A real look at where your business actually stands, security-wise.
A comprehensive assessment that covers vulnerabilities, configurations, policies, cloud posture, backups, and physical security — with a written report and prioritized remediation roadmap. From $2,500 one-time.
Most breaches don't come from unpatched CVEs — they come from what nobody's checking.
Business owners spend on firewalls, endpoint security, and backup, and reasonably assume they're covered. Then they get breached anyway — because the firewall had a rule that made sense in 2018 and hasn't been reviewed since, or because MFA was rolled out to most staff but the owner and admins were exempted "temporarily," or because the backup runs nightly but nobody's actually tested a restore in three years.
A comprehensive security assessment finds those gaps. It's the difference between "we run antivirus so we're fine" and "here's a written report showing exactly where we stand, prioritized." It's also, increasingly, what cyber-insurance carriers actually want when they ask about your security posture.
We do this work for Cape Breton businesses — insurance offices, construction companies, restaurants, retailers, non-profits, colleges. Every industry has different risks; the assessment adapts to yours.
Nine assessment areas. Every business, tailored to fit.
Not every area applies to every business. The Essential tier covers the technical essentials; higher tiers add breadth (cloud, IAM, policy) and depth (on-site, compliance mapping, phishing baseline).
External vulnerability scan
Firewall + perimeter review
Endpoint security config
Backup + disaster recovery
Cloud posture (M365/Google)
Identity + access management
IT policy + procedure review
Physical security walkthrough
Compliance mapping
Four phases. 2 to 6 weeks depending on scope.
- 1
Kickoff
Week 130-minute call with your point of contact. We agree on scope, tier, timeline, and access requirements. You send us basic inventory (endpoint count, cloud platforms, key systems).
- 2
Discovery
Weeks 1-2External scans run. Config exports collected (read-only access, no changes made). Cloud posture reviewed. On-site walk scheduled if included in your tier.
- 3
Analysis
Weeks 2-4Findings correlated, severity ratings applied, remediation options researched, roadmap drafted. This is where the professional judgment happens — separating real risk from noise.
- 4
Report + Debrief
Week 3-6Written PDF delivered. Debriefing call to walk through findings, answer questions, discuss remediation options. Executive briefing (Comprehensive tier) for leadership follow-up.
Three tiers. Scale with your business.
One-time engagements — this is a project, not a subscription. Not sure which tier fits your business? Give us a call and we'll help you scope it in 15 minutes.
Small businesses, under 25 endpoints
- External vulnerability scan (public IPs + websites)
- Firewall and perimeter security review
- Endpoint security config review (Bitdefender or equivalent)
- Backup coverage verification
- Written report with prioritized findings
- Debriefing call (video or phone)
Growing businesses, 25-75 endpoints
- Everything in Essential, plus:
- On-site walkthrough of your business
- Network segmentation and wireless security review
- Cloud posture review (Microsoft 365 or Google Workspace)
- Identity, access, and MFA rollout review
- Departing-employee procedure audit
Regulated industries, 75+ endpoints, or higher-risk profile
- Everything in Standard, plus:
- IT policy and procedure review
- Physical security walkthrough (server room, workstation exposure)
- Compliance mapping (PIPEDA, HIPAA-adjacent, PCI-light)
- Baseline phishing simulation campaign included
- 90-day post-assessment follow-up call
- Executive briefing presentation for leadership
Every tier includes the written report and debrief call. Regulated industries or businesses with unusual scope may need custom quotes — ask us and we'll price it directly.
A deliverable your leadership and insurance carrier can rely on.
The final report is designed to serve two audiences: leadership (who need to understand risk and approve remediation budget) and technical staff (who need actionable specifics on what to fix and how).
