Cybersecurity Environment Review & Recommendations
Authorized technician assessment. Do not enter passwords, recovery codes, private keys, or other authentication secrets.
Use the client contact authorized to receive the completed assessment and recommendations.
Enter “Internal IT” or “None” when applicable.

Assessment Scope & Authorization

Define exactly what was reviewed. Record exclusions so the final report is defensible and does not imply systems were assessed when they were not.
Use “Client self-reported only” only when no technical verification was performed.
Assessment Evidence Sources
Select only evidence actually used.
Authorized Access Confirmed
Confirm the client authorized Tek Guy On Demand to review the systems and settings included in scope.

Business Operations & Sensitive Data

Connect technical findings to operational impact, legal obligations, and the information the client must protect.
Sensitive or Regulated Information Handled
Select all categories stored, transmitted, or processed by the organization.
Primary Data Storage Locations
Applicable Security, Contractual, or Insurance Requirements

General Technology Overview

Record approximate totals before completing the detailed inventory.
List all internet providers when the site has failover or multiple circuits.

Detailed Device & Infrastructure Inventory

Add every workstation, server, printer, firewall, switch, access point, NAS, POS system, camera system, and IoT device discovered. Do not record passwords, recovery codes, private keys, or other authentication secrets.
Use the actual hostname when available; otherwise enter a clear descriptive name.
Connected By
Observed Account and Software Risk Conditions
Check only conditions that were observed or verified.
Drag & Drop Files, Choose Files to Upload You can upload up to 5 files.
Upload only necessary evidence. Do not upload images showing passwords, recovery codes, private keys, full payment-card data, or other authentication secrets.

Network Infrastructure

Assess segmentation, remote access, internet exposure, wireless security, and unknown devices.
VPN Configured
Select a verified or reported status. Do not assume that an unanswered control is secure.
Remote Access Enabled
Select a verified or reported status. Do not assume that an unanswered control is secure.
Firewall Threat Protection / IDS / IPS Enabled
Select a verified or reported status. Do not assume that an unanswered control is secure.
Guest Wi‑Fi Available
Select a verified or reported status. Do not assume that an unanswered control is secure.
Guest Wi‑Fi Segregated
Select a verified or reported status. Do not assume that an unanswered control is secure.
Managed Switches
Select a verified or reported status. Do not assume that an unanswered control is secure.
VLANs Configured
Select a verified or reported status. Do not assume that an unanswered control is secure.
Flat Network
Select a verified or reported status. Do not assume that an unanswered control is secure.
Externally Accessible Ports Documented
Select a verified or reported status. Do not assume that an unanswered control is secure.
Remote Desktop Exposed To Internet
Select a verified or reported status. Do not assume that an unanswered control is secure.
Port Forwarding Configured
Select a verified or reported status. Do not assume that an unanswered control is secure.
Unknown or Unauthorized Devices Detected
Select a verified or reported status. Do not assume that an unanswered control is secure.
Network Device Administration Restricted to Trusted Sources
Firewall / Network Configuration Backups Maintained
UPnP Enabled on Business Network
Default Network Equipment Credentials Present
DNS or Web Content Filtering Enabled

Identity & Account Management

Review how users, administrators, former employees, vendors, and cloud identities are controlled.
Primary Identity Platforms
MFA Enforced for All Users
MFA Enforced for All Administrators
MFA Methods in Use
Former Employee Accounts Disabled Promptly
Inactive and Dormant Accounts Reviewed
Separate Administrator Accounts Used
Password or Account Sharing Occurs
Approved Password Manager Used
Conditional Access / Risk-Based Login Controls Configured
Third-Party Access Is Time-Limited and Reviewed

Email Security

Review email identity controls, sender authentication, filtering, backup, and recent compromise indicators.
MFA Enforced for Email Accounts
Spam Filtering Enabled
DKIM Configured
SPF Configured
DMARC Configured
Email Backups Enabled
Users or Accounts Affected by Recent Phishing / Email Compromise
Mailbox Auditing and Suspicious Sign-In Alerts Enabled
Automatic External Email Forwarding Allowed
Email Administrator Accounts Are Separate and Protected

