Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call
HomeServicesSecurity Assessments

Security Assessments

A security problem you can name is the easy kind. The harder one is a set of assumptions nobody has ever tested. A NetSys assessment tests them: what's exposed to the internet, who can reach what inside, whether the backups actually restore, and how your staff behave when a convincing email arrives. What you get back is a prioritized findings list, an executive summary your leadership can act on, and a remediation plan. The on-site penetration test is free, and it's a common place to start.

Take a Free Assessment

The short answer

A cyber security assessment is a point-in-time review of your environment by an engineer, scoped to how your business actually runs. NetSys assessments examine six areas: external attack surface, identity and Microsoft 365 posture, endpoint and patch state, backup recoverability, network segmentation, and user susceptibility to phishing and wire fraud. You receive three artifacts: a prioritized findings list with a severity and an honest effort estimate on each item, an executive summary written for an owner who doesn't manage IT, and a remediation plan that separates quick wins from projects. A vulnerability scan is automated output; an assessment is an engineer interpreting that output against your business. The free on-site penetration test is a common starting point, and the findings are yours whether or not you hire us.

Cyber Security Assessment Services by The NetSys Group

An assessment is a common way a NetSys relationship starts. Somebody wants to know where they stand before signing anything, so an engineer goes and looks, writes it down, and hands it over. What happens after that is genuinely their call.

We have spent 28+ years in business working with importers, medical practices, law firms, and financial firms, and the scope of the exercise changes with each of them. The output doesn't. You end up with a list you can act on, in priority order, in language your leadership actually understands.

This is the broader assessment practice. The free on-site penetration test is one piece of it — the loudest and most convincing piece — but not the whole picture.

A Scan Is Output. An Assessment Is Judgment.

Any tool can produce a list of missing patches and open ports. That list is close to worthless until somebody knows which server runs your ERP, which mailbox the bookkeeper shares, and what happens on a Friday afternoon when the warehouse is shipping. Our engineers run the tooling, then spend the real hours on interpretation: which findings are genuinely reachable from outside, which are theoretical, which are load-bearing for the business, and which cheap fix removes three of them at once. That's why what you get back is short and ordered rather than long and alphabetical — and why every finding carries an effort estimate next to its severity. A risk you can't schedule isn't actionable.

What We Assess, and What You Get Back

External Attack Surface

What an attacker can see and reach before they have any credentials at all.

  • Internet-facing services, remote access endpoints, and open ports
  • Firewall, VPN, and edge device configuration and firmware state
  • Exposed administrative interfaces and forgotten legacy hosts
  • Domain, DNS, and email authentication records (SPF, DKIM, DMARC)
  • Company credentials already circulating from third-party breaches

Identity & Microsoft 365 Posture

A working login opens more doors than an exploit does. Identity is where we spend the most time.

  • Multi-factor authentication coverage — including the accounts that quietly skipped it
  • Conditional access policies, legacy authentication, and admin role assignment
  • Mailbox forwarding rules, delegate access, and third-party OAuth app consents
  • Former employees, service accounts, and shared logins that still work
  • Tenant audit logging and alerting — whether anything would be noticed

Endpoint & Patch State

Every laptop is a way in. We inventory what's actually deployed, not what the asset spreadsheet claims.

  • Devices with no endpoint detection agent, or an agent that stopped reporting weeks ago
  • Operating system and third-party patch levels, including unsupported versions still in service
  • Local administrator rights and credential reuse across machines
  • Disk encryption and lock-screen policy on anything that leaves the building
  • Unmanaged personal devices touching company mail and files

Backup Recoverability

A backup nobody has restored is a hypothesis. We test it instead of reading the console.

  • Whether backups are genuinely offline or immutable, or reachable with the same credentials as production
  • Timed restore tests against real data — files, mailboxes, and a full system
  • Coverage gaps: Microsoft 365 data, line-of-business databases, cloud file shares
  • Recovery time and recovery point measured against what the business can actually absorb
  • Who holds the keys, and whether recovery depends on one person answering the phone

Network Segmentation & Internal Access

The real question isn't whether someone gets in. It's how far they get afterward.

  • Flat networks where a warehouse scanner can reach the accounting server
  • Guest Wi-Fi, cameras, IoT, and building systems sharing production VLANs
  • File share and folder permissions — who can open payroll, HR, and client matter files
  • Lateral movement paths from a single compromised workstation
  • Vendor and remote-support access routes into the environment

User Susceptibility

The control that is a frequent weak point is a person under time pressure.

  • Authorized phishing simulation against a real employee population
  • Wire-transfer and vendor-bank-change procedures — the process, not just the mail filter
  • Who has been trained, when, and whether behavior changed afterward
  • How staff report something suspicious, and whether anyone is reading those reports

Sample Deliverables

Three artifacts, written for three different people in your building.

