You Can’t Secure What You Can’t See: Why Every IT Relationship Starts with an Assessment
There’s a principle in cybersecurity that gets repeated so often, it risks sounding cliché: You can’t protect what you don’t know you have.
Yet when we sit down with prospective clients, many can’t answer some of the most fundamental questions about their technology environment.
What devices are connected to the network? Who has access to critical systems? Where does company data live? Are backups working? Would anyone know if something went wrong?
An IT assessment is how you find out.
On a recent episode of The Creative Stack, we unpacked what an IT assessment actually involves, what we’re looking for, and why we consider it the foundation of every successful IT partnership we’ve built over the past two decades.
What an IT assessment actually is
At its core, an IT assessment is a comprehensive snapshot of a company’s technology environment.
It documents infrastructure, evaluates security controls, reviews operational processes, and identifies areas where risk, inefficiency, or technical debt may exist.
The easiest comparison is a home inspection.
A good inspector doesn’t simply confirm that a house exists. They identify the roof that’s nearing the end of its life, the electrical panel that’s undersized, or the moisture issue that could become a much larger problem down the road.
An IT assessment serves the same purpose. It provides a clear picture of what’s working, what’s not, and what should be prioritized next.
One important distinction: an assessment is not a quote. A quote tells you what something costs. An assessment tells you what you actually have, what risks exist, and what a realistic technology roadmap should look like.
Those are very different deliverables.
The framework behind the process
Our assessments are built around the NIST Cybersecurity Framework (NIST CSF), one of the most widely adopted cybersecurity standards worldwide.
What makes NIST particularly valuable is that it’s practical.
Rather than prescribing specific products or configurations, it focuses on outcomes. It doesn’t tell you exactly which backup platform to use. It tells you that you should have a reliable backup strategy and recovery process.
That flexibility allows organizations of all sizes to apply the framework in ways that align with their business requirements and risk tolerance.
The framework is organized around six core functions:
- Identify
- Protect
- Detect
- Respond
- Recover
- Govern
Together, they provide a complete view of an organization’s cybersecurity posture—from understanding what assets exist to managing incidents and recovering from disruptions.
What we evaluate
While every environment is different, assessments generally focus on three primary areas.
Infrastructure
This includes networks, devices, Wi-Fi, servers, and the systems that connect everything together.
For organizations with physical offices, Wi-Fi performance is often more complex than people realize.
In dense urban environments like New York City, dozens—or even hundreds—of competing wireless networks may exist within range. Coverage, interference, and device density all impact performance.
We’ve encountered offices where executive offices had the weakest connectivity in the building simply because no one had ever properly evaluated the environment.
Security
This is where we assess the fundamentals:
- Multi-factor authentication (MFA)
- Patch management
- Endpoint protection
- Backup integrity
- Access controls
- Identity management
The issues we uncover are rarely sophisticated. More often, they’re basic controls that were never implemented, never tested, or quietly drifted out of compliance over time.
The good news is that most of these gaps are highly fixable once they’re identified.
Operations and Governance
This is often the most overlooked area—and increasingly the most important. How are employees onboarded and offboarded? Who approves new software? How are vendors managed? Who owns access permissions?
Organizations without formal IT processes frequently discover they have no consistent answers to these questions. That lack of visibility creates operational and security risk regardless of how modern the underlying technology may be.
Remote, hybrid, and in-office companies require different approaches
Not every assessment looks the same.
A fully remote organization may have little physical infrastructure to evaluate, but governance and security become even more important. Device management, identity controls, and access governance take center stage.
Companies with physical offices add networking and infrastructure considerations, including Wi-Fi performance, connectivity, and potentially on-premises systems.
Hybrid organizations often present the greatest complexity because they must secure and support both environments simultaneously while maintaining a consistent user experience.
The framework remains the same. The areas of emphasis change.
Assessment vs. Onboarding
One question we hear frequently is whether an assessment and onboarding are the same thing. They’re not.
An assessment is observational. We’re documenting the current state of the environment, identifying risks, and evaluating what exists against established standards. We’re not making changes.
If MFA isn’t enabled, we’ll identify it as a priority. We won’t enable it during the assessment itself.
Onboarding is the implementation phase. That’s when controls are deployed, systems are standardized, monitoring tools are installed, and security improvements are put into place.
The assessment tells us what needs to happen. The onboarding is where it happens..
Questions to ask any IT provider
If you’re evaluating providers, there are a few questions worth asking before committing to an assessment.
What does the final deliverable look like?
A reputable provider should be able to show examples and clearly explain what you’ll receive.
What framework do you use?
Assessments grounded in recognized standards such as NIST tend to be more rigorous, transparent, and defensible than proprietary checklists.
How often do you perform assessments?
Technology environments evolve constantly. Providers who conduct assessments regularly are generally better positioned to recognize emerging risks and trends.
Can you work alongside an existing IT provider?
A professional assessment shouldn’t require replacing your current IT team. The best providers can collaborate transparently with existing partners when necessary.
Will this disrupt our business?
It shouldn’t. A properly executed assessment is largely observational. Employees should be able to continue working normally while the review takes place.
The assessment is the beginning, not the end
The most valuable outcome of an assessment isn’t the report. It’s the clarity.
A well-executed assessment gives leadership a shared understanding of the current environment, the risks that matter most, and the priorities that should come next.
For us, it’s also the beginning of a relationship. Managed IT providers become deeply integrated into the businesses they support. We communicate regularly, help shape technology strategy, and often become one of the most engaged external partners a company works with.
That level of involvement requires trust.
The assessment allows both sides to determine whether there’s a fit before any long-term commitment is made.
Most organizations don’t come to us asking for an assessment. They come with a specific concern: a recent security incident, a pending acquisition, rapid growth, or simply a feeling that something isn’t quite right.
That’s usually the right place to start. From there, we can determine whether an assessment is the next step—and what it should look like for that particular business.
The Creative Stack is produced by Valiant Technology, a managed IT services provider based in New York specializing in serving creative agencies and PR firms. Listen to episodes at podcast.thevaliantway.com and learn more at thevaliantway.com.























