What is actually there?
A complete inventory, including devices nobody remembers: the old NAS in the meeting room, the time-clock terminal, the multifunction printer emailing scans with a mailbox password stored inside it.
Instead of ploughing through an endless checklist, we answer seven questions every director ought to be asking. Each answer receives a colour rating and a short justification.
A complete inventory, including devices nobody remembers: the old NAS in the meeting room, the time-clock terminal, the multifunction printer emailing scans with a mailbox password stored inside it.
Open ports, the firmware level of the VPN gateway, certificates about to lapse, and the SPF, DKIM and DMARC records for your domain. In short, everything an attacker can learn without knowing a single password.
Former employees whose accounts are still live, admin rights attached to everyday logins, gaps in multi-factor coverage and shared credentials across Active Directory, Entra ID and your line-of-business applications.
Patch status of servers, clients, firewall and switches, together with a list of end-of-support dates so that replacements can be budgeted calmly instead of bought in a panic.
We restore a file as a test and, if you agree, an entire virtual machine, and we time it. We also establish whether a copy exists that ransomware would be unable to reach.
Domain, Microsoft tenant, internet connection, hosting and licences for BMD or your construction costing software: whose name is on them, when they run out and who could cancel or renew them in an emergency.
Relevant GDPR and Austrian data protection points, a preliminary view on whether you might qualify as an essential or important entity under NIS2, and the questions insurers and large customers tend to raise. We get you ready; we do not issue certificates.
For 20 to 40 workstations, allow two to three weeks from kick-off call to finished report. Your own staff spend only a few hours on it in total.
Forty-five minutes on video covering the trigger, your sites, the key applications and any known worries. Afterwards both sides know where to focus.
Temporary read-only accounts and an inventory agent gather data for several working days, supplemented by an external scan of your public IP addresses.
A test restore, a look through the admin centres and brief chats with a couple of everyday users, since workarounds and shadow IT never show up in tooling.
Four pages for management, plus a technical annex listing every finding and an action plan costed in hours. We go through both with you on Teams or Google Meet.
Orphaned accounts are among the least visible yet most widespread weak spots in small networks. The former bookkeeper can still open her mailbox, the summer intern from three years back still has VPN, and an outside supplier logs in through a shared admin account with no second factor. For an intruder, access like that is far more convenient than any software flaw. If we come across it, you hear from us straight away rather than weeks later in the report.
A scanner will spot open ports and missing patches. It will not notice that the domain is registered to the founder personally, or that backups have been writing to an empty folder ever since the server was moved. Tools do the legwork; people do the judging.
Before connecting for the first time we sign a data processing agreement. We use named accounts and recorded sessions, and we delete the raw data within the agreed period once the job is done. The report and annex remain with you.
Yes. The agent only needs one reachable computer per site, and someone on the spot can photograph the network cabinet with a phone. Each location gets its own chapter, as branches often look quite different from head office.
That depends on your sector, headcount and turnover and, in individual cases, on how the competent authority classifies you. We give you a reasoned first assessment and a list of the documents you would be missing. A binding legal opinion should come from a lawyer.
The work is billed by time at €110 per hour plus VAT, with an estimated range of hours given before we start. You are not committed to anything: the action plan is written so that your existing provider or any other IT company can carry it out.
Let us know your number of workstations and sites and what has prompted the review. We will propose a kick-off slot and an hours range by the end of the next working day.
Your enquiry has arrived
Our reply reaches you within one working day. Outages that leave your staff unable to work are dealt with first.
We could not find that town. Try another spelling, or choose whichever provincial capital lies closest; as everything is handled remotely, you get the same service in all nine Austrian states.