Our flagship independent assessment

Now accepting reviews

The Actually Review.

A comprehensive, evidence-based review of your technology, cybersecurity, service providers, spending and strategy. The result is a plain-language picture of where you stand, what matters most and what should happen next.

An open, bound technology review report on a desk, annotated in pencil in the margin, with a pencil and reading glasses beside it, black and white
The deliverable, not a dashboard.

Why it exists

There is often a gap between reported and verified.

Your provider may be sending reports. Your team may be completing checklists. Your systems may appear operational. But routine reporting may not answer the questions leadership actually needs answered. The Actually Review examines the evidence behind the reports.

What is an independent IT review?

An independent IT review is an assessment of a company's technology carried out by a firm that does not manage that technology and does not sell it. It verifies what the internal team or the IT provider has reported: that backups restore, that security controls are active, that spending matches what was agreed. The reviewer has no stake in the answer.

What we review

Six domains, plus spending and planning.

01

Business & leadership

  • Objectives, growth plans, priorities
  • Governance and risk tolerance
  • Technology dependence
  • and previous incidents
02

Technology environment

  • Infrastructure and cloud services
  • Networks, devices, identity
  • Documentation and monitoring
  • and lifecycle planning
03

Cybersecurity

  • Access controls and MFA
  • Endpoint and email protection
  • Patching and vulnerabilities
  • and incident response
04

Backup & recovery

  • Coverage and retention
  • Off-site or immutable copies
  • Restoration testing
  • and recovery time expectations
05

IT operations

  • Tickets and escalations
  • Onboarding and offboarding
  • Change management
  • and vendor coordination
06

Providers & contracts

  • Scope and service levels
  • Pricing and reporting
  • Cybersecurity obligations
  • and exit provisions

Plus a full review of spending and planning: current costs, licensing, duplication, unused services and the technology roadmap.

Methodology

We do not audit by questionnaire alone.

Leadership interviewsProvider interviewsDocumentation reviewContract reviewReport reviewTechnical evidenceConfiguration samplingProcess observationControl validationIndependent analysis

Rating approach

Every finding is placed in business context.

Risk.
What could happen if the issue remains unresolved?
Impact.
How could it affect operations, finances, customers or reputation?
Urgency.
How quickly should leadership act on the finding?
Effort.
What time, cost and complexity may be required?

This prevents a long technical list from becoming an unmanageable collection of equally urgent recommendations.

A bound review document alone on a long boardroom table, page markers along its fore edge and one marker in yellow, empty chairs beyond, black and white
The review, before it becomes a conversation.

What you receive

Five deliverables. Evidence, exhibited.

01

Executive Briefing

02

Independent Assessment Report

03

90-Day Action Plan

04

Technology Risk Register

05

Provider Discussion Guide

In their words

“The Actually Review provided a level of strategic insight that went beyond day-to-day IT support. It gave our leadership team an independent perspective on technology risk and a clear roadmap for strengthening our environment.”

Leadership Team, Goodkey, Weedmark & Associates Limited

Two engagements, and the deliverables each of them produced, are described in the case record.

What happens after

A review is where the work begins, not where it ends.

01Manage the action plan internally
02Ask your provider to complete the work
03Use actually. to verify remediation
04Begin quarterly oversight

We do not automatically recommend replacing the provider. In many cases the best result is a stronger provider relationship with clearer expectations and greater accountability. Where a review should become a standing rhythm, it leads into Actually Oversight.

Who should consider a review

Particularly valuable when…

You are unsure whether your provider is performing
Reports appear too simple or consistently green
Your provider contract is renewing
You have experienced a cybersecurity incident
You are acquiring or selling a company
A senior IT employee has left
Technology costs are increasing
The board is asking more cybersecurity questions

You already know what you have been told.
Now find out what the evidence says.

Weighing it up? The FAQ covers cost, access and timing, and what a review means for your current provider.