Advanced IT Support • Managed IT Services • Jacksonville, FL

What Actually Happens During a Free IT Assessment

Not a sales meeting with a clipboard. Here is the exact inventory we run, step by step

Quick AnswerA free IT assessment should be a genuine inventory of your environment, not a sales pitch. It typically covers your devices and network equipment, where your data actually lives, whether your backups would actually restore, account security including former employee access, and your current security stack. You walk away with a written summary of what’s there and where the gaps are, whether or not you hire the provider afterward.
“Free assessment” is one of those phrases that makes people brace for a sales pitch dressed up as a favor. That skepticism is fair, a lot of “free assessments” in this industry are exactly that. This post explains what a free IT assessment should actually involve, what we specifically look at when we do one, and what you should expect to walk away with regardless of whether you ever hire us.

The honest version of this process has a simple goal: find out what’s actually in your environment, where the risk is, and give you a clear picture of it. Whether that leads to a conversation about working together is a separate question, and it shouldn’t change what you get out of the assessment itself.


Why “Free” Makes People Suspicious, and Why That’s Fair

A lot of “free assessments” in IT and other industries are built to manufacture urgency. A sales rep walks through a scripted checklist, finds a handful of alarming-sounding issues regardless of the actual environment, and uses that as leverage to push a signature before you leave the room.

We think that approach is a bad way to earn a client and an even worse way to run a business long term. An assessment is worth doing because understanding your own environment has value on its own, not because it’s a means to an end. Here’s what that actually looks like in practice.


Step 1: A Full Inventory of What You Have

What we’re looking at

Every device connected to your network: workstations, laptops, servers, printers, firewalls, switches, access points. We document what’s there, how old it is, and what condition it’s in. For most small businesses, nobody has a complete, current list of this anywhere, which makes this step useful on its own even before any analysis happens.

This step often surfaces things the business owner didn’t know were there: an old server nobody remembers the purpose of, network equipment nearing end of life, a firewall running firmware that hasn’t been updated in years. None of that requires any judgment call, it’s just an accurate accounting of what exists.


Step 2: Where Does Your Data Actually Live

What we’re looking at

For every critical system, email, accounting, client records, line-of-business applications, we trace where the actual data lives. Cloud-hosted and reachable from anywhere, or tied to a physical server in the office. Most businesses are a mix of both, and few owners have a clear map of which is which.

This matters for a lot of practical reasons: what happens if the office loses power, what your options are for remote work, and what your actual exposure looks like if a single piece of hardware fails. It’s also directly relevant to disaster planning of any kind, including hurricane preparedness for businesses in this region.


Step 3: Backup Verification, Not Just Backup Existence

What we’re looking at

Whether backups exist, how often they run, where they’re stored, and critically, whether they’ve ever actually been tested with a real restore. A backup that has never been tested is an assumption, not a guarantee, and this is one of the most common gaps we find.

We’ll also check whether backups are stored somewhere genuinely separate from the systems they protect. A backup drive sitting next to the server it backs up doesn’t hold up in a lot of failure scenarios, including the kind we’ve seen firsthand with ransomware.


Step 4: Account and Access Security

What we’re looking at

Who has access to what, whether multi-factor authentication is enabled on critical accounts, and whether any former employees still have active credentials. This last one comes up more often than most business owners expect.

Finding an active account belonging to someone who left the company months or years earlier is one of the most common findings in an assessment. It’s rarely malicious, it’s just a step that fell through the cracks because nobody had a consistent offboarding process. We’ll flag exactly what we find here without any judgment attached, since almost every business we assess has at least one gap like this.


Step 5: Your Current Security Stack

What we’re looking at

What’s actually protecting your environment beyond basic antivirus: endpoint detection and response, email filtering, dark web monitoring, and how current your patch and update status is across every device.

We compare what’s in place against what a current security baseline actually looks like, not a generic checklist, but the specific layers that address the attacks we see most often: phishing, credential theft, and ransomware exploiting unpatched systems. Where there are gaps, we’re specific about what they are and why they matter, rather than a vague “your security needs work.”


Step 6: Documentation and Who Actually Owns It

What we’re looking at

Whether network documentation, passwords, and licensing information exist somewhere accessible to the business itself, or whether that information is locked inside a current or former IT provider’s systems with no clear way for you to get to it.

This one often surprises business owners. If your current provider left tomorrow, could you get into your own systems? For a meaningful number of businesses we assess, the honest answer is no, and that’s worth knowing regardless of who ends up managing the environment going forward.


What You Walk Away With

At the end of the assessment, you get a written summary covering what we found in each of the areas above: your inventory, where your data lives, your backup status, your account security findings, your security stack gaps, and your documentation situation. It’s specific to your environment, not a generic template with your company name filled in.

You keep this regardless

The summary is yours whether or not you ever become a client. If the findings lead to a conversation about working together, that conversation happens after you’ve seen the assessment, not as a condition of getting it. If you take it to another provider or handle the gaps yourself, that’s a completely reasonable outcome and not one we’re going to make awkward.


How Long It Takes and What We Need From You

For most small businesses, an assessment takes a few hours on site combined with some remote review of systems and accounts. We’ll need access to view your network, your key systems, and a conversation with whoever manages your accounts day to day, usually an office manager or the owner.

We don’t need administrative control of anything to do this. Read access and a walkthrough conversation are enough to build an accurate picture. Nothing changes in your environment during an assessment, we’re documenting and reviewing, not making modifications.


An Assessment Should Give You Something, Not Just Take Something

The test for whether a “free assessment” is worth your time is simple: does it produce something useful on its own, or does it only exist to set up a pitch? A real assessment leaves you with an accurate picture of your own environment that you didn’t have before, and that has value regardless of what you decide to do with it.

That’s the standard we hold ours to.