Find Out Where You Actually Stand
A written, scored assessment of your real security posture — external footprint, email authentication, identity, backups, and process — with every gap ranked by what to fix first.
45 min · Free · No commitment
Nobody needs another security opinion. You need a baseline.
Ask three IT providers whether your security is adequate and you will get three different answers, each shaped by what that provider happens to sell. None of them will hand you a number you can track over time, and none will tell you which of the twelve items they listed actually matters most this quarter.
Meanwhile the questions keep arriving — from your cyber insurance renewal, from a client's vendor security questionnaire, from a board member who read something alarming over the weekend. Answering any of them honestly requires knowing your current state, and most businesses genuinely do not.
Facet MSP produces a written baseline: what we can observe from outside, what your answers reveal about internal process, a score, and an ordered list of what to address. Some of it you can fix yourself in an afternoon, and we will tell you which parts those are.
What the assessment actually examines
External Footprint Scan
We look at what an attacker sees before touching anything — your public DNS, mail routing, and where your domain is hosted. This runs automatically the moment you submit your domain, and requires no access to your systems whatsoever.
Email Authentication Check
We resolve your SPF, DKIM, and DMARC records and report what is actually published against what should be. Misconfigured or entirely absent email authentication is the single most common finding we see, and also among the cheapest to fix.
Identity & Access Review
How many people hold administrative rights, whether MFA is genuinely enforced rather than merely available, what happens to accounts when someone leaves, and whether anyone is still sharing a login between two people.
Backup Reality Check
Not whether backups exist, but whether a restore has ever been tested, how far back recovery actually reaches, and whether the backups are reachable by an attacker who compromises your network. Untested backups are the most common false comfort in this industry.
Endpoint & Patch Posture
What protection is deployed, how consistently it is deployed, and how far behind the fleet has drifted on updates. Consistency matters considerably more here than any individual product choice.
Process & Human Factors
Payment approval, onboarding and offboarding, who can authorize a change, and what training staff have genuinely received. Most successful attacks exploit process rather than software, and process rarely appears on a technical scan.
A Scored, Prioritized Report
Findings ranked by risk and by effort, rather than dumped as an undifferentiated list. You get a defensible baseline you can re-run in six months to demonstrate movement to a board or an insurer.
You leave with something concrete
- A written baseline you can hand to an insurer or a client
- Findings ranked by what to fix first, not alphabetically
- A clear line between what needs us and what does not
- Honest answers for vendor security questionnaires
- A score you can re-run later to show progress
- No obligation to buy anything at the end of it
An assessment that can return bad news
The scan is real, not a lead form.
We resolve your actual DNS, mail, and authentication records and report what we find. You get the findings whether or not you ever speak to us again.
We tell you what you can fix without us.
Some findings are a twenty-minute change in your own admin console. Pretending otherwise would make the report a sales document rather than an assessment.
A score, not an adjective.
"Your security is weak" is unactionable. A number with ranked findings underneath it is something you can budget against and measure again next year.
Assessment questions
Is this really free, or is it a sales call in disguise?
The assessment and the written report are free. There is a 45-minute call to walk you through the findings, and if you ask, we will explain what engaging us would involve. If you take the report and fix everything yourself, that is a legitimate outcome and it does happen.
Do you need access to our systems?
Not for the external portion, which runs against public DNS and mail records the moment you submit your domain. The internal picture comes from your answers to the questionnaire. A deeper technical review with system access is a separate, paid engagement.
How long does it take?
The questions take about ninety seconds. The written assessment comes back within a few business days, because a person reviews the automated findings and writes the prioritization rather than a template generating it instantly.
What if the report says we are in bad shape?
Then you have something genuinely useful. Most assessments surface two or three things that really matter and a longer tail that does not. The entire point of ranking findings is so you can act on the first group without being paralyzed by the second.
Will this satisfy a client security questionnaire?
It gives you accurate answers to most of what those forms ask, plus a document showing you assessed yourself deliberately. It is not a SOC 2 report or a formal audit — if you need one of those, we will say so and help you scope it properly.
Ready to take this off your plate? Six questions.
Spend 90 seconds answering. We'll spend a few hours putting together a written assessment of where your IT stands — and a 45-minute call with one of our engineers.