Defensive assessment

Infrastructure Security Assessment for SMBs

A structured technical baseline assessment for businesses that want to know which risks should be addressed first. Offensive testing is not part of the standard scope.

SecureInfra methodology
READ-ONLY
ScopeWindows / Linux / AD / Backupagreed
EvidenceTraceable and structuredpreserved
OutputPrioritized actions30/60/90
The exact scope depends on your environment.
What is assessed

Not a generic scan, but a clearly defined assessment scope.

Not every company needs the same checks. Before work begins, we define which systems and roles are relevant. Missing evidence is not reported as a confirmed weakness.

Systems & servers

Windows and Linux baselines, services, local security settings and relevant operational information.

Identity & AD

Users, privileged roles and selected GPO, trust and delegation contexts depending on the agreed scope.

Network

Locally bound services, firewall context, allowed source networks and evidenced external reachability are clearly distinguished.

Backup

Evidence about coverage, recency, monitoring and documented recovery tests.

Server roles

Depending on the environment, IIS, RDS, SQL Server and Exchange can be added selectively.

Documentation

Technical evidence is translated into understandable findings, priorities and an actionable plan.

Methodology

Observed does not automatically mean reachable – and it does not automatically mean risk.

We distinguish technical observation, reachability, exploitability and business relevance as far as possible. Unknown or uncollected information remains explicitly visible as such.

Standard scope

Technical collection is defensive and strictly read-only. There is no active exploitation, password spraying, credential theft or destructive change. Extended or offensive testing requires a separate written agreement.

You receive

Technical depth and a management view based on the same evidence.

The deliverables are designed to support decisions and implementation – not merely count findings.

Executive Summary

Key risks, priorities and limitations in an understandable form.

Technical Findings

Traceable findings with context, evidence and recommendations.

30/60/90-day plan

Prioritized sequence for immediate and planned actions.

Evidence Summary

Transparency about the evidence behind the assessment and its limitations.

Remediation Tracker

Structured working list for status, ownership and follow-up.

Review meeting

Joint review and selection of the most sensible next steps.

Process

From agreed scope to the review meeting.

Systems, responsibilities and data use are clarified before work begins. Technical collection starts only after the scope is agreed.

01

Initial discussion & scope

Clarify environment, goals, scope and organizational boundaries.

02

Collection

Collect agreed technical evidence read-only.

03

Analysis & review

Assess results in technical context and prepare the report.

04

Results & planning

Review the report and prioritize next actions.

Start without commitment

We first clarify whether the assessment fits your environment.

For the first inquiry, an approximate number of systems and a brief description of your situation are enough.