- Executive summary (2 pages, non-technical) — risk snapshot leadership can read in 5 minutes
- Detailed findings section — each risk with severity, description, and remediation
- 30 / 60 / 90-day prioritized roadmap — what to fix first, second, later
- Compliance mapping (Comprehensive tier) — where you stand against relevant frameworks
- Written recommendations any competent IT professional can act on
- Available as PDF for your files; delivered by email or printed on request
Multi-factor authentication is enforced for standard user accounts on Microsoft 365, but is not enforced for the 3 administrator accounts. If any of these accounts is compromised, the attacker gains full tenant-level control with no additional barriers.
Recommendation:
Enforce Conditional Access policy requiring MFA on all Global Admin and equivalent roles. Estimated effort: 1-2 hours. Recommended tool: existing M365 Business Premium Conditional Access.
Roadmap timing:
Within 30 days.
One finding per page. Sortable, printable, actionable.
Security assessment FAQ
How is this different from a penetration test?+
A penetration test is one type of security check — a human actively tries to break in. It's expensive ($4,000-$25,000) and typically only makes sense once your obvious weaknesses are already closed off. A comprehensive security assessment is broader and comes first: we look at everything (vulnerabilities, configurations, policies, cloud posture, physical security, staff behaviour) and give you a prioritized roadmap. Think of it as the physical exam that comes before any specialist referral. Most Cape Breton businesses should do the assessment before spending on a pen test.
Why not just run a vulnerability scan?+
Vulnerability scans (which we also offer, from $29/mo) catch known technical vulnerabilities in your public-facing systems. They're valuable but they only see one slice — technical, external, automated. A comprehensive assessment looks at the whole picture: how your firewall is configured, whether your backups actually restore, whether your staff have MFA, whether your policies match your practice, whether someone could walk into your server room. Most breaches don't come from unpatched CVEs — they come from misconfigurations, weak policies, and human factors that a scan won't catch.
Is this driven by our cyber insurance renewal?+
Often yes. Cyber-insurance carriers increasingly require documented security assessments as a condition of coverage or reasonable premium rates. If your renewal questionnaire is getting more detailed each year, a formal assessment is what most carriers actually want to see when they ask about "security posture." We can structure the deliverable to answer your carrier's specific questions if you send us the questionnaire in advance.
Do we need to shut down or take systems offline during the assessment?+
No. Everything we do is designed to be non-disruptive. External vulnerability scanning happens against your public-facing systems the same way an attacker would probe them — no impact to your operations. On-site work is walk-through observation and configuration review, not active testing that could crash a system. The whole assessment runs while your business runs.
What does the final report look like?+
A written PDF with an executive summary (readable by non-technical leadership), a detailed findings section (each risk rated Critical / High / Medium / Low with specific remediation recommendations), a prioritized 30/60/90-day roadmap, and — for the Comprehensive tier — compliance mapping showing where you stand against relevant frameworks. Everything is written to be actionable, not academic. Sample structure is available on request; email us if you want to see the format before booking.
Who at our company needs to be involved?+
Minimal disruption. We need: (1) one point of contact to answer questions and grant read-only access to systems, (2) an IT lead or vendor to attend the debrief if you have one, and (3) leadership availability for the executive briefing (Comprehensive tier only). We do the heavy lifting; you don't need to prep anything special.
What happens after the assessment — do we get support fixing the findings?+
That's your call. If you're an existing managed IT client of ours, remediation of the findings is folded into your regular support work. If you're not, you can hire us hourly for remediation, hand the report to your in-house IT team, or (for compliance-driven work) use it as a briefing document for a security consultant. The report is structured so any competent IT professional can act on it — you're not locked into using us for the fixes.
How much of this could our in-house IT team just do themselves?+
Some of it, in theory. In practice, in-house teams almost never do a full assessment on themselves — different priorities, blind spots to their own work, no time to write the report. An outside assessment brings fresh eyes, dedicated hours, and a written deliverable your leadership and insurance carrier can rely on. If your in-house team is thorough, they'll agree with 80% of our findings and have their own notes on the other 20% — that's a healthy assessment.
Book a scoping call.
15 minutes on the phone to understand your business, agree on the right tier, and set a timeline. From that call to a signed report is typically 2 to 6 weeks.