Patch & Vulnerability Management

Determine whether operating systems, applications, firmware, and identified vulnerabilities are managed consistently.
Operating System Updates Centrally Managed
Third-Party Applications Regularly Updated
Firewall, Switch, Access Point, Printer, and IoT Firmware Reviewed
Unsupported Operating Systems or Applications Present
Authenticated or Internal Vulnerability Scanning Performed
Security Advisories and New Vulnerability Alerts Monitored

Security Monitoring & Detection

Confirm whether security tools are actively monitored and whether meaningful alerts reach someone who can respond.
Endpoint Protection Covers All Supported Endpoints
Security Alerts Monitored Outside Business Hours
Firewall and Network Security Events Reviewed
Microsoft 365 / Google Workspace Security Alerts Enabled
Unusual Login Locations and Repeated Failures Monitored
Centralized Logging or SIEM Implemented
Known Security Incidents or Warning Events
Security Alerting and Escalation Tested

Backup & Disaster Recovery

Verify backup coverage, isolation, security, retention, testing, and recovery objectives.
Backups Currently Performed
Backup Restore Tested Recently
Immutable Backups
Air‑Gapped Backups
Written Disaster Recovery Plan
Ransomware Recovery Plan
Cyber Insurance Policy Active
Systems and Data Included in Backup
Backup Destinations
Backup Data Encrypted in Transit and at Rest
Backup Administration Uses Separate Credentials
MFA Enabled for Backup Administration

Incident Response & Business Continuity

Assess readiness to contain, communicate, investigate, recover from, and report a security incident.
Written Cybersecurity Incident Response Plan
Authority to Disconnect Affected Systems Is Defined
Cyber Insurance, Legal, Forensics, and Law-Enforcement Contacts Documented
Internal, Customer, and Vendor Communication Plan Documented
Incident Response Plan Tested by Tabletop or Exercise
Evidence Preservation and Chain-of-Custody Procedure Defined
Regulatory and Contractual Reporting Requirements Known

Employees, Security Awareness & Policies

Review training, onboarding, offboarding, acceptable use, remote work, removable media, and reporting expectations.
Security Awareness Training Performed
Phishing Simulations Performed
New-Hire Security Orientation Completed
Employee Termination / Access Removal Checklist Used
Documented Security Policies
Employees Know How and Where to Report Suspicious Activity

Cloud Services, Domains & Third-Party Vendors

Identify external services and parties that store data or retain administrative access.
Major Cloud and Hosted Platforms
External File and Folder Sharing Reviewed and Restricted
Vendor Accounts and Access Reviewed Periodically
Vendor Agreements Include Security and Breach Notification Requirements
Domain Auto-Renewal, Registrar Lock, and Registrar MFA Enabled

Technician Observations

Summarize observed strengths, risks, limitations, and the client's overall management need.
Observed Physical and Operational Conditions
Selected Risk Rating: 0
0 = Not evaluated, 1 = Low, 2 = Low–Moderate, 3 = Moderate, 4 = High, 5 = Critical.
Selected Management Need: 0
0 = Not evaluated, 1 = Minimal, 2 = Limited, 3 = Moderate, 4 = Significant, 5 = Immediate managed-services need.

Findings & Corrective Action Recommendations

Create one record for each material finding. Evidence, impact, priority, and corrective action should be specific enough to support the client report.

Assessment Findings and Recommendations

Add each verified or materially reported finding. Avoid speculative statements and clearly distinguish verified evidence from client-reported information.

Final Assessment Summary & Attestation

Complete only after the scope, evidence, findings, and recommendations have been reviewed.
Required before submission. This questionnaire supports a cybersecurity environment review and recommendations; it is not, by itself, a penetration test, compliance certification, insurance attestation, or guarantee that the environment is secure.
Assessment records may contain confidential infrastructure information. Access should be limited to authorized personnel and retained according to Tek Guy On Demand’s assessment-record retention policy.