The review starts with a short conversation about the size of the installation: roughly how many users and systems the company runs. From that we recommend a package, confirm the fixed scope and tell you what it costs, so there is no open ended engagement.
The review itself works through the agreed areas: accounts and password policy, patching, user access in Active Directory, administrator accounts, firewalls, wireless and wired networks and backup, extending into third party software and external cloud services in package 2, and into monitored network traffic and user behaviour in package 3. The result is not a pile of raw scanner output but a written report: each finding described in clear language, with its risk and the recommended action, ranked so you know what to fix first.
Tell us roughly how many users and systems you run
We recommend a package and confirm the fixed scope and price
The review works through accounts, patching, firewalls, networks and backup
Package 2 extends into third party software, DNS, cloud email and other cloud services
Package 3 adds monitoring hardware and traffic analysis over an agreed period
You receive a written report with findings ranked by risk and effort