Independent IT & cybersecurity check
We find weak points before someone else does
The IT Check shows you where your business is exposed, how serious each finding is and what you should fix first. A specialist assesses your IT on site, point by point.
From 1,299 € excl. VAT. 8 areas, over 100 checks On site assessment Findings in two weeks, presented in person Book a call
IndependentConfidentialRead onlyNo obligation
Afterwards you know where you are exposed
Every gap, how critical it is, what to fix first.
IT Check · Findings
Documented findings
The current state of your IT, audited against over 100 checks in eight areas and presented in plain language.
Risk assessment
Every finding is classified: what is genuinely critical, what can wait, what is uncritical. You see immediately where it hurts.
Personal presentation
We walk you through the results in person, on site or remote. On request together with your existing IT partner.
Prioritised action plan
Concrete next steps, ordered by urgency and effort. You decide what to implement and with whom.
Attackable businesses in Austria can be found in under 30 seconds. There are dedicated search engines for it, filterable down to the town. Do not believe it? We will show you in the first call.
Cybercriminals are not looking for “you”.
In most cases nobody is looking for “Smith Ltd”. The search is for open systems, automated, thousands of times a minute. Like someone walking down a street trying every door handle. When a door opens, someone checks what is inside: patient records, client files, wages, access to the company account. Can you work without that data? If not, you are a target worth the effort.
Attacks have become a business, and it is growing. What counted as secure ten years ago is not enough today.
- 96 % of ransomware victims with a known company size are small and mid sized businesses. Verizon Data Breach Investigations Report 2026
- 80 % of 320 test systems deliberately left exposed online were compromised within 24 hours. Unit 42, Palo Alto Networks
- 62.328 reports of internet crime in Austria in 2024, more than six times the 2015 figure. Bundeskriminalamt, Cybercrime Report 2024
Do not be low hanging fruit.
Threat report as PDFThe IT Check is a thorough IT audit for businesses. It documents the state of your IT across eight areas: from network, server room and servers to workstations and user accounts, through to email, domain and the technical measures relevant to GDPR.
Can you answer these questions?
For every question you hesitate on, an outside view helps. That is what the IT Check delivers, on request as a second opinion alongside your IT partner.
We find out whether
- your systems are reachable from the internet without needing to be
- outdated or unpatched software is giving attackers a way in
- credentials from your business already appear in known data leaks
- two factor sign in is active where it counts
- your backups would survive a ransomware attack
- you could actually restore when it matters
- one infected computer is enough to reach your servers
- your email domain can be abused for forged senders
- a power cut costs you data because the server room has no protection
- your backup sits on the same network and gets encrypted along with everything else
What we check
Eight audit areas with over 100 concrete checks, all at one fixed price.
-
Network
Firewall, remote access (VPN), Wi-Fi and the separation of company and guest network.
-
Server room
Access, climate, fire and water protection and uninterruptible power supply (UPS).
-
Servers
Hardware, operating system, security updates, running services and their licenses.
-
Workstations
Security updates, virus protection, disk encryption, screen lock and USB media.
-
User accounts
Two-factor login, password rules, admin rights and orphaned accounts.
-
Email
Protection against spoofed senders (SPF, DKIM, DMARC), filtering and forwarding rules.
-
Domain
Secured management of domain and DNS, so nobody can reroute your email traffic.
-
GDPR
The relevant technical measures: encryption, access control, logging and deletion concept.
Eight areas, more than 100 checks, findings within two weeks. From 1,299 € excl. VAT.
Not there yet? Self check in five questions, without contact details.
Three questions the IT Check answers
The IT Check works along three questions that actually matter for your business. Behind them sit over 100 concrete checks across 8 audit areas, from firewall rules to the backup concept, all at one fixed price.
Can someone get in? Almost every attack starts from outside. We check the entry points attackers typically go for first.
- Firewall and remote access (VPN): configuration, rule set and version, so no outdated or open access becomes a way in
- Wi-Fi and internal network: encryption, clean separation of company and guest network and hardened switches, so a single compromised device cannot take the whole network with it
- Email: protection against spoofed senders in your name (SPF, DKIM, DMARC), spam and malware filtering, and risky forwarding rules that quietly carry data out of the house
- Domain and DNS: secured management, so nobody can take your domain away or reroute your email traffic
- Workstations: security updates, virus protection, disk encryption, screen lock and the handling of USB media, the most underrated way in day to day
- Your visibility on the internet: in a light penetration test we see your systems the way an attacker finds them from outside, and show what is openly reachable. For a full review across several attack paths there is the standalone penetration test
What if it happens anyway? No protection is perfect. What matters is whether your business survives an incident and is back up within hours.
- Backup concept: runs, offsite copy and a restore concept that holds up when it counts. A backup that does not restore is not a backup
- A backup copy that ransomware cannot delete or encrypt, your last line of defence against a ransom demand
- Servers: hardware condition and headroom, operating system, security updates and known vulnerabilities that attackers demonstrably exploit
- Programs and services running on the server and their licenses, so no forgotten service becomes a security risk or an expensive re-licensing bill
- Server room and power: access, environment (climate, fire and water protection) and uninterruptible power supply (UPS), so a power cut does not turn into data loss
- User accounts and permissions: analysis of your user directory (e.g. Active Directory), active, inactive and orphaned accounts of former staff, two-factor login, password rules, admin rights and the joiner, mover and leaver process
Are we actually compliant? The GDPR applies whether anyone inspects you or not. You have to prove it when something happens: to the data protection authority, your insurer and your customers.
- Which technical measures under GDPR Article 32 are actually in place: encryption, access control, logging
- Where personal data resides and whether a deletion concept exists
- Whether the measures are actually lived day to day
- Documentation of network, servers and access that you need for a breach notification under Article 33 within 72 hours
Add-ons
Bookable in addition to the standard check.
- Cloud check: Microsoft 365, Google Workspace and similar services
- Data leak check: whether company credentials have surfaced in known breaches
- Phishing simulation
- Network inventory
There is no such thing as complete security, and we do not promise it. The IT Check shows you where you stand today and where your biggest risks are.
Need a NIS2 supplier evaluation or a gap analysis against DORA, NIS2 or ISO 27001? We handle that separately in the compliance area. Go to compliance overview →
More details on the process and the areas we check are in the PDF.
IT Check print version (PDF)How the IT Check works
Kept lean, so your business keeps running.
-
Call and setup
A short call clarifies how your business works. We settle the confidentiality agreement and the access we need in the same step.
-
On site capture
A single appointment at your site. We only read and document, nothing on your systems is changed, and your business keeps running undisturbed.
-
Findings and review
We evaluate everything carefully, prioritise by risk and walk you through the documented findings in person. You receive them within two weeks.
All data and results stay strictly confidential. We sign a confidentiality agreement before we start, the findings are yours and are never disclosed to third parties.
Common questions
How long does an IT Check take?
What does an IT Check cost?
Is a penetration test included?
Do we have to commit to anything afterwards?
Who is the IT Check for?
Terms such as IT audit, penetration test or GDPR measures are explained briefly in the IT security knowledge base.
Ready?
Request the IT Check
Start with an IT Check. The first call quickly clarifies whether the IT Check makes sense for your business.