Technical point of contact
A professional with basic knowledge of the infrastructure, from the internal IT team or the vendor responsible for administering the environment.
Evaluation
The evaluation period operates on production infrastructure rather than a demonstration environment. At its conclusion, the organization holds the security index, the list of critical risks identified, and the recommended action for each item, irrespective of the contracting decision.
Step by step
Day 1
Registration of contact and organization details. No credit card is required at any stage of the evaluation period.
Day 2
A thirty-minute session to survey the environment, formally define the monitoring scope, and grant the access required for execution.
First week
Delivery of the initial security index and the prioritized risk queue, with asset identification and a recommended action for each record.
Conclusion
The decision is taken on the basis of results obtained in the organization’s own environment. The technical report for the period remains with the organization.
Scope
The purpose of the evaluation is to establish the organization’s security position, not to present a tour of features.
On your side
Conditions necessary to execute the evaluation, recorded in advance.
A professional with basic knowledge of the infrastructure, from the internal IT team or the vendor responsible for administering the environment.
Executing a security scan requires authorization from whoever is legally accountable for the organization, recorded before any verification takes place.
Thirty minutes for the scoping meeting. Subsequent follow-up is conducted by the platform itself.
Questions
Monitoring the external surface requires no installation, since verification is executed from outside the perimeter. Monitoring the internal network requires an agent installed on a machine in the network, carried out jointly with the organization during the scoping meeting.
Scans are parameterised to operate without impact on availability, and both the scope and the execution window are agreed in advance. Sensitive equipment, such as medical devices and industrial control systems, is handled through passive verification.
The term is defined at the scoping meeting, together with the breadth of monitoring. The commitment given is delivery of the initial security index and the prioritized queue within the first week.
Platform access is terminated and the technical report of findings remains with the organization. There is no penalty, retroactive charge, or minimum term, since the evaluation precedes any contractual commitment.
The process provides for the scoping meeting, one interim contact for clarifications, and a closing contact. The organization may elect to conduct communication exclusively by email.