Resource
IT & Security Health Assessment Overview
What we review, who it is for, what happens after you submit a request, and the limits of an initial assessment.
Last Updated: September 20, 2026
What It Is
An initial Retrisa IT & Security Health Assessment is intended to help identify potential technology, administration, security, backup, access and operational gaps — and to describe them in language a business owner can act on.
What We Review
Depending on your environment and what has been authorized, a review may cover:
- Users, accounts and group membership;
- Multi-factor authentication coverage and access policies;
- Privileged and administrative accounts;
- Devices: inventory, encryption, patch state and management coverage;
- Email configuration, including mail authentication records and phishing defenses;
- File sharing, permissions and external sharing settings;
- Backup configuration, success history and whether restores have been tested;
- Endpoint protection coverage;
- Remote access and network exposure; and
- Licensing already paid for but not in use.
Who It Is For
Organizations that have outgrown ad-hoc IT and want an honest picture of where they stand: businesses changing providers, businesses that have never had a structured review, businesses facing an insurance or customer security questionnaire, and leadership teams who simply want to know whether the technology they depend on is in good shape.
What Happens After You Submit a Request
- We review what you sent and follow up using the contact details you provided.
- We have a short conversation to understand your environment and what matters to you.
- We agree the scope in writing, including exactly what we will look at and how.
- You grant the access required for that agreed scope — nothing more.
- We carry out the review and document what we find.
- We walk you through the findings and a prioritized list of what we would do first.
Submitting a request does not create a customer relationship and does not obligate you to purchase anything.
What an Initial Assessment Is Not
Unless specifically agreed otherwise in writing, an initial assessment is not:
- A penetration test;
- A formal vulnerability assessment;
- A compliance audit;
- A legal or regulatory certification;
- A forensic investigation; or
- A guarantee that an environment is secure.
Recommendations are based on the information and authorized access available at the time of the assessment.