Answers
Frequently asked questions.
Are you an MSP?
No. actually. does not provide, resell or replace IT services, and takes no commissions from anyone who does.
We independently review what your IT provider reports, and both clients in our case studies kept the provider they already had.
What is an independent IT audit?
An independent IT audit is an assessment of your technology carried out by a firm that does not manage that technology and does not sell it. It examines the evidence behind what your IT provider or internal team reports, such as recovery tests, security controls and spending commitments. Findings explain what the agreed scope and checks support, and what remains unverified.
The reviewer earns nothing from the tools being assessed, so it has no stake in the answer.
How is this different from the audit our IT provider already does?
A provider's internal review can produce useful evidence. It is different from an external independent examination because the provider is reviewing work it is responsible for delivering.
actually. examines evidence within an agreed scope and explains what the checks support and what remains unverified. In either kind of review, the method, evidence and limitations matter.
How much does an independent IT review cost?
The fee depends on the size of the organization and the agreed scope, and it is quoted before any work begins. There are no hourly surprises and no vendor commissions.
Tell us about your organization and we will tell you what the review would involve and what it would cost.
Are you trying to replace our current provider?
actually. does not take over IT delivery. Your provider or internal team continues to operate the technology and implement changes.
The audit can inform your decision to retain or change a provider. We report what the evidence supports, including work that is being done well and commitments that need attention.
Will our IT provider feel threatened?
Some providers may initially be unfamiliar with independent oversight.
Strong providers usually recognize that a clear review can validate good work, clarify responsibilities and strengthen the client relationship.
Do you need access to our systems?
The required access depends on the scope. Some reviews can begin with interviews, reports, contracts and documentation. More comprehensive verification may require read-only or supervised access to selected systems and configurations.
Access requirements are agreed upon before the engagement begins.
Will you perform penetration testing?
Not as part of a standard review.
Where specialized penetration testing is appropriate, we can help define the scope, coordinate a qualified independent specialist and interpret the findings for leadership.
Is this a compliance audit?
Not unless the engagement is specifically scoped for a regulatory or contractual framework.
The Actually Review is primarily a business technology, cybersecurity and governance assessment.
How long does a review take?
The timeframe depends on the size and complexity of the organization and the agreed scope.
Focused assessments may be completed more quickly, while comprehensive reviews require additional interviews, evidence collection and validation.
What size of company do you work with?
actually. is designed primarily for organizations with approximately 25 to 250 employees, although other organizations may also be suitable.
Can you review an internal IT department?
Yes. We work with outsourced providers, internal IT teams and hybrid environments.
Can you help implement the recommendations?
Our preferred role is to define the required outcome, advise leadership and verify completion.
Implementation can often be performed by your current provider or internal team. Where additional specialists are required, we can help coordinate the work while maintaining appropriate independence.
How often should we have an independent review?
A comprehensive review is commonly conducted annually or when a major change or concern occurs.
Higher-risk or faster-growing organizations may benefit from quarterly or monthly oversight.
Will this damage the relationship with our IT provider?
It should not. The review is not an accusation and we do not arrive looking for someone to blame.
A provider doing good work has nothing to fear from evidence of it. A review becomes uncomfortable in one situation: when something was being reported as done and was not.
What is a fractional CIO?
A fractional CIO is a senior technology leader engaged part time. They own the roadmap, the budget and the governance, hold providers accountable, and report to leadership in business terms.
It suits companies where technology decisions have become material but the need does not yet justify a full-time executive hire.
What does cybersecurity verification actually check?
Whether the controls you are paying for are present, correctly configured, actively monitored and properly governed: multi-factor authentication, privileged access, endpoint protection, patching, monitoring, backups and offboarding among them.
Owning a security tool and being protected by it are different things, and only one of them shows up on the invoice.
Do you sell the software or services you assess?
No. actually. does not resell technology, does not take vendor commissions and has no financial interest in what we recommend.
If we did, our findings would be marketing. Independence is the product.
What do we actually receive at the end?
A plain-language executive report: what was examined, what the evidence showed, what it means for the business, and a prioritized action plan.
It is written to be read by leadership, not only by technical staff. It is a document, not a dashboard.
We already have cyber insurance. Do we still need this?
An independent review can examine whether the evidence supports the control statements on your insurance application. Having a policy does not itself establish that those controls operate as described.
The audit does not determine insurance coverage or a claim outcome. Confirm policy and application questions with your insurer or broker.
Do you work outside Toronto?
Yes. actually. is based in Toronto and works with organizations across Canada, and selectively elsewhere in North America.
Much of the work is done through evidence, interviews and reporting, so geography is rarely the constraint.
If your question is about your own provider rather than about us, start with ten questions to ask your IT provider. It is free, it takes an email address, and each question comes with the document, date or number that settles it.
Still have a question?
Keep reading
Where to go next.
The review, ongoing oversight, and leadership
Three ways to work with an independent firm, from one report to a standing seat at the table.
Who we helpBusinesses of 25 to 250 people
Big enough to depend on a provider, small enough that nobody inside checks the provider's work.
ContactRequest an independent review
A short form, a reply from a person, and a sample report if you want to see one first.