private until they've read the findings, and that's entirely reasonable.

If your provider is doing good work, the findings will show it and we'll say so plainly.

What if we're not ready to change anything?

That's a normal outcome and it's fine. Knowing where your gaps are has value even if you fix them next quarter, next year, or yourself.

The findings document is yours. We won't chase you about it.

Two minutes now, a clear picture next week.

Scroll back up to the form, or call and we'll start the first conversation straight away.