  • Prioritized findings list — each item states what we found, how we found it, what it exposes, a severity, and an honest effort estimate: an afternoon, a weekend, or a project
  • Executive summary — a plain-English read for an owner or partner who doesn't manage IT, covering the handful of findings that genuinely matter and what they put at risk
  • Remediation plan — the fixes in the order we'd do them, marked by who should own each one: your staff, your existing vendor, or us
  • Raw tool output attached as an appendix, so nothing is hidden — but the appendix is not the report
  • A walkthrough with the engineer who did the work, so you can argue with the conclusions
  • Everything is yours to keep, including if you hand it to another provider tomorrow

How It Starts and What Happens Next

The free on-site penetration test is the front door. Nothing after it is automatic.

  • An engineer visits your office, safely demonstrates how an attacker would get in, and leaves a prioritized fix list — no cost, no obligation
  • If the visit raises deeper questions, we scope a broader assessment across the areas above
  • Findings that line up with carrier questions feed straight into cyber-insurance readiness work
  • Businesses that want the program owned, budgeted, and reported over time move to a vCISO engagement
  • Remediation can go to your team, your current provider, or us — and we'll say plainly if something is outside our lane

Where We Assess

On-site visits across our service regions; remote assessment work anywhere.

  • On-site: New York metro, the lower Hudson Valley, New Jersey, Connecticut, Pennsylvania
  • On-site: Southwest Florida and Palo Alto, California
  • Remote assessment of cloud, identity, and endpoint posture wherever your systems live
Why NetSys

Why Businesses Choose NetSys for Security Assessments

Let The Netsys Group assess and help you resolve your exposure. Call 845-203-3914 for your complimentary risk assessment consultation today!

  • An engineer interprets the findings — you're not handed a scanner export and wished luck
  • The entry point is a free on-site penetration test, and the findings are yours either way
  • Engineers who have worked real environments for 28+ years — importers, medical practices, law firms, financial firms
  • A 100% ransomware recovery record standing behind everything we tell you about your backups
  • Findings ranked by real-world risk and remediation effort, not by vulnerability count
  • Confidentiality-first — financial clients stay unnamed, and so do you
  • Month to month, like every NetSys agreement, if you decide to keep working with us
Common Questions

Security Assessments FAQs

What is the difference between a security assessment and a vulnerability scan?

A scan is automated output — a tool lists missing patches, open ports, and known vulnerabilities. An assessment is an engineer reading that output against how your business actually runs: which findings are genuinely reachable, which one sits on the server your ERP depends on, and which single change closes several at once. We run scans as part of an assessment. We don't hand you the scan and call it a report.

What does a network security assessment actually examine?

Six areas: your external attack surface, identity and Microsoft 365 posture, endpoint and patch state, backup recoverability, internal network segmentation and permissions, and user susceptibility to phishing and wire fraud. Scope is agreed before we start — some clients want all six, some want the two they're already worried about.

What deliverables do we receive at the end?

Three things. A prioritized findings list, where every item states what we found, how we found it, what it exposes, a severity, and an effort estimate. An executive summary written for an owner or partner who doesn't manage IT. And a remediation plan ordered the way we'd actually do the work, split by who should do each piece. Raw tool output is included as an appendix, and an engineer walks you through all of it. It's yours to keep — including if you hand it to a different provider.

How is this different from your penetration testing service?

The penetration test is one deliverable inside the broader assessment practice — an engineer demonstrating live how someone gets in, physically and digitally. An assessment is wider and quieter: configuration review, identity posture, restore testing, permissions, segmentation. The free on-site penetration test is a common starting point, because watching it is more persuasive than reading about it, and an assessment is then scoped around whatever it surfaced.

Is the assessment disruptive to our operations?

No. Everything runs with your written authorization and is scoped to avoid production impact — we demonstrate what's reachable without damaging systems or touching client data. Restore testing runs against isolated copies. Anything carrying a real risk of disruption gets scheduled with you first, not sprung on you.

Do we have to become a managed client afterward?

No. The free on-site penetration test carries no obligation and the findings are yours regardless. Larger assessments are scoped and agreed up front. If you want the fixes handled by your own staff or your current provider, that's a fine outcome — the report is written so somebody else can act on it.

Will the findings help with our cyber insurance application or a client security questionnaire?

Usually, yes. What carriers and enterprise clients ask about — multi-factor authentication coverage, endpoint detection, tested backups, training — is largely what an assessment examines, so you answer from evidence instead of memory. We implement and document controls; coverage and premium decisions stay between you and your carrier.

How often should we reassess?

Environments drift. New staff, a new vendor, another office, a platform change, one exception granted 'temporarily' — the picture looks different a year later. An annual revisit is a sensible cadence, and so is timing one ahead of an insurance renewal, an acquisition, or a client security review. Managed clients get much of this continuously through monitoring rather than as a separate exercise.

Ready to get started?

Protect your business before the next threat strikes.

Take control of your security today. Schedule your comprehensive cybersecurity assessment with The NetSys Group and stay one step ahead of every threat.