Network Assessment Process

Last updated

Where the assessment fits

A network assessment does double duty. Pre-contract, it is your best sales tool: a low-commitment free or paid audit is one of the most effective offers for landing your first clients, because it replaces a sales pitch with evidence. Post-signature, the same assessment is the input to client onboarding – the discovery phase of a 30/60/90 onboarding is essentially this process run at full depth.

Run it at three cadences: pre-sales (time-boxed, top findings only), at onboarding (full depth, first 30 days), and then periodically as a standards review feeding the QBR. In a small shop the founder or senior tech runs the whole thing; once you have staff, a tech runs discovery and the owner presents findings.

Step 1: scope and written authorization

Never scan a network you don't have written permission to scan. Unauthorized scanning is legally risky and looks amateur if discovered. Before any tool touches the environment:

  1. Define scope in writing: which sites, subnets, tenants, and systems are in scope; whether you'll deploy temporary agents; what you will not touch (production databases, OT equipment, anything the owner flags).
  2. Get a signed authorization – a one-page letter for a pre-sales assessment, or scope language inside the agreement for onboarding. For prospects, include basic confidentiality language both ways.
  3. Get named admin credentials or an escorted session for Active Directory and the Microsoft 365 tenant. How hard it is to obtain access is itself a finding.
  4. Agree the timeline and the deliverable: a findings report and a roadmap conversation, on a named date.

Step 2: discovery and inventory

Work through the environment systematically. The checklist:

  • Directory and identity: AD and/or Entra review – stale accounts, admin group membership, service accounts, password policy, MFA coverage on admin and user accounts.
  • M365 tenant: license SKUs and waste, mail-flow and email security configuration, external sharing settings, admin roles.
  • Network scan: discover every device with an IP – switches, firewalls, printers, wireless, IoT surprises. Note firmware age, default credentials, and flat-network topology.
  • Endpoints and servers: OS versions and support status, patch levels, local admin rights, disk encryption, AV/EDR presence and health.
  • Software inventory: installed applications, versions, EOL software, unlicensed installs, shadow tooling.
  • Backup posture: what is backed up, schedule, retention, where copies live, when a restore was last tested – verify, don't accept the client's word. This feeds directly into backup and DR.
  • Security posture: open ports and exposed services, remote access methods in use, firewall rules, patch management state, prior incidents.
  • Licensing and vendors: ISP details, circuit IDs, contract and renewal dates, LOB application vendors and support contacts.

Capture everything into your documentation platform as you go – the assessment is the first draft of the client's permanent record per your documentation standards.

Step 3: rank findings by risk

Resist the wall-of-red-text report. Sort every finding into three or four tiers by business risk – likelihood times impact, in plain language: "no tested backups + admin accounts without MFA" outranks "switch firmware is old." Tag each finding with an owner-relevant consequence (downtime, data loss, breach, compliance exposure, wasted spend) and a rough remediation cost. Findings without a consequence and a price are trivia.

Step 4: build the deliverable

The deliverable is three documents in one:

  1. Findings report – risk-ranked, each finding with evidence, consequence, and recommendation. Lead with an executive summary of the top five.
  2. Roadmap – remediation sequenced over quarters: immediate quick wins, 90-day stabilization, and longer-term projects. This becomes the standardization plan below.
  3. Budget – dollar ranges per roadmap phase, split between one-time projects and ongoing managed spend, so the owner can plan rather than react.

Step 5: present to the owner

You are presenting to a non-technical business owner, so translate ruthlessly. Frame findings as risk reduction and cost control, not technology: what could take the business down, what it costs to fix, what it costs to ignore. Use the tiers – "three things need attention this month, five this quarter" – and stop. Do not tour the full inventory; leave the detail in the report appendix. For prospects, the close is natural: "here's the roadmap; this is what it looks like when we run it for you."

Step 6: convert findings into the standardization plan

Every finding is a deviation from your standards library, and every deviation becomes a roadmap item – this is the standardization discipline that mature MSPs credit with cutting reactive tickets by roughly two-thirds. Two tracks:

  • Quick wins (first 30 days): things the client can feel immediately – MFA enforcement, endpoint protection deployed, email security, patching the scary stuff. Don't wait for "stabilization" to deliver visible value.
  • Standardization projects (days 31–60 and beyond): migrate backup, AV/EDR, email security, and remote access onto your standard stack, priced into onboarding or the first-year rate – not absorbed as free work.

Tooling and time budget

Acronis RMM is one option for the baseline inventory: Device Sense identifies managed and unmanaged devices, while hardware and software inventory records what is installed. Pair it with the Microsoft 365 admin center for tenant data. If assessment volume justifies a dedicated tool, RapidFire Tools' Network Detective, now Kaseya-owned, automates collection and report generation. For a small shop, time-box the pre-sales version: a half day on site or remote for collection, a half day for analysis and the report, spread across a week of calendar time. The onboarding-depth version fills the first 30 days of the 30/60/90 plan alongside agent deployment. Unbounded assessments are how free audits eat a week of unbilled labor – remember that onboarding a client already typically costs $10–15k before profit.

Exit criteria

The assessment is done when:

  • Every in-scope system appears in the inventory, and the inventory lives in your documentation platform
  • Findings are risk-ranked, each with consequence, recommendation, and rough cost
  • The report, roadmap, and budget have been presented to the owner in person or on a call
  • Quick wins are scheduled with dates (post-signature) or quoted (pre-sales)
  • The roadmap items exist as tickets or projects in your PSA, not just in the PDF

If the prospect doesn't sign, you still exit cleanly: hand over the report, revoke any temporary access, and log the work – assessments that don't convert are marketing spend, and they refer surprisingly well.