An IT assessment isn't a sales pitch with extra steps. Done properly, it's the first honest look most businesses get at what's actually running underneath their day-to-day operations.
The word “assessment” covers a lot of ground in IT. One provider uses it for a 20-minute checklist call. Another means a multi-week audit with network scans and staff interviews. Most businesses booking one for the first time can’t tell which kind they’re getting until the report shows up.
This guide walks through what a thorough IT assessment involves, from the first conversation to the written report, so you know what to expect and what to question. It’s written for owners, controllers, and operations leads at small and mid-sized Ontario businesses, especially those comparing managed IT services or reviewing a provider before a contract renewal. Where we describe how ACT360 runs its own assessment, we say so. Where an outside framework applies, we link to it.
TL;DR. A useful IT assessment has 3 parts, a discovery conversation about how the business works, a hands-on review of your network, Microsoft 365 security, backups, licensing, and documentation, and a written report that ranks what matters. At ACT360 it’s free, usually takes a few days to about a week, and carries no obligation. If a report arrives bundled with a contract and a deadline, treat it as a sales document, not an assessment.
What Happens Before an IT Assessment Starts?
Before any technical work, a good assessment starts with a discovery conversation. Expect questions about how your team works, which applications you can’t run without, where the business is headed over the next 2 to 5 years, and what’s frustrating about your current setup. System access is arranged only after that conversation.
That order matters more than it looks. A server that’s perfectly adequate today can still be the wrong purchase if the business plans to move its accounting software to the cloud next year, and nobody learns that from a device scan. The business questions are what keep the technical findings tied to how you actually operate, instead of turning into a generic checklist.
You don’t need to prepare anything for the first call. It does speed things up later if you can find a few items, such as a list of the software your team uses every day, your latest Microsoft 365 and IT invoices, any contract with your current provider, and the name of whoever holds the admin passwords. If nobody’s sure who holds them, that’s already a finding.
How Long Does an IT Assessment Take?
In ACT360’s experience, most assessments take a few days to about a week from the first conversation to the written report. The biggest variables are the number of locations, whether servers sit on-site, and how quickly admin access can be arranged.
We haven’t found a published industry benchmark for assessment length, so treat any timeline, ours included, as a scoping estimate rather than a standard. A single-office business running mostly on Microsoft 365 moves faster than a multi-site operation with an on-premise server and a line-of-business application nobody ever documented. Adam Bowles, Partner and CEO at ACT360, puts the reason for not rushing it plainly.
“I don’t want to give you a quote based on a headcount and a device list. Give me a week to actually look.”
Adam Bowles, Partner & CEO, ACT360
One caveat worth knowing. A penetration test or a formal compliance audit is a different, deeper exercise, and it takes longer. If an insurer or a client has asked for one of those specifically, say so up front so the scope matches the request.
What Does an IT Assessment Actually Evaluate?
A thorough IT assessment looks at 6 areas, which are your network and hardware, identity and access, endpoint security and patching, backup and recovery, software and licensing, and documentation. Recognized security frameworks cover much of the same ground, which is a good sign the scope isn’t arbitrary.
- Network and hardware, meaning firewalls, switches, Wi-Fi, servers, and workstations, including their age and whether they still receive security updates. Windows 10 is the most common example right now. Microsoft ended Windows 10 support on October 14, 2025, so any machine not enrolled in Extended Security Updates no longer gets security fixes.
- Identity and access in Microsoft 365 and Entra ID, such as whether multi-factor authentication covers every account, how many people hold global admin rights, whether legacy sign-in protocols are still allowed, and whether former employees can still log in.
- Endpoint protection and patching, for example whether Microsoft Defender or another endpoint detection and response tool is running on every device, and whether updates are actually installing rather than failing quietly.
- Backup and recovery, covering what gets backed up, where the copies live, how long they’re kept, and when someone last proved a restore works.
- Software and licensing, comparing the Microsoft 365 plans and other subscriptions you pay for with what people actually use.
- Documentation, which comes down to whether anyone other than one person knows the passwords, the network layout, and the vendor contacts.
None of this is proprietary. The CIS Critical Security Controls v8.1 open with inventories of hardware and software for a reason, since you can’t protect what you haven’t listed. The Canadian Centre for Cyber Security’s baseline controls for small and medium organizations include automatic patching, strong user authentication, and backups among 13 baseline controls, and they advise organizations to keep clear restore procedures and verify them regularly. NIST’s Cybersecurity Framework 2.0 treats this kind of inventory and risk review as the Identify function, the work that comes before deciding how to protect anything. What varies between providers is how deep they actually go.
