Enterprise technology health check
Business priorities, applications, infrastructure, security, operations, suppliers, cost and risk
Technology strategy and governanceFilter by domain or search by keyword to find the assessment that fits your challenge. Not sure? Tell us your scope and we'll recommend.
88 assessments
Business priorities, applications, infrastructure, security, operations, suppliers, cost and risk
Technology strategy and governanceBusiness alignment, investment themes, sequencing and dependencies
Technology strategy and governanceInvestment, architecture, governance, programme and board decisions
Technology strategy and governanceRoles, accountability, sourcing, service ownership and escalation
Technology strategy and governanceCommittees, policies, approvals, exceptions and reporting
Technology strategy and governanceBusiness value, technical health, cost, duplication and retirement
Technology strategy and governanceJourneys, manual work, handoffs and feasibility
Technology strategy and governanceBenefits, total cost, operating impact, risks and options
Technology strategy and governanceBusiness, application, data, integration, infrastructure and security architecture
Technology strategy and governanceSystems, contracts, identities, networks, data and separation dependencies
Technology strategy and governanceMonitoring, events, incidents, changes, staffing and reporting
IT operations and service managementIncident, request, problem, change, knowledge, asset and configuration workflows
IT operations and service managementChannels, volumes, resolution, self-service, staffing and automation
IT operations and service managementService owners, dependencies, hours, service levels and escalation
IT operations and service managementLogs, metrics, traces, synthetic checks, alerts and service mapping
IT operations and service managementRecurring incidents, event volumes, data quality and safe automation
IT operations and service managementConfiguration sources, relationships, quality, ownership and change integration
IT operations and service managementCompute, storage, network and database demand
IT operations and service managementScope, staffing, transition, governance, SLA and pricing units
IT operations and service managementContracts, service reports, incidents, penalties and concentration risk
IT operations and service managementWorkloads, dependencies, data, licensing, connectivity and skills
Cloud, infrastructure and modernizationIdentity, network, policy, logging, backup, keys and resilience
Cloud, infrastructure and modernizationWave plans, test, cutover, rollback, cost and handover
Cloud, infrastructure and modernizationIdentity, network, monitoring, security and support ownership across environments
Cloud, infrastructure and modernizationAllocation, idle capacity, sizing, commitments and forecasting
Cloud, infrastructure and modernizationPlatform lifecycle, virtualization, storage, network and facilities
Cloud, infrastructure and modernizationTopology, segmentation, exposure, WAN, redundancy and visibility
Cloud, infrastructure and modernizationBusiness value, technical debt, scalability and dependencies
Cloud, infrastructure and modernizationInterfaces, authentication, contracts, errors and observability
Cloud, infrastructure and modernizationCI/CD, infrastructure as code, releases and production support
Cloud, infrastructure and modernizationGovernance, assets, identity, protection, detection, response and suppliers
Cyber governance and riskCritical services, threats, vulnerabilities, controls and business impact
Cyber governance and riskTranslate business risk into policy, people, process and technology priorities
Cyber governance and riskRisk reviews, policy, board reporting and supplier assurance
Cyber governance and riskISMS scope, risk method, controls, evidence and internal audit
Cyber governance and riskEntity classification, national implementation, governance and incident duties
Cyber governance and riskICT risk, incidents, resilience testing and third parties
Cyber governance and riskSupplier tiering, due diligence, contracts, access and exit
Cyber governance and riskPolicies, standards, exceptions, control owners and testing
Cyber governance and riskRisk-related metrics, data sources and thresholds
Cyber governance and riskUnderwriting evidence for MFA, backup, incident response and suppliers
Cyber governance and riskLifecycle, MFA, privilege, service accounts and access review
Cyber architecture and technical assuranceIdentity, devices, apps, paths, data access and policies
Cyber architecture and technical assuranceFirewall rules, exposure, remote access and administration
Cyber architecture and technical assuranceConfigurations, permissions, logs, encryption and key management
Cyber architecture and technical assuranceHardening, EDR, patching, privilege and unsupported assets
Cyber architecture and technical assuranceCoverage, prioritization, remediation, exceptions and verification
Cyber architecture and technical assuranceRequirements, threat models, dependencies, secrets and release gates
Cyber architecture and technical assuranceScoped authentication, authorization, inputs, logic and data exposure
Cyber architecture and technical assuranceAuthorized scoped attack paths and defensive response
Cyber architecture and technical assuranceDomain authentication, phishing, sharing, retention and incident flows
Cyber architecture and technical assuranceSensitive data, access, encryption, retention, DLP and deletion
Cyber architecture and technical assuranceKeys, certificates, secrets, rotation and recovery
Cyber architecture and technical assuranceCoverage, staffing, triage, escalation, tooling and intelligence
SOC, detection and responseLog sources, ingestion, parsing, cost, detection and automation
SOC, detection and responseThreat scenarios, telemetry, rules, false positives and testing
SOC, detection and responseRoles, communications, containment, evidence and playbooks
SOC, detection and responseExecutive and technical response to realistic scenarios
SOC, detection and responseTelemetry, hypotheses, intelligence and analyst processes
SOC, detection and responseEntry paths, lateral movement, backup compromise and recovery
SOC, detection and responseCritical services, tolerable disruption, dependencies and recovery needs
Continuity, DR and resilienceGovernance, plans, alternate working, communications and exercises
Continuity, DR and resilienceDependencies, replication, backup, recovery sites and runbooks
Continuity, DR and resilienceCoverage, immutability, retention, separation and actual restores
Continuity, DR and resilienceRTO/RPO, consistency, connectivity, cost and complexity
Continuity, DR and resilienceTabletop, component, app or full-service recovery tests
Continuity, DR and resilienceEnd-to-end applications, people, facilities and suppliers
Continuity, DR and resilienceSites, processes, systems, connectivity, ownership and safeguards
OT and industrial cybersecurityPLC, HMI, SCADA, historians, workstations and process criticality
OT and industrial cybersecurityControl networks, IT/OT links, cloud, remote sites and vendors
OT and industrial cybersecuritySecurity grouping, communications and inter-zone controls
OT and industrial cybersecurityCyber scenarios affecting safety, production, environment and quality
OT and industrial cybersecurityAsset owner, integrator or product supplier obligations
OT and industrial cybersecurityFirewalls, DMZ, jump hosts, historians, transfers and identity
OT and industrial cybersecurityApproval, identity, sessions, vendor devices and emergency access
OT and industrial cybersecurityAdvisories, vendor support, maintenance, test and compensating controls
OT and industrial cybersecurityPLC logic, configurations, HMI/SCADA, historians and spares
OT and industrial cybersecuritySafe telemetry, process-aware alerts, escalation and containment
OT and industrial cybersecurityProcurement, engineering, FAT, SAT and handover
OT and industrial cybersecurityVendor security, maintenance, lifecycle and contractual duties
OT and industrial cybersecurityApproved passive, lab or carefully controlled site tests
OT and industrial cybersecurityManufacturing, utilities, energy, transport, healthcare or buildings
OT and industrial cybersecurityOwnership, quality, lineage, access, retention and issues
Data, AI and emerging technologyIngestion, integration, storage, analytics, cost and reliability
Data, AI and emerging technologyProblems, data, integration, economics and oversight
Data, AI and emerging technologyAI inventory, data, models, evaluation, oversight and monitoring
Data, AI and emerging technologyData exposure, prompt injection, permissions, RAG and validation
Data, AI and emerging technologyIdentity, provisioning, firmware, cloud integration and lifecycle
Data, AI and emerging technologyBook an independent, standards-based assessment. We'll scope the right engagement for your environment.