Access and scope
We agree what is in scope, you provide read-level access, and we confirm nothing disruptive will run during business hours.
Network Security Audit
An audit is not a scan report with a logo on it. We inspect identity, firewall policy, patching, endpoint protection, backup integrity and external exposure, then rank what we find by risk and by what it costs to fix. The document is yours regardless of what you do next.
The Deliverable
Plenty of providers offer a free assessment that turns out to be a sales meeting with a screen share. Ours produces a written document with findings, evidence, risk ratings and remediation cost, and you keep it even if you never speak to us again.
Findings are ranked two ways, because those are the two questions an owner actually asks. First by risk: what is most likely to cause a breach or an outage. Second by effort: what can be fixed this week for free, what needs a project, and what needs a budget line next year. A list of forty findings in alphabetical order is useless. A list that says start with these three, they cost nothing, and they close most of your exposure is something you can act on Monday.
Identity and access: MFA coverage across every account, legacy authentication protocols, administrative account count and separation, dormant accounts belonging to former staff, password policy and conditional access rules. This is where the majority of real-world compromise happens and it is where most audits are thinnest.
Perimeter and network: firewall rule base with justification for every inbound permit, remote access exposure, firmware currency against published advisories, VLAN segmentation, and what your public IP addresses actually present to the internet. We also review wireless security, guest isolation and IoT placement.
Endpoint protection coverage and whether alerts are being reviewed by anyone. Patch state for operating systems and the third-party applications that get exploited in practice. Local administrator rights, disk encryption status, and machines running operating systems that no longer receive security updates.
Then the recovery side, which people forget is a security control. Are backups completing. Are they immutable or could an attacker with domain credentials delete them. When was the last successful restore test, and how long would a full recovery take. An environment with excellent prevention and no tested recovery is one bad morning from a very long week.
There is a free tier and a paid tier and we are open about the difference. The free Deep Dive is a genuine review: inventory, identity posture, patch state, backup verification, Microsoft 365 security settings, external exposure and network mapping. It finds the issues that affect most small businesses, and for a lot of companies it is enough. It takes us a few hours of work and we do it because it is also how we decide whether we can help you.
The paid audit goes deeper: full firewall rule-by-rule review, internal vulnerability scanning with authenticated checks, credential exposure research, segmentation validation, Microsoft 365 configuration against a hardening baseline, and a formal report suitable for an insurer or a client security questionnaire. Related work sits on our vulnerability testing page and cyber security page. More at security.orcait.io.
If you hand our findings to another provider and have them do the work, that is entirely your right. We would rather you fix the problems than leave them open out of loyalty to a quote.
Scope
Each area produces findings with evidence, a risk rating and a remediation estimate.
MFA coverage, legacy authentication, admin account sprawl, dormant accounts, conditional access and password policy across your tenant and domain.
What your public addresses present to the internet, open remote access, firewall rule justification and firmware currency on edge devices.
VLAN structure, inter-VLAN rules, where IoT and camera systems sit, and whether a compromised device could reach your servers.
Protection coverage, patch currency including third-party software, local admin rights, encryption status and unsupported operating systems.
Share structure, who has access to what, orphaned permissions, sensitive data locations and whether retention exists at all.
Job success, immutability, offsite copies, restore test history and a realistic estimate of your current recovery time.
| Element | Free Deep Dive | Paid audit |
|---|---|---|
| Asset inventory | Yes | Yes, with lifecycle detail |
| Identity and MFA review | Yes | Yes, plus conditional access design review |
| External exposure | Basic scan | Full external assessment |
| Firewall review | Obvious issues | Rule-by-rule with justification |
| Vulnerability scanning | No | Authenticated internal scanning |
| Backup verification | Job status and design | Live test restore |
| Report format | Prioritized summary | Formal report for insurers and questionnaires |
| Cost | Free | Quoted before we start |
How It Works
We agree what is in scope, you provide read-level access, and we confirm nothing disruptive will run during business hours.
Automated discovery plus manual review by an engineer. Tools find the obvious; a human finds the rule that should not be there.
Findings written up with evidence, risk rating and remediation cost, ordered so the highest value fixes are at the top.
We sit down and explain it in plain English, answer questions, and separate what you should fix now from what can wait.
Read-level access and passive discovery during business hours. Anything intrusive is scheduled and agreed in advance.
Yes, and you keep the report. It takes us several hours and we do it because it is also how we work out whether we are a good fit for your business. There is no obligation to buy anything and no charge if you decide to go elsewhere.
The standard audit uses read-level access and passive discovery, so it runs safely during business hours. Anything with potential to disrupt, such as intrusive scanning or a live restore test, is scheduled with you in advance and normally happens outside working hours.
Read-level administrative access to your Microsoft 365 tenant, domain, firewall and backup console, plus a site visit if you want the physical and wireless side covered. We document every account used and remove access when the audit finishes.
The free Deep Dive is usually a few days end to end, including scheduling. A full paid audit for a small business typically takes one to two weeks depending on size, complexity and how quickly access is arranged.
We always do. The most common findings are incomplete MFA coverage, dormant administrative accounts, unpatched edge device firmware, backups that have never been restore tested, and a flat network with cameras or IoT on the same segment as servers.
The paid audit is written for that purpose and maps directly to the questions insurers and client security questionnaires ask. The free version is a working document for you rather than a formal deliverable, though it will still tell you where you stand.
No. Findings are written so any competent provider can act on them, and plenty of clients fix the easy items themselves. We quote remediation if you want it, but the report is not a bait for a contract.
Annually for most small businesses, and after any significant change: a new office, a merger, a major system replacement or a security incident. Managed clients get continuous monitoring plus a lighter review at each Surface Check, which spreads the same work across the year.
An independent, written and prioritized view of your security posture.
Talk to Your Pod
The free Deep Dive covers the essentials and produces a real document. If you want depth, full configuration review, credential exposure, segmentation testing, we quote that separately and say so upfront.
(602) 677-0779Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced
A few details and your pod gets right back to you, usually the same business day.