Security assessments usually arrive as a list of products you do not own yet. This one starts from your actual exposure: what an attacker would reach first, what it would cost you, and which controls change that math. Companies of your size are rarely targeted by name. They are caught in campaigns that punish the ordinary gaps.
Ransomware is a business continuity event with a legal and insurance tail. What determines the cost is not the malware; it is whether identity, backups, and the first hour of response were sorted out beforehand.
We score against this benchmark, meaning what a well-run company of 50 to 500 employees should reasonably have in place, rather than against theoretical perfection.
Every account that touches company data requires a second factor, including administrators, contractors, service accounts, and the legacy systems that sit outside your identity provider.
Standing admin access is the exception rather than the convenience. Someone can produce the current list of privileged accounts and explain why each one exists.
Offboarding is a defined process covering every system, not just email, and there is evidence it ran for the last several people who left.
Detection tooling is monitored by a named party, internal or contracted, with an agreed response time. A license that nobody watches is a purchase, not a control.
People know who declares an incident, who calls the insurer and counsel, who can authorize a shutdown, and how the company communicates while systems are down.
Insurance applications and customer security questionnaires are answered from documented reality, so the answers stay true when they are tested at claim time.
Patterns common enough to name. None of them indicate a bad team. They are what happens when a company grows faster than the decisions that shaped its technology.
Coverage is real for email and genuinely absent for the VPN, the ERP, or a shared administrative account, precisely the paths an attacker prefers.
Accounts still active months after departure, almost always in a system that sits outside the central identity provider and outside the offboarding checklist.
Endpoint detection is deployed and licensed, and the alerts land in a console or mailbox that no one has an obligation to read within any particular timeframe.
Questions about MFA, backups, or privileged access were answered as intended rather than as implemented. The gap becomes a coverage argument at exactly the wrong moment.
The backup system trusts the same directory as everything else, so a single compromised administrator account takes production and recovery together.
Where a document does not exist, that is itself a finding, and we say so plainly rather than treating the gap as an obstacle.
What would a ransomware event actually cost us, and how likely is it today?
Can we answer our largest customer’s security audit without a fire drill?
Every domain is scored 0–10 on the same scale, so the scorecard shows you where to look first rather than a single undifferentiated grade.
Something here can hurt the business now. These findings lead the roadmap.
Functioning, but behind where a company of your size and stage should be.
In good shape. Worth maintaining rather than investing further right now.
A genuine strength, and often something to build on elsewhere.