Identity is where we’d point most small businesses first. Microsoft states that more than 99.9% of common identity-related attacks are stopped by using multifactor authentication and blocking legacy authentication, which makes MFA coverage one of the cheapest, highest-impact items an assessment can check. For Microsoft 365 environments, Microsoft Secure Score is a useful reference number too, though Microsoft is clear that a high score isn’t a guarantee against a breach. If security is your main concern, our guide to what a cybersecurity assessment actually covers goes deeper on that side alone.
Which Problems Does an IT Assessment Usually Find?
Most assessments turn up the same handful of problems, and nearly all of them are invisible day to day. The table below maps each area to what gets checked, the problems our team runs into most often in small business environments, and why each one matters to the business.
| IT Assessment Area | What Gets Checked | Common Problems | Why It Matters |
|---|---|---|---|
| Network and hardware | Firewall firmware, switch and Wi-Fi age, server health, workstation operating systems | Windows 10 machines past end of support, consumer-grade routers, failing server drives | Unsupported hardware stops getting security fixes, and hardware failures cause unplanned downtime |
| Identity and access | MFA coverage, admin roles, Conditional Access or security defaults, stale accounts | MFA on some users but not all, shared admin logins, former staff accounts still active | One stolen password can open email, files, and payment approvals |
| Endpoint security and patching | Endpoint detection and response coverage, patch status, local admin rights | Protection on most devices but not every one, updates failing silently | A single unprotected laptop is enough of a foothold for ransomware |
| Backup and recovery | What’s backed up, retention, off-site copies, last successful restore test | Backups that have never been restored, Microsoft 365 data not included in any backup | A backup nobody has restored is an assumption, not a recovery plan |
| Software and licensing | Microsoft 365 plans against actual use, overlapping tools, renewal dates | Paying for seats nobody logs into, 2 tools doing the same job | Licensing cleanup is often one of the quickest cost savings available |
| Documentation | Password vault, network diagram, vendor contacts, admin credentials | Everything lives in one person’s head or inbox | If that person is away or leaves, every fix and recovery takes longer |
The Common Problems column reflects what ACT360’s team regularly sees in the field. It isn’t a statistical survey.
Backup is the row that surprises owners most. In our experience, plenty of businesses have a backup job that runs every night and has never been restored, so nobody knows whether recovery would take an hour or a week. When that’s the gap, business continuity and disaster recovery planning is what turns a backup into a recovery plan with a known timeline.
What Should an IT Assessment Report Include?
A good report tells you what’s working, what’s a real risk, what can wait, and roughly what each fix would cost. It’s written so an owner or controller can follow it without an IT background, and it ranks findings by business impact rather than technical severity alone.
A useful technology assessment report usually includes these 5 things.
- A 1-page summary written for leadership, not for technicians.
- Findings grouped by priority, each with a plain explanation of what it means for the business.
- A rough effort or cost range for each item, so you can plan a budget instead of reacting to one.
- A list of what’s fine as-is, because knowing what doesn’t need money is as useful as knowing what does.
- What isn’t being recommended yet, and why.
That last item is the one most reports leave out. At ACT360 it’s part of every proposal, because “here’s what we’d hold off on” is often the clearest sign a recommendation was built around your business rather than a sales target.
| Finding | What it means for the business | Priority | Rough effort |
|---|---|---|---|
| MFA not enforced on 6 of 22 Microsoft 365 accounts | One stolen password could open email, files, and banking approvals | HIGH | Hours |
| Backups run nightly but have never been restore-tested | Nobody knows how long recovery would take, or whether it works | HIGH | 1 day |
| 4 workstations still on Windows 10 | No security fixes since October 2025 without Extended Security Updates | MEDIUM | Replace or upgrade |
| 5 unused Microsoft 365 licences | Money spent every month on seats nobody logs into | MEDIUM | Minutes |
| No current network diagram or password vault | Recovery slows down if the one person who knows is away | LOW | 2 to 3 days |
| Firewall firmware current and supported | No action needed right now | FINE AS-IS | None |
How Can You Tell a Thorough Assessment From a Shallow One?
A thorough assessment means someone actually reviews your systems, asks when a backup was last restored, and hands you a written report you keep. A shallow one is built from a headcount and a device list, and it usually ends with a quote.
Here’s the part people don’t expect. Free doesn’t mean shallow, and paid doesn’t mean thorough. Some providers charge for an assessment and still deliver a template. Others, ACT360 included, offer it free because it’s how we earn the right to make a recommendation. Judge it by what gets examined and what you walk away with, not by the price.
