Cloud Data Services · Managed services

IT Security Review

A scoped assessment of your business IT security

Vikingegaarden reviews the accounts, systems and networks your business depends on. Three packages cover core IT controls, third party systems and, where agreed, network traffic analysis. The scope is confirmed before work begins, with findings and recommended actions reported for your team.

  • Three packages
  • Fixed scope
  • Written report
  • Ranked by risk
areas reviewed: accounts, patching, firewalls, wireless, backup
5
language findings, readable without an IT background
Plain
by risk and effort, so you fix the important things first
Ranked

Overview

What gets reviewed

Each package builds on the one before it. Most companies start with the first and decide from the findings.

Package 1: the standard weak points

A review of the points most often misused in a standard IT system: password policy, Windows updating and patching, user access in AD, administrator accounts, firewall security, wireless network security, security on the wired network, and a review of your backup.

Package 2: third party systems

Everything in package 1, plus a deeper look at the company's IT systems: the third party software the company depends on, whether it is updated and patched, and the security of external services such as DNS, cloud email and other cloud services.

Package 3: traffic and behaviour

All points from packages 1 and 2, extended with analysis of network traffic over an agreed period. Security hardware is installed to monitor the company's traffic pattern and flag what may pose a threat, alongside a further in depth review of user IT behaviour on the company's machines.

Findings ranked by risk and effort

Findings are prioritised by risk and the work required, helping the business decide which actions to address first.

Findings for the management team

A written report describes the findings and recommended actions in clear language for the people responsible for the business.

How it works

How an IT security review runs

A fixed scope agreed up front, a structured review, and a written report at the end.

The review starts with a short conversation about the size of the installation: roughly how many users and systems the company runs. From that we recommend a package, confirm the fixed scope and tell you what it costs, so there is no open ended engagement.

The review itself works through the agreed areas: accounts and password policy, patching, user access in Active Directory, administrator accounts, firewalls, wireless and wired networks and backup, extending into third party software and external cloud services in package 2, and into monitored network traffic and user behaviour in package 3. The result is not a pile of raw scanner output but a written report: each finding described in clear language, with its risk and the recommended action, ranked so you know what to fix first.

  • Tell us roughly how many users and systems you run

  • We recommend a package and confirm the fixed scope and price

  • The review works through accounts, patching, firewalls, networks and backup

  • Package 2 extends into third party software, DNS, cloud email and other cloud services

  • Package 3 adds monitoring hardware and traffic analysis over an agreed period

  • You receive a written report with findings ranked by risk and effort

Product guide

IT security review packages for small and mid sized companies

Use an agreed review scope to understand which IT controls have been checked and what action the findings require.

Agree the scope before the review

Start with the number of users, the systems they rely on and the areas that need to be examined. A defined scope makes it clear which controls and systems are included and what the business will receive at the end.

The packages build on one another. The first covers core controls, the second extends into third party systems and cloud services, and the third adds traffic analysis over an agreed period.

Package 1: the standard weak points

The first package reviews password policy, Windows updates and patching, user access in Active Directory, administrator accounts, firewall settings, wired and wireless network security and backup.

These checks address the configuration and maintenance of the systems used in everyday work. Findings help identify accounts, settings and routines that need attention.

Package 2: the third party systems you depend on

The second package includes the first package and examines the third party software and external services the company uses. It covers updates and patching for those systems and security of services such as DNS, cloud email and other cloud services.

Identify these dependencies when the review is scoped so the relevant systems and responsibilities can be considered.

Package 3: watching the traffic, not just the configuration

The third package adds analysis of network traffic over an agreed period. Security hardware is used to monitor traffic patterns, together with a further review of user IT behaviour on the company's machines.

The monitoring period and systems included are agreed for the review. Ongoing monitoring or incident response requires its own defined service scope.

The report, and what happens after it

The review produces written findings and recommended actions, prioritised by risk and the work required. The business can use that report to assign follow-up work and decide which improvements to address first.

For a specific need around shared passwords and team access, NordPass business licences and rollout support are available separately. Contact Vikingegaarden in Denmark to discuss the scope of a broader IT security review.

Good to know

Frequently asked questions about the IT security review

What does an IT security review cover?

The core review covers the standard weak points of an IT installation: password policy, Windows updating and patching, user access in Active Directory, administrator accounts, firewall security, wireless and wired network security and backup. Larger packages extend into third party software, external cloud services and monitored network traffic.

Which security package should we start with?

Most companies start with package 1, the review of the standard weak points, and decide from the findings whether to go deeper. The packages build on each other, so nothing is lost by starting small: package 2 includes everything in package 1, and package 3 includes both.

What does package 2 add to the basic review?

A deeper look at the company's IT systems: the third party software the company depends on, whether those systems are updated and patched, and the security of external services such as DNS, cloud email and other cloud services.

What does package 3 add?

Analysis of what actually happens on the network. On top of all points from packages 1 and 2, security hardware is installed to monitor the company's traffic pattern over a given period and flag what may pose a threat, and the review goes further into user IT behaviour on the company's machines.

What do we receive at the end of the review?

A written report with the findings, the risk each finding carries and the recommended action, ranked by risk and effort. It is written in plain language so it can be read by people who do not work in IT, including a board.

Who is the IT security review for?

Small and mid sized companies that depend on their IT but do not have a dedicated security function. The fixed scope and the plain language report are designed so that management can commission the review and act on it without translating between security specialists and the business.

How do we book an IT security review?

Contact us and tell us roughly how many users and systems you run. From that we recommend the package that fits, confirm the fixed scope and tell you what it costs before anything starts.

Does the review include ongoing monitoring or incident response?

Package 3 includes traffic analysis over an agreed period. Continuous monitoring and incident response are not implied by the review package and need a separately agreed scope. Confirm the systems, review period and expected deliverables before work starts.

Have a question about your project?

Talk to our team

Let’s talk about your project

Book a security review

Tell us roughly how many users and systems you run and we will tell you which package fits and what it costs.

Talk to Vikingegaarden

Discuss your project

IT Security Review

Tell us what you need. We will help with the configuration and next steps.

Your contact details and project

We use your details to respond to your enquiry. Privacy policy

Prefer to speak to us? +45 7580 3960
sales@vikingegaarden.com