Holistic IT and security assessment (Holistic Approach)
We see the whole picture. We fix what matters. An assessment that looks at technology, security, cost and compliance together.
Most businesses look at their IT piece by piece: one supplier for the network, another for email, another for security, and nobody for the whole. The Holistic Approach (HA) does the opposite: it examines the whole picture together, because the real risk hides in the gaps between the pieces.
We start with a meeting with the owner or the IT manager. We map how the business works, from infrastructure and applications to networks and telecommunications, and propose improvements: more modern technology, lower cost, fewer and better connected tools. The proposals are centred on Microsoft 365 and cybersecurity, and are given both as immediate actions and as a 12-month programme.
- Meeting with management and the IT manager
- Mapping of infrastructure, applications, systems, networks and telecommunications
- Maturity scoring and an HA score from 0 to 100
- Cost analysis and technology consolidation proposals
- Mapping to NIS2 (Article 21), ISO 27001 and the CIS Controls
- 30-day quick wins and a 12-month programme
- Presentation of the results to management
What we examine: 10 pillars
Each pillar contains specific controls that are scored on a maturity scale from 0 to 4.
IT strategy and governance
Who decides, on what criteria, and how well IT is controlled.
Identity and access
Accounts, multi-factor authentication, administrator rights.
Devices and endpoints
Management, protection and compliance of computers and mobile devices.
Productivity and collaboration (Microsoft 365)
How well the licences and tools you already pay for are used.
Data and information protection
Where the data is, who has access and how it is protected.
Applications and business systems
The applications your work depends on and how they connect to each other.
Infrastructure and cloud
Servers, storage and cloud services, and what they cost.
Networks and connectivity
Network, firewall, remote access.
Telecommunications
Telephony and connections, in relation to cost and need.
Security operations and resilience
Backup, monitoring, incident response, business continuity.
Four lenses, one picture
Security
How exposed are we? Maturity scoring, critical gaps and 30-day quick wins.
Cost
Are we paying the right amount for technology? Cost baseline, overlaps, consolidation and right-sized licences.
Compliance
Are we in line with NIS2 and GDPR? Mapping to Article 21 of NIS2, ISO 27001 and the CIS Controls.
Productivity
Are people working efficiently? Making the most of Microsoft 365 and simplifying tools.
How we work
For the full assessment the target is 10 working days from the meeting with management to the presentation of the results.
Meeting and assessment
A conversation with the owner and the IT manager, to understand how the business works.
Data collection
Microsoft 365 configuration data in read-only mode, an inventory and three months of bills.
Analysis
Scoring of the controls, cost and consolidation analysis, mapping to NIS2.
Design
Quick wins of 0 to 30 days, phase 1 (1 to 3 months) and a 3 to 12-month programme, with a business case.
Management presentation
The picture, the risks, the financials and the decision on the next step.
Implementation
Quick wins and the programme, with owners and a timeline.
Quarterly review
A review every quarter and a new HA score, so progress is visible.
What we deliver
HA Snapshot
One page: the HA score, the top five risks and three quick wins.
HA Report
Summary, a view of the 10 pillars, findings, roadmap, cost and NIS2 mapping.
Management presentation
Ten slides: the picture, risks, financials, decision.
Technical findings
A detailed file with the evidence and the score of every control.
Ways of working together
You can start with a first look and go as far as you want. For pricing, talk to us.
Discover
A short meeting and a first picture with the HA Snapshot.
Assess
The full assessment and the presentation to management.
Program
Implementation of the quick wins and the 12-month programme.
Continuum
Quarterly review and tracking of progress.
Frequently asked questions
What is the holistic IT and security assessment (Holistic Approach)?
It is an assessment of a business's IT and security that examines infrastructure, applications, networks, telecommunications, security, cost and compliance together, and ends with a concrete improvement plan.
Who is it for?
Small and medium businesses, typically from 10 to 300 employees, that want an overall picture of their IT and a prioritised plan, without needing their own IT department.
Do you need access to my systems?
For Microsoft 365 we collect configuration data in read-only mode, with permissions that you approve. We do not change anything in your systems during the assessment.
How long does it take?
For the full assessment the target is 10 working days from the meeting with management to the presentation of the results. The duration depends on size and on how quickly the data is provided.
What happens after the assessment?
You get a prioritised plan: 30-day quick wins and a 12-month programme. You decide which of the proposals go ahead and how.
Is it a NIS2 compliance audit?
The assessment maps the findings to the Article 21 measures of NIS2, but it is not legal advice or an official compliance audit. It can be the basis for a compliance programme.