- ✕Built from a headcount and a device list
- ✕Run by a sales rep reading a checklist
- ✕No one actually logs into your systems
- ✕Backups marked yes because they exist
- ✕Ends with a quote and a deadline to sign
- ✓Starts with how your business actually runs
- ✓Done by the senior people who would do the work
- ✓Hands-on review of Microsoft 365, devices, and network
- ✓Asks when a restore was last proven to work
- ✓Ends with a written report you keep, even if nothing needs to change
Pressure is the other tell. If the findings arrive already packaged with an urgent recommendation to sign a specific agreement this week, treat the document with some skepticism. A genuine assessment stands on its own, whether or not you ever work with the people who did it.
What Did One Assessment Actually Uncover?
A 35-person commercial painting contractor came to ACT360 about a failing server and a $60,000 replacement quote from its existing provider. Asking what the business was planning next cut that number to $25,000, and later monitoring surfaced a security problem nobody knew about.
The symptoms were familiar. Sage, the company’s accounting and job-costing system, could take up to 30 minutes to open, the file share crawled, and the server’s drives were failing. The previous provider had reached the right technical conclusion, that the hardware was finished, and then sent a quote by email without a conversation.
The discovery conversation changed the answer. The company plans to replace its ERP, which will move Sage off-premise within a couple of years. Buying a full-specification server built for 5 to 7 years of use made little sense in that context. ACT360 delivered a server sized to bridge the migration for $25,000, including hardware, installation, setup, and migration.
The second finding came after onboarding, not during the assessment itself, and it’s worth being precise about that. Within weeks of the new security monitoring going live, identity monitoring flagged account access from Latvia, the Philippines, and the United States, plus 1 incident serious enough to isolate an account automatically. None of it had been visible before. The company had come to talk about a server.
The client asked to stay anonymous, so identifying details are generalized. The full painting contractor server right-sizing case study has the numbers and the timeline.
How Does ACT360 Run Its IT Readiness Assessment?
ACT360’s IT Readiness Assessment is free, carries no obligation, and follows the Assess and Comprehend steps of our ACTION methodology. It starts with a conversation about your business, then moves to a technical review of network, security, backups, and licensing, done by the senior team that would do the work.
Jeffrey Bowles, Partner and Director of IT Services, runs the technical side, including the environment review, security posture, and backup verification. The report that follows is written for a business owner, with findings ranked by risk and cost. If the honest answer is that your current setup is mostly fine, that’s what you’ll hear.
What happens next depends on what the report shows. A security gap usually leads to a conversation about cybersecurity services. If you already have an internal IT person who just needs backup, co-managed IT keeps them in charge while we cover the gaps. And sometimes the right next step is nothing at all for another year.
Questions Businesses Ask About IT Assessments
Realistically, how long will an IT assessment take?
A few days to about a week, in ACT360’s experience, from the first conversation to the written report. Multiple locations, on-site servers, and slow access to admin accounts all stretch that timeline.
Should an IT assessment cost anything?
ACT360’s IT Readiness Assessment is free, with no obligation to buy anything afterward. Across the industry it varies. Some providers offer a free assessment as the start of a relationship, while specialized work like penetration testing or a formal compliance audit is normally a paid engagement. Price matters less than scope, so ask what will actually be examined and whether you’ll get a written report you can keep.
Do you need admin access to our systems?
Not for the first conversation. Access to systems, if it’s needed, is arranged after that call, and a reputable provider should tell you exactly what they need and why before you hand anything over.
Will this disrupt my team’s workday?
Very little, when it’s run properly. Most of the technical review happens in the background through admin tools, and staff time is usually limited to a few short questions about how they work.
What if the assessment finds nothing worth changing?
Then you’ve learned something useful, and a good provider will say so plainly. Sometimes the right outcome is confirming your setup is sound and knowing which 1 or 2 things to watch before your next renewal. That’s a better result than being sold changes you don’t need.
Am I locked into working with whoever does the assessment?
No obligation should come attached. Some businesses book an assessment specifically to find out whether switching providers is even worth it, and the report is yours to act on alone, with your current provider, or with someone else. If you’d like to see what ACT360’s version includes, the IT Readiness Assessment page walks through it.
Final Thought
An IT assessment is only as useful as what it actually looks at and how clearly the results come back to you. A thorough one gives you a real starting point for decisions about spending, security, and your provider. A shallow one mostly serves whoever is selling something at the end of it.
If you’d rather know than guess, ACT360’s IT Readiness Assessment is a free, no-obligation review of your network, security, backups, and licensing, with a written report you keep either way.
Call 705-739-2281 or email [email protected]