Identity and access
Review administrator roles, user accounts, multifactor authentication, access changes, remote access, and the way people join or leave the organization.
F09 Tech reviews the systems, access, data, vendors, and recovery plans your business depends on. You get a clear view of risk and a prioritized plan for reducing it.
Risk assessment map
Evidence, business impact, responsible owners, and a documented next step
What we review
A useful assessment connects technical controls to the work, data, obligations, and operational consequences they protect. The scope is documented so findings are clear and repeatable.
Review administrator roles, user accounts, multifactor authentication, access changes, remote access, and the way people join or leave the organization.
Examine endpoint protections, patching, mailbox security, cloud configuration, logging, and the controls around common attack paths.
Review what is backed up, where copies are stored, who can change them, how recovery is tested, and which systems must return first.
Assess ownership, vendor access, security expectations, employee guidance, incident contacts, escalation, communications, and recovery decisions.
How the assessment works
The engagement is designed to give decision-makers a useful sequence, not a long list of warnings without context or ownership.
Identify the locations, systems, data, users, vendors, obligations, and business processes included.
Review configurations, policies, inventories, access, backup records, and interviews relevant to the scope.
Connect observed gaps to likely scenarios, business impact, existing safeguards, and dependencies.
Separate urgent exposure, quick risk reduction, foundational projects, and longer-term improvements.
Document the next action, responsible owner, validation method, and follow-up for each priority.
What you receive
Findings are written for action. Technical detail supports the evidence, while the executive view keeps risk, cost, ownership, and sequence visible.
NIST Cybersecurity Framework 2.0 for small businessNIST provides a small-business quick-start path for managing cybersecurity risk. Our assessment can use CSF 2.0 concepts as an organizing framework without claiming certification or endorsement.Good fit signals
An independent view is valuable when the business cannot clearly explain its current security posture or needs to make an upcoming technology or risk decision.
Decision support
Use this small business cybersecurity assessment checklist to examine ownership, accounts, devices, data, vendors, backups, and incident readiness.
Read the guideCommon questions
The scope can include business-critical systems, administrator access, multifactor authentication, user accounts, email protections, endpoints, patching, backups, recovery, vendors, policies, security awareness, and incident response readiness. The exact review is agreed before work begins.
No. A risk assessment reviews the organization, systems, controls, and business impact to identify and prioritize gaps. A penetration test is a separate technical exercise that attempts to exploit vulnerabilities within an authorized scope. Testing can be recommended or scoped separately when it is appropriate.
The assessment can use NIST Cybersecurity Framework 2.0 concepts to organize governance, identification, protection, detection, response, and recovery. It is a practical, framework-informed review and does not represent NIST certification or endorsement.
Yes. Findings are organized by business impact, likelihood, exposure, effort, dependency, and urgency. The output separates immediate risk-reduction steps from projects that require budget, policy, vendor coordination, or longer implementation work.
Yes. F09 Tech can scope follow-on work across identity, endpoint protection, cloud configuration, backup and recovery, monitoring, policies, user training, and incident response. You can also take the written priorities to another provider.
Start with the systems, data, access, vendors, and operational risks that matter most. We will define the assessment scope and the decision it needs to support.