Get in touch
Holistic Approach

Holistic IT and security assessment (Holistic Approach)

We see the whole picture. We fix what matters. An assessment that looks at technology, security, cost and compliance together.

Most businesses look at their IT piece by piece: one supplier for the network, another for email, another for security, and nobody for the whole. The Holistic Approach (HA) does the opposite: it examines the whole picture together, because the real risk hides in the gaps between the pieces.

We start with a meeting with the owner or the IT manager. We map how the business works, from infrastructure and applications to networks and telecommunications, and propose improvements: more modern technology, lower cost, fewer and better connected tools. The proposals are centred on Microsoft 365 and cybersecurity, and are given both as immediate actions and as a 12-month programme.

What is included
  • Meeting with management and the IT manager
  • Mapping of infrastructure, applications, systems, networks and telecommunications
  • Maturity scoring and an HA score from 0 to 100
  • Cost analysis and technology consolidation proposals
  • Mapping to NIS2 (Article 21), ISO 27001 and the CIS Controls
  • 30-day quick wins and a 12-month programme
  • Presentation of the results to management

What we examine: 10 pillars

Each pillar contains specific controls that are scored on a maturity scale from 0 to 4.

IT strategy and governance

Who decides, on what criteria, and how well IT is controlled.

Identity and access

Accounts, multi-factor authentication, administrator rights.

Devices and endpoints

Management, protection and compliance of computers and mobile devices.

Productivity and collaboration (Microsoft 365)

How well the licences and tools you already pay for are used.

Data and information protection

Where the data is, who has access and how it is protected.

Applications and business systems

The applications your work depends on and how they connect to each other.

Infrastructure and cloud

Servers, storage and cloud services, and what they cost.

Networks and connectivity

Network, firewall, remote access.

Telecommunications

Telephony and connections, in relation to cost and need.

Security operations and resilience

Backup, monitoring, incident response, business continuity.

Four lenses, one picture

Security

How exposed are we? Maturity scoring, critical gaps and 30-day quick wins.

Cost

Are we paying the right amount for technology? Cost baseline, overlaps, consolidation and right-sized licences.

Compliance

Are we in line with NIS2 and GDPR? Mapping to Article 21 of NIS2, ISO 27001 and the CIS Controls.

Productivity

Are people working efficiently? Making the most of Microsoft 365 and simplifying tools.

How we work

For the full assessment the target is 10 working days from the meeting with management to the presentation of the results.

Meeting and assessment

A conversation with the owner and the IT manager, to understand how the business works.

Data collection

Microsoft 365 configuration data in read-only mode, an inventory and three months of bills.

Analysis

Scoring of the controls, cost and consolidation analysis, mapping to NIS2.

Design

Quick wins of 0 to 30 days, phase 1 (1 to 3 months) and a 3 to 12-month programme, with a business case.

Management presentation

The picture, the risks, the financials and the decision on the next step.

Implementation

Quick wins and the programme, with owners and a timeline.

Quarterly review

A review every quarter and a new HA score, so progress is visible.

What we deliver

HA Snapshot

One page: the HA score, the top five risks and three quick wins.

HA Report

Summary, a view of the 10 pillars, findings, roadmap, cost and NIS2 mapping.

Management presentation

Ten slides: the picture, risks, financials, decision.

Technical findings

A detailed file with the evidence and the score of every control.

Ways of working together

You can start with a first look and go as far as you want. For pricing, talk to us.

Discover

A short meeting and a first picture with the HA Snapshot.

Assess

The full assessment and the presentation to management.

Program

Implementation of the quick wins and the 12-month programme.

Continuum

Quarterly review and tracking of progress.

Frequently asked questions

What is the holistic IT and security assessment (Holistic Approach)?

It is an assessment of a business's IT and security that examines infrastructure, applications, networks, telecommunications, security, cost and compliance together, and ends with a concrete improvement plan.

Who is it for?

Small and medium businesses, typically from 10 to 300 employees, that want an overall picture of their IT and a prioritised plan, without needing their own IT department.

Do you need access to my systems?

For Microsoft 365 we collect configuration data in read-only mode, with permissions that you approve. We do not change anything in your systems during the assessment.

How long does it take?

For the full assessment the target is 10 working days from the meeting with management to the presentation of the results. The duration depends on size and on how quickly the data is provided.

What happens after the assessment?

You get a prioritised plan: 30-day quick wins and a 12-month programme. You decide which of the proposals go ahead and how.

Is it a NIS2 compliance audit?

The assessment maps the findings to the Article 21 measures of NIS2, but it is not legal advice or an official compliance audit. It can be the basis for a compliance programme.