Independent IT & cybersecurity check

We find weak points before someone else does

The IT Check shows you where your business is exposed, how serious each finding is and what you should fix first. A specialist assesses your IT on site, point by point.

From 1,299 € excl. VAT. 8 areas, over 100 checks On site assessment Findings in two weeks, presented in person Book a call

IndependentConfidentialRead onlyNo obligation

Afterwards you know where you are exposed

Every gap, how critical it is, what to fix first.

IT Check · Findings

Documented findings

The current state of your IT, audited against over 100 checks in eight areas and presented in plain language.

Risk assessment

Every finding is classified: what is genuinely critical, what can wait, what is uncritical. You see immediately where it hurts.

Personal presentation

We walk you through the results in person, on site or remote. On request together with your existing IT partner.

Prioritised action plan

Concrete next steps, ordered by urgency and effort. You decide what to implement and with whom.

Attackable businesses in Austria can be found in under 30 seconds. There are dedicated search engines for it, filterable down to the town. Do not believe it? We will show you in the first call.

Cybercrime threat report 2026

Cybercriminals are not looking for “you”.

In most cases nobody is looking for “Smith Ltd”. The search is for open systems, automated, thousands of times a minute. Like someone walking down a street trying every door handle. When a door opens, someone checks what is inside: patient records, client files, wages, access to the company account. Can you work without that data? If not, you are a target worth the effort.

Attacks have become a business, and it is growing. What counted as secure ten years ago is not enough today.

  • 96 % of ransomware victims with a known company size are small and mid sized businesses. Verizon Data Breach Investigations Report 2026
  • 80 % of 320 test systems deliberately left exposed online were compromised within 24 hours. Unit 42, Palo Alto Networks
  • 62.328 reports of internet crime in Austria in 2024, more than six times the 2015 figure. Bundeskriminalamt, Cybercrime Report 2024

Do not be low hanging fruit.

Threat report as PDF

The IT Check is a thorough IT audit for businesses. It documents the state of your IT across eight areas: from network, server room and servers to workstations and user accounts, through to email, domain and the technical measures relevant to GDPR.

Can you answer these questions?

For every question you hesitate on, an outside view helps. That is what the IT Check delivers, on request as a second opinion alongside your IT partner.

We find out whether

  • your systems are reachable from the internet without needing to be
  • outdated or unpatched software is giving attackers a way in
  • credentials from your business already appear in known data leaks
  • two factor sign in is active where it counts
  • your backups would survive a ransomware attack
  • you could actually restore when it matters
  • one infected computer is enough to reach your servers
  • your email domain can be abused for forged senders
  • a power cut costs you data because the server room has no protection
  • your backup sits on the same network and gets encrypted along with everything else

What we check

Eight audit areas with over 100 concrete checks, all at one fixed price.

  1. Network

    Firewall, remote access (VPN), Wi-Fi and the separation of company and guest network.

  2. Server room

    Access, climate, fire and water protection and uninterruptible power supply (UPS).

  3. Servers

    Hardware, operating system, security updates, running services and their licenses.

  4. Workstations

    Security updates, virus protection, disk encryption, screen lock and USB media.

  5. User accounts

    Two-factor login, password rules, admin rights and orphaned accounts.

  6. Email

    Protection against spoofed senders (SPF, DKIM, DMARC), filtering and forwarding rules.

  7. Domain

    Secured management of domain and DNS, so nobody can reroute your email traffic.

  8. GDPR

    The relevant technical measures: encryption, access control, logging and deletion concept.

Eight areas, more than 100 checks, findings within two weeks. From 1,299 € excl. VAT.

Not there yet? Self check in five questions, without contact details.

Three questions the IT Check answers

The IT Check works along three questions that actually matter for your business. Behind them sit over 100 concrete checks across 8 audit areas, from firewall rules to the backup concept, all at one fixed price.

