01
Assess the highest-impact attack paths
Most small-business incidents start with a stolen password, a phishing email or an unpatched laptop. The first engagement finds which of those paths are open in your company and what each one would cost to close.
- Administrator, user and service-account access review
- Multi-factor authentication, conditional access and account-recovery workflows
- Email authentication, phishing exposure and mailbox controls
- Endpoint inventory, patching, encryption and security-tool coverage
- Backup separation, restore evidence and ransomware recovery dependencies
