Home › Free IT health check

No cost · No obligation

A free 15-point IT health check.

Wherever you are in the country, most businesses have no real idea whether their backups work, who still has access to their systems, or what they are paying for and not using. We will look, and tell you plainly — in writing, in English, with nothing to sign.

Why we offer this

Because the first honest conversation is usually the most valuable one, and because most of what we find is not dramatic — it is a backup nobody has tested, three accounts belonging to people who left, a firewall four years past support, and a Microsoft subscription paying for licenses nobody uses.

None of that requires a sales pitch to be worth knowing. If you read the summary, fix it yourself, and we never hear from you again, that is a fine outcome. If you hand it to your current IT provider and ask them to sort it out, that is also fine — and honestly, if they do, they have earned keeping your business.

The fifteen points

This is the whole list. No hidden scoring, no proprietary index — just the things that actually determine whether a small business has a bad year.

Backups — and the last real restore

Not whether backups run. Whether anyone has successfully restored from one, and how long it took.

Multi-factor authentication coverage

What percentage of your accounts actually have it, including administrators. The answer should be all of them. For Microsoft 365 tenants we also pull your Secure Score and compare it against Microsoft’s benchmark for similar organizations.

Local administrator rights

Who can install software on their own machine. This is how most ransomware gets its foothold.

Patch status

Operating systems and third-party software — browsers, PDF readers, Java. The unglamorous ones are the ones that get exploited.

Endpoint protection

Present, current, and actually reporting in. We regularly find machines that stopped checking in months ago.

Firewall configuration and age

Firmware version, support status, and whether anything is exposed to the internet that should not be.

Email authentication records

SPF, DKIM and DMARC. Missing records mean anyone can send email that looks like it came from you.

Hidden mailbox rules

Forwarding and inbox rules across your mailboxes. The first thing an attacker sets up, and almost nobody checks.

License fit versus spend

What you are paying Microsoft or Google for against what you actually use. This one frequently saves money.

Dormant and departed accounts

Active accounts belonging to people who left. We find these on most first reviews.

Shared and reused credentials

Logins passed around the office, and whether anything important shares a password.

Device encryption

Full-disk encryption on every laptop and portable device. Massachusetts law is explicit about this one.

Network equipment lifecycle

Switches, access points and routers past end-of-support, still carrying your business.

Wi-Fi and guest separation

Whether guest traffic is genuinely isolated from your business network, and whether coverage matches your space.

Domain, DNS and SSL

Who owns your domain, when it expires, and who controls the DNS. More businesses than you would think do not hold their own.

KNOWLEDGE
DESIGNS

Fifteen points, one written summary, zero obligation.

Request yours →

Setting expectations

What this is not

It is not a scan that produces a red dashboard and a risk score out of a hundred designed to frighten you. It is not a pretext to get in front of you and pitch. And it is not a commitment — there is nothing to sign, no trial to cancel, and we will not put you on a follow-up sequence. If we find your setup is in good shape, we will say so and that will be the end of it.

How it works

1. A short call. Fifteen minutes to understand what you run, how many people, and what has been frustrating you. We will tell you exactly what read-only access we need. We never need anyone’s password.

2. We look. A couple of hours of our time across the fifteen points above. This is not intrusive and it does not interrupt anyone’s work.

3. A written summary. Back to you within a few business days: what is fine, what needs attention, and what is genuinely urgent — in that order, in plain language, with no obligation attached.

Anywhere in the US

Nationwide health checks

The whole review is remote, so where you are does not matter. We run these for businesses well outside Massachusetts, and the fifteen points are identical wherever you sit.

We are happy to work alongside your existing IT team. This is not a stalking horse for taking the account. Plenty of these are requested by an owner who wants a second opinion, or by an internal IT person who already knows something needs attention and would like it written down by somebody independent before they take it to the budget holder.

If that is the situation, say so when you get in touch and we will handle it that way — findings written plainly, addressed to whoever is going to act on them, with no pitch attached. If your provider is doing a good job, our report will say that too, and they can use it.

The only thing we will not do is tell you something is broken when it is not, whoever is asking.

Request your health check

Tell us a little about your setup and we will be in touch the same business day to arrange the short call.

No cost, no obligation, nothing to cancel. Your details stay with us — see our privacy policy.

Common questions

No. The review is entirely remote, so we run it for businesses anywhere in the United States. The fifteen points do not change with geography.

Not if we are told that up front. We are glad to work alongside an existing team, and a fair number of these are requested by internal IT people who want an independent write-up to support something they have already flagged. We report what we find, plainly, addressed to whoever will act on it — including saying so when the current setup is in good shape.

Genuinely free. It takes us a couple of hours, and we do it because businesses that see a clear picture of their own environment tend to make good decisions. If you take the report and fix everything yourself, or hand it to your current provider, that is a completely acceptable outcome.

No. There is no obligation of any kind, and we will not chase you. Plenty of these end with us telling a business their current setup is in decent shape, which is a perfectly good answer.

Read-only access is enough for most of it — typically a look at your Microsoft 365 or Google Workspace admin area, your backup console, and a brief look at the network. We will tell you exactly what we need before we start, and we do not need anyone’s password.

Usually a short call to understand your setup, then a couple of hours of our time, and a written summary back to you within a few business days.

A written summary in plain language: what is fine, what needs attention, and what is genuinely urgent, in that order. No risk scores out of a hundred, no red dashboard designed to frighten you into buying something.

We will tell you what we found, factually. Sometimes that reflects well on the incumbent and sometimes it does not. What we will not do is manufacture alarm to win the account — that is the oldest trick in this industry and we would rather not be in that business.

Related: How to choose an IT provider · Switching IT providers · Small business cybersecurity.

Rather just talk it through?

Prefer to pick a time? Book an appointment →

Or call (978) 885-1819 — if we’re on a job, leave a message and you’ll hear back the same business day.