What an IT assessment should actually give you
Plenty of companies offer a free assessment. Most of them are a sales call with a checklist attached, and the checklist exists to justify the recommendation the salesperson was going to make anyway. Here is how to tell the difference before you spend a fee or a Saturday on one.
A findings register, not a slide deck
A real assessment ends with a document you can read on your own, months later, without the person who wrote it in the room. If the deliverable is a slide presentation designed to be walked through by the vendor, the value lives in the pitch, not the paper.
Severities tied to a business consequence, not just a technical score
"CVSS 8.1" tells you nothing about your business. A finding worth paying attention to should say what happens if it goes wrong, in terms you already understand, such as: an attacker with this access can read every client file in this share.
Fixed remediation prices, not a follow-up call to discuss pricing
If every finding ends with "let's set up a call to talk about fixing this," the assessment was a lead-generation exercise. A genuine one prices the fix at the same time it identifies the problem, because the assessor already knows what the fix involves.
You should own the document, whoever fixes it
Ask directly: is this deliverable mine to keep, and can I take it to another provider? A vendor confident in their pricing has no reason to make the findings hostage to hiring them for the remediation.
Questions worth asking before you pay for one
Will I receive a written report I can read without you? Do you disclose any reseller margin on products you might recommend? What is explicitly out of scope? How long did the review actually take, and who did it? Straight answers to these four questions filter out most of the sales-call assessments.
What good looks like when it is done
A findings register with a severity, a plain-language consequence and a fixed price on every item; a short executive summary that could be read by whoever approves the budget; and no pressure to sign anything before you have had time to read it.
More from Nixitek
Microsoft 365 multi-factor authentication: what to turn on first
A practical order of operations for enabling multi-factor authentication across Microsoft…
Why your AWS bill keeps growing, and five places to look first
The most common causes of cloud cost creep on AWS and Azure, in the order we usually find…
SPF, DKIM and DMARC, explained without the jargon
What the three email authentication records do, why partial setup is the most common…