Our flagship independent assessment
Now accepting reviewsThe Actually Review.
A comprehensive, evidence-based review of your technology, cybersecurity, service providers, spending and strategy. The result is a plain-language picture of where you stand, what matters most and what should happen next.

Why it exists
There is often a gap between reported and verified.
Your provider may be sending reports. Your team may be completing checklists. Your systems may appear operational. But routine reporting may not answer the questions leadership actually needs answered. The Actually Review examines the evidence behind the reports.
What is an independent IT review?
An independent IT review is an assessment of a company's technology carried out by a firm that does not manage that technology and does not sell it. It verifies what the internal team or the IT provider has reported: that backups restore, that security controls are active, that spending matches what was agreed. The reviewer has no stake in the answer.
What we review
Six domains, plus spending and planning.
Business & leadership
- Objectives, growth plans, priorities
- Governance and risk tolerance
- Technology dependence
- and previous incidents
Technology environment
- Infrastructure and cloud services
- Networks, devices, identity
- Documentation and monitoring
- and lifecycle planning
Cybersecurity
- Access controls and MFA
- Endpoint and email protection
- Patching and vulnerabilities
- and incident response
Backup & recovery
- Coverage and retention
- Off-site or immutable copies
- Restoration testing
- and recovery time expectations
IT operations
- Tickets and escalations
- Onboarding and offboarding
- Change management
- and vendor coordination
Providers & contracts
- Scope and service levels
- Pricing and reporting
- Cybersecurity obligations
- and exit provisions
Plus a full review of spending and planning: current costs, licensing, duplication, unused services and the technology roadmap.
Methodology
We do not audit by questionnaire alone.
Rating approach
Every finding is placed in business context.
This prevents a long technical list from becoming an unmanageable collection of equally urgent recommendations.

What you receive
Five deliverables. Evidence, exhibited.
Executive Briefing
Independent Assessment Report
90-Day Action Plan
Technology Risk Register
Provider Discussion Guide
“The Actually Review provided a level of strategic insight that went beyond day-to-day IT support. It gave our leadership team an independent perspective on technology risk and a clear roadmap for strengthening our environment.”
Two engagements, and the deliverables each of them produced, are described in the case record.
What happens after
A review is where the work begins, not where it ends.
We do not automatically recommend replacing the provider. In many cases the best result is a stronger provider relationship with clearer expectations and greater accountability. Where a review should become a standing rhythm, it leads into Actually Oversight.
Who should consider a review
Particularly valuable when…
You already know what you have been told.
Now find out what the evidence says.
Weighing it up? The FAQ covers cost, access and timing, and what a review means for your current provider.