Can someone get in? Almost every attack starts from outside. We check the entry points attackers typically go for first.
  • Firewall and remote access (VPN): configuration, rule set and version, so no outdated or open access becomes a way in
  • Wi-Fi and internal network: encryption, clean separation of company and guest network and hardened switches, so a single compromised device cannot take the whole network with it
  • Email: protection against spoofed senders in your name (SPF, DKIM, DMARC), spam and malware filtering, and risky forwarding rules that quietly carry data out of the house
  • Domain and DNS: secured management, so nobody can take your domain away or reroute your email traffic
  • Workstations: security updates, virus protection, disk encryption, screen lock and the handling of USB media, the most underrated way in day to day
  • Your visibility on the internet: in a light penetration test we see your systems the way an attacker finds them from outside, and show what is openly reachable. For a full review across several attack paths there is the standalone penetration test
What if it happens anyway? No protection is perfect. What matters is whether your business survives an incident and is back up within hours.
  • Backup concept: runs, offsite copy and a restore concept that holds up when it counts. A backup that does not restore is not a backup
  • A backup copy that ransomware cannot delete or encrypt, your last line of defence against a ransom demand
  • Servers: hardware condition and headroom, operating system, security updates and known vulnerabilities that attackers demonstrably exploit
  • Programs and services running on the server and their licenses, so no forgotten service becomes a security risk or an expensive re-licensing bill
  • Server room and power: access, environment (climate, fire and water protection) and uninterruptible power supply (UPS), so a power cut does not turn into data loss
  • User accounts and permissions: analysis of your user directory (e.g. Active Directory), active, inactive and orphaned accounts of former staff, two-factor login, password rules, admin rights and the joiner, mover and leaver process
Are we actually compliant? The GDPR applies whether anyone inspects you or not. You have to prove it when something happens: to the data protection authority, your insurer and your customers.
  • Which technical measures under GDPR Article 32 are actually in place: encryption, access control, logging
  • Where personal data resides and whether a deletion concept exists
  • Whether the measures are actually lived day to day
  • Documentation of network, servers and access that you need for a breach notification under Article 33 within 72 hours

Add-ons

Bookable in addition to the standard check.

  • Cloud check: Microsoft 365, Google Workspace and similar services
  • Data leak check: whether company credentials have surfaced in known breaches
  • Phishing simulation
  • Network inventory

There is no such thing as complete security, and we do not promise it. The IT Check shows you where you stand today and where your biggest risks are.

More details on the process and the areas we check are in the PDF.

IT Check print version (PDF)

How the IT Check works

Kept lean, so your business keeps running.

  1. Call and setup

    A short call clarifies how your business works. We settle the confidentiality agreement and the access we need in the same step.

  2. On site capture

    A single appointment at your site. We only read and document, nothing on your systems is changed, and your business keeps running undisturbed.

  3. Findings and review

    We evaluate everything carefully, prioritise by risk and walk you through the documented findings in person. You receive them within two weeks.

All data and results stay strictly confidential. We sign a confidentiality agreement before we start, the findings are yours and are never disclosed to third parties.

Common questions

How long does an IT Check take?
Data capture on site is done in a single appointment. It is read-only and runs without interruption, so your business carries on as normal. You receive the documented findings within two weeks, presented in person.
What does an IT Check cost?
The IT Check starts at 1,299 € excl. VAT. The final price depends on the size and scope of your IT and is fixed after the first call.
Is a penetration test included?
The IT Check includes a light penetration test. It looks at what is reachable from outside through an attacker's eyes and is deliberately kept lean in scope. If you need a full review across several attack paths, that is commissioned as a separate penetration test.
Do we have to commit to anything afterwards?
No. The IT Check is a standalone step. The findings are yours. What you act on, and at what pace, is entirely your decision.
Who is the IT Check for?
For mid sized businesses that want to know where their IT security stands. It is especially useful for companies that work with sensitive data or have lost the overview over time.

Ready?

Request the IT Check

Start with an IT Check. The first call quickly clarifies whether the IT Check makes sense for your business.

Price from 1 299 € excl. VAT
Book a first call

How secure is your IT really?

The IT Check reviews your IT across 8 areas with more than 100 checks. Findings within two weeks, from 1,299 € excl. VAT.