Service · IT infrastructure

IT infrastructure review

Switching IT supplier, renewing a cyber insurance policy, bidding for a public contract, or simply wanting to stop relying on the one colleague who knows every password: nearly every review we run starts with one of these. What helps at that point is not somebody's opinion but a trustworthy snapshot of how things really stand. Our engineers take it by connecting from a distance with read-only permissions, leaving settings untouched and never setting foot in your office. The report is written for management, and the technical detail sits in appendices for whoever carries out the work.

Fully remote
nobody visits
Read-only
nothing gets changed
Traffic lights
red, amber, green
Hours quoted
for each task

What falls within the scope of this service

Seven areas are covered. In a small firm some of them fill half a page; with several offices each earns a chapter of its own.

Pin down the details with one of our engineers

Network and service map

Which devices exist, how they link up, what faces the internet and through which route. If no diagram exists, we draw one from the scan results and photos your staff send across.

Servers and virtual machines

OS version, outstanding patches, disk health, free space, installed roles nobody uses, and services starting under administrator credentials.

Workstations

Machines still on unsupported Windows 10, drives without BitLocker, staff with local admin rights, lapsed antivirus and computers that have not rebooted in months.

Microsoft 365 or Google Workspace

Two-factor coverage, automatic forwarding to outside addresses, shared mailboxes with their own password, unassigned licences and third-party app permissions someone clicked through without reading.

Backup and recovery

How long it would genuinely take to get working again if the server died first thing on a Monday, and how many days of work would vanish. A test restore proves the answer.

Suppliers and ownership

Domain, fibre line, hosting, ERP licences and support contracts: who holds them, when they expire and who has the login details.

Applicable rules

Points that matter under GDPR and Spain's LOPDGDD, under NIS2 where your sector is in scope, and under the ENS if you serve the public sector. We lay the groundwork; we do not certify.

How the engagement unfolds, one stage at a time

For a business with 20 to 40 users and one or two servers, expect two or three calendar weeks. The precise timetable is fixed up front.

01

Pre-review questionnaire

Twenty plain questions about your company, software and suppliers. Thirty minutes to fill in, and it saves days later on.

02

Access and scanning

Your administrator sets up temporary read-only accounts. A small agent collects information over several working days without bothering anyone.

03

Short user chats

Fifteen-minute video calls with two or three people from different departments. What users tell us rarely shows up in any scan.

04

Report and walkthrough

Executive summary, risk traffic lights, technical appendices and an action plan with hour estimates, presented together in an online meeting.

The most common risk is not malware but a single person. In many small firms everything hinges on one employee or outside technician who knows it all and has written none of it down. If they leave, fall ill or close their business, nobody can renew the domain or log in to the router. That is why the report includes a register of credentials and account holders that stays with you.

Common questions

Usually, yes. Cyber policy questionnaires ask about two-factor sign-in, offline backups, patching and antivirus, and the report answers all of that with evidence. If your broker has sent a specific form, share it at the start and we will cover it.

Normally. All it takes is someone in your company with a Microsoft 365 admin account and access to one machine on the network for the agent. Anything the provider refuses to hand over is recorded in the report as a risk in its own right, because it is one.

No. We work in read-only mode, with named accounts, two-factor sign-in and every session logged, and we sign the GDPR processor agreement before connecting. If we find something critical, such as remote desktop open to the internet, we alert you that day and you choose who fixes it.

Not at all. The action plan is written so any competent technician can follow it. Many firms use it to collect quotes from several suppliers and compare them on equal terms.

It is charged by the hour at €75 per hour + VAT, within a range agreed before we begin. If you already have a Start, Business or Premium plan, the time comes out of your plan hours in line with your contract.

Book your infrastructure review

Tell us how many users and offices you have and what prompted the idea. Within one working day we will send the questionnaire and a likely range of hours.

Hours
Monday to Friday, 9:00-18:00 Spanish time (CET), answers within a working day
Meetings
Video calls via Google Meet or Teams

This site only stores the cookies it needs to work and to remember your chosen city. No advertising or tracking cookies are set. See our privacy policy for the details.