Independent technology assurance and advisory

Do you know what your IT provider is actually doing?

actually. reviews your technology, cybersecurity, IT provider, spending and strategy, so you can decide on evidence instead of assumptions.

We don’t sell IT. We verify it, independently. No vendor commissions, no stake in the answer.

Black and white photograph, over the shoulder of an independent reviewer in a suit marking a single line of a company's IT audit report in yellow highlighter, a laptop showing a security access log on the desk beside it
Going through it, line by line.

Trust is important.
Evidence is better.

The problem

Everything looks fine, until it isn’t.

Most leaders do not receive bad information intentionally. They get technical reports without context, and dashboards full of green indicators. The important questions often go unanswered.

Editorial illustration: a wall of identical grey indicator tiles, all reading the same, with a single small figure lifting one tile to check the dark space hidden behind it.
Every indicator reads clear. None independently verified.
01Are the backups actually recoverable?
02Are former employees fully removed?
03Are security alerts actually being reviewed?
04Are systems actually patched?
05Are you paying for services you actually receive?
06Who is independently checking the checker?

Every one of these is a question the checker cannot answer about itself.

You audit your finances. Who’s auditing your technology?

Editorial illustration: a tight inward-facing huddle of figures with their backs turned, and one figure standing apart, reading from a document

The oversight gap

We provide the oversight business technology has been missing.

Established precedent

Editorial illustration of a magnifying glass over a row of tally bars, one bar shown clear under the lens
Accountants
independently review financial information.
Editorial illustration of a fountain pen underlining one clause on a page of redaction bars
Lawyers
independently review legal risk.
Editorial illustration of a spirit level resting on a beam with its bubble exactly centred
Engineers
inspect buildings and systems.

Yet many businesses rely almost entirely on their technology provider to assess and report on its own work. actually. adds the independent layer between leadership and the people managing the technology.

Further readingWhy technology has become a concentrated business riskHow the dependence built up, what the evidence shows, and what independent oversight of it looks like.Read the argument
A hand tracing a single yellow network cable to a port on a modern switch
The evidence, up close.

The essentials

Five questions every business leader should be able to answer.

  1. 1
    Are we secure?
    Not “do we own security tools?” Are the right controls configured, monitored and tested?
  2. 2
    Can we recover?
    Not “do we have backups?” Can critical systems and information actually be restored within an acceptable timeframe?
  3. 3
    Are we receiving what we pay for?
    Are contracted services delivered consistently, documented properly and producing measurable value?
  4. 4
    Is technology helping the business?
    Does the technology plan support growth, efficiency, profitability and risk reduction?
  5. 5
    Who is independently verifying all of this?
    Your provider should be trusted. That does not mean its work should never be independently reviewed.

Five questions. One independent answer.

If any of these gives you pause, that is what a review answers.

Request a Review

How it works

Five steps, start to finish.

Step 01
Discover
We meet leadership to understand the business, environment, concerns and providers.
Step 02
Examine
We review documentation, systems, contracts, reports, configurations and evidence.
Step 03
Verify
We test whether important controls and commitments actually function as intended.
Step 04
Explain
We translate findings into clear business language: risk, impact, urgency, ownership.
Step 05
Improve
We build a prioritized action plan and can verify improvements are completed.
An independent technology review in progress
Evidence, examined in person.

What we often discover

The gap between what leadership believes and what the evidence shows.

/Backups that have never been restoration-tested
/Security tools installed but poorly configured
/Incomplete employee offboarding
/Excessive administrator access
/Unsupported or aging systems
/Missing policies and response procedures
/Unmanaged SaaS applications
/Overlapping software subscriptions
/Weak vendor accountability
/IT reporting that measures activity, not outcomes

“Everything was green.”

Green dashboards do not always mean low risk. Sometimes they simply mean that no one is measuring the right things.

Who we help

Built for businesses that have outgrown blind trust.

Established organizations of 25 to 250 people that depend on technology but have no independent technology governance.

A business leader standing in her daylit office with a colleague at a desk behind her
The people who carry the risk.
01.Financial Services
02.Law and Professional Services
03.Associations and Unions
04.Owner-Managed Businesses
05.Businesses in Transition

We do not sell the tools we assess.

Independent advice, not another subscription. Our role is to determine what you have, what you need, what is working, what is being missed, and what should happen next. More on why independence matters here.

Andre, founder of actually.
Andre, founder.

About the founder

Three decades in business technology.

Andre founded his first technology business in 1995 and built it into an established management and consulting company. He saw the industry from both sides, and the structural problem facing owners: the company that sells, implements and monitors the technology is often the only one explaining whether it works.

actually. was created to provide the independent perspective that was missing.

The Actually Brief

Clear thinking for leaders responsible for technology.

No unnecessary technical language. No product pitches. No panic. Just the questions leaders should be asking.

Find out what is actually happening.