Free Resource · checklist

IT and Network Assessment Checklist

An IT assessment is a structured review of everything your business runs, hardware, network, security, backups, cloud accounts, and documentation, that turns "we think we're fine" into a prioritized list of what's solid and what's exposed. The checklist below is the same ground a professional network assessment covers: inventory first, then network health, then security controls, then backup verification, then the people and paperwork layer. Work through it honestly and the gaps rank themselves.

Most businesses have never actually inventoried what they run, and the first assessment almost always surprises the owner: forgotten admin accounts, a server out of warranty, backups that quietly stopped months ago. This checklist walks the same territory a professional IT and network assessment covers, so you can either work it yourself or know exactly what a good provider should be checking.

The checklist

Print it, or paste it into a doc and work through it as a team. An item you can’t answer is a finding in itself.

1. Inventory and hardware

  • Every workstation, laptop, server, and mobile device is listed, with owner, age, and operating system
  • No machines running an unsupported OS (Windows 10 reached end of support in October 2025)
  • Servers and network gear are under warranty or have a documented replacement plan
  • You know which machines are older than 5 years and what replacing them costs
  • Software licenses are inventoried and match what’s installed

2. Network

  • The firewall is a business class device, under support, with firmware current
  • No remote access ports (RDP, VNC) open to the internet
  • Wi-Fi is segmented: guest traffic can’t reach business systems
  • Switch and wiring closet gear is labeled and documented
  • Internet bandwidth matches actual usage, and there’s a failover plan if the primary line drops
  • Remote workers connect through a VPN or secured cloud access, not exposed services

3. Accounts and identity

  • Multi factor authentication is enforced on every email account, not just some
  • MFA also covers VPN, remote access, and admin logins
  • Former employees’ accounts are disabled, verified against a current staff list
  • Admin rights are limited to people who need them, and nobody works daily from an admin account
  • No shared logins for business systems
  • Company credentials have been checked against known breach dumps

4. Security controls

  • Every device runs endpoint protection (EDR, not just legacy antivirus) and someone reviews its alerts
  • Operating systems and applications are patched on a schedule, with stragglers chased down
  • Email filtering and spoofing protection (SPF, DKIM, DMARC) are configured
  • A payment change or wire request requires verbal verification before money moves
  • Staff receive recurring security awareness training, not a single onboarding video
  • Laptops and portable drives are encrypted

5. Backups and recovery

  • You know exactly what is backed up, and what isn’t
  • At least one backup copy is off site and immutable, so ransomware can’t encrypt or delete it
  • Microsoft 365 (email, OneDrive, SharePoint) has its own third party backup
  • Someone has actually restored from backup in the last quarter, and timed it
  • A written recovery plan exists: what comes back first, how fast, and who does it

6. Documentation and vendors

  • Network diagrams, passwords, and vendor contacts are documented somewhere that survives a disaster
  • You know who to call, and in what order, when something breaks
  • Cyber insurance is in place, and the application’s answers are actually true
  • Compliance obligations (HIPAA, FTC Safeguards, client security requirements) are identified and mapped to controls

How do you score it?

Don’t average it. Rank the misses by what they’d cost you. An unchecked box in accounts, security, or backups is urgent, because those are the three areas that turn a bad day into a closed business: a phished password with no MFA behind it, a machine with no endpoint protection, or a backup that doesn’t restore. Inventory and documentation gaps matter, but they hurt you slowly; the security and recovery gaps hurt you all at once.

If more than a handful of boxes are unchecked, or unanswerable, that’s normal. Most 10 to 100 person businesses we assess start there. The point of the checklist is that the fixes now have an order.

Where a professional assessment goes further

Self assessment finds the visible gaps. A professional network assessment adds the parts that need tooling: scanning every device instead of trusting the list, verifying MFA coverage account by account, checking whether your credentials already circulate in breach dumps, testing whether backups genuinely restore, and reviewing firewall rules line by line. It also produces the documentation, which is increasingly what clients and cyber insurers want to see.

Braintek offers this as a free risk assessment for Houston and Dallas-Fort Worth businesses, performed with an independent third party so the findings are objective rather than a provider grading its own work. You get a prioritized, plain English report, what’s exposed, what it would cost you, and what to fix first. From there, fixes can go to your internal team, your current provider, or Braintek’s managed IT services, which typically run $150 to $250 per device per month with the security and backup layers above included and maintained.

Want this done for you, free?

Braintek runs a free, independent risk assessment for Houston and Dallas-Fort Worth businesses. You get a prioritized, plain English report of where you actually stand, no jargon and no scare tactics. Tell us a little about your environment and we'll take it from there.

By submitting, you agree to be contacted by Braintek about your inquiry.

FAQs

What is an IT assessment?

An IT assessment is a structured review of a business's technology: every device and account inventoried, the network tested for reliability and exposure, security controls verified rather than assumed, backups actually restore tested, and the findings ranked by risk. The output is a prioritized action list, not a grade.

What's the difference between an IT assessment and a network assessment?

A network assessment focuses on the connectivity layer, firewall, switches, Wi-Fi, internet, and remote access, while an IT assessment covers the whole environment including workstations, servers, cloud accounts, security, backups, and documentation. In practice a good provider does both in one pass, because a locked down network with unpatched machines behind it is still exposed.

How long does an IT assessment take?

For a business of 10 to 100 employees, a professional assessment typically takes a few days from kickoff to written report, with only an hour or two of your team's time. Working through this checklist yourself takes an afternoon and will surface the obvious gaps, though some items, like verifying backups restore or checking for leaked credentials, need tooling to answer properly.

How much does an IT assessment cost?

Braintek's risk assessment is free for Houston and Dallas-Fort Worth businesses, and it's performed with an independent third party so the findings are objective rather than a sales document. Paid assessments elsewhere commonly run from a few hundred to several thousand dollars depending on scope.

How often should we run an IT risk assessment?

Annually at minimum, plus after any major change, an office move, a merger, new line of business software, or a change in IT providers. Cyber insurance renewals are a natural forcing function, since the questionnaire asks for exactly the evidence an assessment produces.

What happens after the assessment?

The findings get ranked by likelihood and impact, and you fix in that order. Most lists start with the same few items, MFA gaps, unsupported machines, and backups nobody has ever restored, and most of those fixes cost far less than the incident they prevent.

Ready for IT that just works?

Book a no-pressure discovery call. We'll review your setup and show you exactly where you stand.