Skip to content
IT and security · questionnaire

16 questions, and you will learn something from answering them.

Once you know where your estate stands, give your AI assistant sourced reference knowledge to read it against: Lattice. See Lattice

16 questions, and most of them are one click. They are the same ones we would ask in the first meeting, and answering them ahead of it means that meeting is about what to do rather than about what you have.

Not ready for this? The ordinary contact form is two lines, and what the service covers is a page you can read first.

“Not sure” is a real answer and it is on every question. You have no IT department — that is the reason you are here, and finding out is our job, not yours.
Who you are

Optional. Only if you would rather we called.

Optional. Tells us whether we can come to you.

Your setup
01

It sets the shape of everything else. A team of six and a team of sixty are different problems.

02

Including the machine in the corner nobody logs into any more. Especially that one.

03

Name the two or three that would end the day if they broke. Specialist tools matter here — they usually have licensing and hardware requirements that generic IT support gets wrong.

04

This single answer decides most of the infrastructure — and most of the backup conversation.

05

A backup nobody has restored is a belief, not a backup. This is the question that changes the most minds.

06

If the honest answer is the last one, that is usually fixable and usually worth more than anything else on this list.

07

A consumer router doing the job of a business network is the most common thing we find, and the cheapest to fix.

08

If the answer is the second one, we are usually giving that person their week back.

09

Small firms with large clients get audited by proxy. It is worth knowing before it arrives, not during.

Accounts and access

Most firms answer “not sure” or “probably” to several of these. That is what happens without someone whose job it is; it is not a failing, and we would rather know.

10

One account per person is what makes everything else possible: removing someone's access in one place, turning on two-step everywhere at once, and being able to say who did what. Logins accumulated tool by tool is the most common answer, and the most expensive to unpick later.

11

The single change that prevents the most damage for the least money, and the first thing an insurer or a client questionnaire asks about (two-factor, or MFA, if you are comparing quotes).

12

A shared login for a licence portal or the bank is normal and understandable. It is also why nobody can say who did what, and why access cannot be removed for one person without changing it for everyone.

13

It decides how far a bad click travels. It is also the setting most likely to irritate people if it is changed badly, so we would talk it through rather than just turn it on.

14

Encryption is already built into these machines and usually just not switched on. It is the difference between losing a laptop and having to tell your clients you lost their files.

15

Almost every firm answers one of the last three. It is not a failing; it is what happens without an offboarding checklist.

One more thing
16

Something usually did. It is still the most useful answer on this page.