Cybersecurity Assessment for Small Businesses
Understand your IT security setup and what needs attention
Your business may have antivirus, backups, and multi-factor authentication in place, yet still lack a clear picture of how they are configured and managed.
Turbo IT Solutions provides a paid cybersecurity assessment for small businesses in Vancouver and across Metro Vancouver. We review everyday business IT within an agreed scope and provide documented findings and practical priorities.
You gain a clearer basis for security decisions and spending. The report has value on its own, with no obligation to purchase implementation or ongoing support.
What we can review
The areas below illustrate what an assessment can cover. We agree with you on the systems and depth of review before preparing a quote. Only the agreed areas are included.
IT assets and software
Available inventories of computers, servers, network equipment, software, and cloud services. We look for unsupported software, unmanaged devices, unclear administrative ownership, and documentation gaps that could affect security decisions.
User accounts and access controls
How access is granted, managed, and removed. This can include multi-factor authentication (MFA), administrator privileges, shared and inactive accounts, password-management practices, third-party access, and employee onboarding and offboarding.
Windows computer and server security
Relevant settings on Windows computers and Windows servers, where used: operating-system and application updates, Microsoft Defender or other endpoint protection, endpoint detection and response (EDR) where deployed, Windows Firewall, BitLocker encryption and recovery-key management, local administrator rights, and remote access.
Where Active Directory, Group Policy, or Microsoft Intune is in use, the review can include relevant policies and their application to the devices in scope.
Microsoft 365 and Google Workspace security
Cloud security settings, taking account of your subscription and available features.
For Microsoft 365, this can include Microsoft Entra ID administrator roles, MFA enforcement, Security Defaults or Conditional Access policies, legacy authentication, and external access or sharing in Exchange Online, SharePoint, OneDrive, and Teams.
For Google Workspace, this can include administrator roles, 2-Step Verification enforcement, account recovery, Gmail security settings, Google Drive sharing, and third-party application access.
Email security and domain authentication
Spam, phishing, and impersonation settings, external forwarding, mailbox delegation, and SPF, DKIM, and DMARC configuration.
Detailed investigation of delivery failures or domain reputation can be scoped through our separate Email Deliverability & Domain Reputation service.
Network, firewall, and remote-access security
Relevant router, firewall, switch, and Wi-Fi configurations, including firmware maintenance, administrative access, guest-network separation, VPN connections, and other remote-access arrangements.
The review can also cover port-forwarding rules, internet-facing services identified in available configurations, physical access to network equipment, and configuration backups.
Data access, backups, and recovery arrangements
Where important business information is stored and how access is controlled, including relevant file-server permissions and cloud-sharing settings.
Backup reviews can cover schedules, retention, administrative access, failure notifications, separation from production systems, offline or immutable copies, and available records of restore testing. Performing a restore test is included only when expressly agreed in the scope.
Security logging and incident readiness
Whether relevant logs and alerts are enabled, how long records are retained, and who reviews or responds to them.
The assessment can also cover existing procedures for reporting suspicious activity, handling lost devices or compromised accounts, and maintaining staff security awareness. This reviews existing arrangements; it does not provide ongoing monitoring or incident response.
What you receive
You receive a written report with a plain-English summary, technical findings your chosen IT provider can use, and a discussion of the results.
The report covers:
- The systems and security arrangements reviewed.
- Controls that appear adequate based on available evidence.
- Identified gaps, their significance, and recommended priorities.
- Practical next steps, including areas needing further investigation.
- Review limitations and information that could not be verified.
We combine configuration reviews, available documentation, and discussions with you or your IT contact. Recommendations draw on relevant vendor guidance and established security practices, including applicable CIS Controls.
This is a general assessment within an agreed scope and depth. It does not include penetration testing or certify compliance. Findings reflect the evidence available at the time; they do not establish that every vulnerability has been identified.
Custom applications, development infrastructure, and specialized server environments are outside the general scope. Reviewing them requires a separate agreement, appropriate expertise, and input from the people who manage those systems. Areas outside scope or unavailable for verification are identified in the report.
Scope and pricing
Tell us about your business, the systems you use, and any particular concerns. We first agree on the scope and depth of review, then provide a quote covering the deliverables and fee. Required access, your team’s involvement, and expected delivery timing are confirmed before work begins.
Work begins after you accept the quote and make payment.
The report is a standalone deliverable. You can act on it internally, share it with your existing IT provider, or choose another firm to implement the recommendations.
If you would like Turbo IT Solutions to assist with implementation, that work is optional and separately scoped and quoted. No ongoing IT service agreement is required.
