Service · IT infrastructure

Infrastructure health check

Suppose a civil engineering practice in Innsbruck with eighteen employees is losing the IT contractor it has relied on for years, because he is retiring. What gets handed over is a USB stick containing a password list, plus the assurance that everything more or less runs fine. Nobody can confirm it. How old is the server in the storeroom, really? Who manages the domain? Can the backups be restored? Why is the plotter PC running an unsupported system? Moments like this are what the health check was designed for. It is just as useful when an insurer sends a cyber questionnaire, when a major client asks for proof of information security, or when the directors are about to sign off a large purchase and want to know where the money matters most. We connect with read-only permissions, leave your configuration exactly as it is and have no need to visit. You end up with a report the managing director can get through in thirty minutes, and a technical annex for whoever does the follow-up work.

Seven questions
rather than a 300-item checklist
Read-only access
your settings stay untouched
Test restore
not just a glance at backup logs
Ranked
by risk and by hours

Everything this covers

Instead of ploughing through an endless checklist, we answer seven questions every director ought to be asking. Each answer receives a colour rating and a short justification.

Settle the details with an engineer

What is actually there?

A complete inventory, including devices nobody remembers: the old NAS in the meeting room, the time-clock terminal, the multifunction printer emailing scans with a mailbox password stored inside it.

What can outsiders see?

Open ports, the firmware level of the VPN gateway, certificates about to lapse, and the SPF, DKIM and DMARC records for your domain. In short, everything an attacker can learn without knowing a single password.

Who is allowed to do what?

Former employees whose accounts are still live, admin rights attached to everyday logins, gaps in multi-factor coverage and shared credentials across Active Directory, Entra ID and your line-of-business applications.

How current is everything?

Patch status of servers, clients, firewall and switches, together with a list of end-of-support dates so that replacements can be budgeted calmly instead of bought in a panic.

Could you recover from an outage?

We restore a file as a test and, if you agree, an entire virtual machine, and we time it. We also establish whether a copy exists that ransomware would be unable to reach.

Who owns what?

Domain, Microsoft tenant, internet connection, hosting and licences for BMD or your construction costing software: whose name is on them, when they run out and who could cancel or renew them in an emergency.

What do the law and your partners expect?

Relevant GDPR and Austrian data protection points, a preliminary view on whether you might qualify as an essential or important entity under NIS2, and the questions insurers and large customers tend to raise. We get you ready; we do not issue certificates.

Our working method

For 20 to 40 workstations, allow two to three weeks from kick-off call to finished report. Your own staff spend only a few hours on it in total.

01

Kick-off call

Forty-five minutes on video covering the trigger, your sites, the key applications and any known worries. Afterwards both sides know where to focus.

02

Automated collection

Temporary read-only accounts and an inventory agent gather data for several working days, supplemented by an external scan of your public IP addresses.

03

Spot checks

A test restore, a look through the admin centres and brief chats with a couple of everyday users, since workarounds and shadow IT never show up in tooling.

04

Two-part report

Four pages for management, plus a technical annex listing every finding and an action plan costed in hours. We go through both with you on Teams or Google Meet.

Orphaned accounts are among the least visible yet most widespread weak spots in small networks. The former bookkeeper can still open her mailbox, the summer intern from three years back still has VPN, and an outside supplier logs in through a shared admin account with no second factor. For an intruder, access like that is far more convenient than any software flaw. If we come across it, you hear from us straight away rather than weeks later in the report.

Frequently asked questions

A scanner will spot open ports and missing patches. It will not notice that the domain is registered to the founder personally, or that backups have been writing to an empty folder ever since the server was moved. Tools do the legwork; people do the judging.

Before connecting for the first time we sign a data processing agreement. We use named accounts and recorded sessions, and we delete the raw data within the agreed period once the job is done. The report and annex remain with you.

Yes. The agent only needs one reachable computer per site, and someone on the spot can photograph the network cabinet with a phone. Each location gets its own chapter, as branches often look quite different from head office.

That depends on your sector, headcount and turnover and, in individual cases, on how the competent authority classifies you. We give you a reasoned first assessment and a list of the documents you would be missing. A binding legal opinion should come from a lawyer.

The work is billed by time at €110 per hour plus VAT, with an estimated range of hours given before we start. You are not committed to anything: the action plan is written so that your existing provider or any other IT company can carry it out.

Book an infrastructure health check

Let us know your number of workstations and sites and what has prompted the review. We will propose a kick-off slot and an hours range by the end of the next working day.

Availability
Monday to Friday, 8:00-17:00 Austrian time (CET/CEST), reply within one working day
Meetings
By video on Microsoft Teams or Google Meet

We only use cookies that are technically required: to run the website and to remember the location you picked. There are no advertising or tracking cookies. Details are in the privacy notice.