Answers

Frequently asked questions.

What is an independent IT audit?

An independent IT audit is an assessment of your technology carried out by a firm that does not manage that technology and does not sell it. It verifies what your IT provider or internal team has reported: that backups restore, that security controls are active, that spending matches what was agreed.

The reviewer earns nothing from the tools being assessed, so it has no stake in the answer.

How is this different from the audit our IT provider already does?

A provider reviewing its own work is reporting, not auditing. However well intentioned, it is being asked to grade itself on the very things it is paid to deliver.

actually. reviews the evidence behind the report. That is the whole difference, and it is the reason the firm exists.

How much does an independent IT review cost?

The fee depends on the size of the organization and the agreed scope, and it is quoted before any work begins. There are no hourly surprises and no vendor commissions.

Tell us about your organization and we will tell you what the review would involve and what it would cost.

Are you an MSP?

No. actually. does not operate as your day-to-day help desk or automatically seek to replace your existing technology provider.

We independently assess, advise and provide oversight.

Are you trying to replace our current provider?

Not necessarily. The review exists to establish what is actually happening, not to unseat anyone. It can equally end with you keeping your provider, on clearer expectations, with better documentation, reporting and accountability.

We recommend change only when the evidence supports it.

Will our IT provider feel threatened?

Some providers may initially be unfamiliar with independent oversight.

Strong providers usually recognize that a clear review can validate good work, clarify responsibilities and strengthen the client relationship.

Do you need access to our systems?

The required access depends on the scope. Some reviews can begin with interviews, reports, contracts and documentation. More comprehensive verification may require read-only or supervised access to selected systems and configurations.

Access requirements are agreed upon before the engagement begins.

Will you perform penetration testing?

Not as part of a standard review.

Where specialized penetration testing is appropriate, we can help define the scope, coordinate a qualified independent specialist and interpret the findings for leadership.

Is this a compliance audit?

Not unless the engagement is specifically scoped for a regulatory or contractual framework.

The Actually Review is primarily a business technology, cybersecurity and governance assessment.

How long does a review take?

The timeframe depends on the size and complexity of the organization and the agreed scope.

Focused assessments may be completed more quickly, while comprehensive reviews require additional interviews, evidence collection and validation.

What size of company do you work with?

actually. is designed primarily for organizations with approximately 25 to 250 employees, although other organizations may also be suitable.

Can you review an internal IT department?

Yes. We work with outsourced providers, internal IT teams and hybrid environments.

Can you help implement the recommendations?

Our preferred role is to define the required outcome, advise leadership and verify completion.

Implementation can often be performed by your current provider or internal team. Where additional specialists are required, we can help coordinate the work while maintaining appropriate independence.

How often should we have an independent review?

A comprehensive review is commonly conducted annually or when a major change or concern occurs.

Higher-risk or faster-growing organizations may benefit from quarterly or monthly oversight.

Will this damage the relationship with our IT provider?

It should not. The review is not an accusation and we do not arrive looking for someone to blame.

A provider doing good work has nothing to fear from evidence of it. A review becomes uncomfortable in one situation: when something was being reported as done and was not.

What is a fractional CIO?

A fractional CIO is a senior technology leader engaged part time. They own the roadmap, the budget and the governance, hold providers accountable, and report to leadership in business terms.

It suits companies where technology decisions have become material but the need does not yet justify a full-time executive hire.

What does cybersecurity verification actually check?

Whether the controls you are paying for are present, correctly configured, actively monitored and properly governed: multi-factor authentication, privileged access, endpoint protection, patching, monitoring, backups and offboarding among them.

Owning a security tool and being protected by it are different things, and only one of them shows up on the invoice.

Do you sell the software or services you assess?

No. actually. does not resell technology, does not take vendor commissions and has no financial interest in what we recommend.

If we did, our findings would be marketing. Independence is the product.

What do we actually receive at the end?

A plain-language executive report: what was examined, what the evidence showed, what it means for the business, and a prioritized action plan.

It is written to be read by leadership, not only by technical staff. It is a document, not a dashboard.

We already have cyber insurance. Do we still need this?

Cyber insurance pays out against the answers you gave on the application. Those answers describe controls, and controls are exactly what an independent review verifies.

The time to find out that a control was not in place is before a claim, not during one.

Do you work outside Toronto?

Yes. actually. is based in Toronto and works with organizations across Canada, and selectively elsewhere in North America.

Much of the work is done through evidence, interviews and reporting, so geography is rarely the constraint.

Still have a question?