Technology Blueprinting
// Strategy · 05

12 questions to ask before you let anyone assess your IT.

Most IT assessments are sold as clarity. Many deliver a sales pitch dressed in a spreadsheet. Here's how to tell the difference before you sign anything.

person Zachary Will
schedule 7 min read

There's a version of this story that plays out constantly in conference rooms: a business owner gets a call from a vendor, a consultant, or an MSP they've never worked with. The pitch is that they'll come in, look at everything, and tell you what needs to be fixed. It's framed as a gift. Objective. Comprehensive. Sometimes even free.

Six weeks later, you get a 40-page deck with red, yellow, and green traffic lights, plus a proposal to fix everything they flagged at the bottom of page 38.

That's not an assessment. That's a lead generation campaign with extra steps.

A real IT assessment — whether it's called an audit, a roadmap, a blueprint, or a gap analysis — should leave you better equipped to make decisions, not more dependent on the firm that delivered it. The output should be something you can act on with any qualified partner, including doing some things in-house. It should reflect your actual environment, your actual risk tolerance, and your actual priorities.

The trouble is, from the outside, the good ones and the bad ones look almost identical. Both come with credentials. Both come with methodology decks. Both walk you through your network and ask about your backups.

These twelve questions help you find out which kind you're dealing with.

Before the engagement starts

1. What do you do with the findings after the engagement ends?

This is the most revealing question on the list. If the answer involves upselling, onboarding you as a managed services client, or routing findings into their sales pipeline, you should know that upfront. There's nothing inherently wrong with a firm that also offers implementation services. But you should know going in whether the person scoping your environment has a quota attached to the outcome.

2. Will the report be ours to keep and share?

Some vendors produce assessments that are intentionally proprietary: formatted in a way that's hard to hand off, locked to their portal, or referencing their own internal scoring system. You should walk away with a report you can share with your board, your attorney, your next vendor, or your cyber insurance carrier without needing to go back to the original firm for translation.

3. Who actually does the work?

Bigger consultancies sometimes sell engagements at a senior level and deliver them through junior staff or offshore teams. Ask specifically who will be on-site, who will run the interviews, and who will sign off on the final report. You want to know that the person interpreting your environment has real experience, not that they're following a checklist.

4. What's your conflict of interest policy?

If the firm sells hardware, software, or managed services, ask directly: "Are there vendors or products you have a financial relationship with?" A firewall reseller who also does security assessments is not automatically untrustworthy, but they should disclose it, and their findings should be able to stand without the recommended remedy being a product they profit from.

During scoping

5. What does your methodology actually cover?

Generic answers here are a warning sign. A credible firm should be able to describe, specifically, which domains they assess: infrastructure, endpoints, identity and access, security controls, backup and recovery, cloud configuration, governance and compliance, vendor risk, business continuity. The more precise and bounded their answer, the more trustworthy the output. A good assessment doesn't try to cover everything loosely. It tells you exactly what it examined and what fell outside scope.

6. How do you handle things you can't directly access?

No assessment covers everything. Some environments have air-gapped systems, third-party-managed applications, or legacy infrastructure that resists scanning. Ask how they handle that. Do they note it clearly in the report? Do they use questionnaires as a proxy? Do they pretend those gaps don't exist? The answer matters less than the honesty of it.

7. What will you need from our team, and how much time will this take?

An assessment that requires nothing from you is probably not learning much about you. A thorough engagement needs access to key staff: your IT lead, maybe your CFO or operations director, whoever owns vendor relationships. It also needs time. If someone promises a full assessment in a few hours, they're doing a surface scan, not an assessment. Our Technology Blueprinting engagements run three to four weeks across four phases (Kickoff & Discovery, Scan & Data Collection, Analysis & Peer Review, and Blueprint Report Delivery) because that's what it takes to understand an environment well enough to give useful guidance.

8. How do you prioritize findings?

Every environment has dozens of things that could be improved. The question is: which ones actually matter? Look for a firm that ties findings to business risk, not just technical severity scores. A misconfigured admin account in a system that nobody uses is not the same risk as one in your billing platform, even if the technical vulnerability score is identical. If a firm can't explain how they prioritize, they'll hand you a list and let you figure it out. That's not useful.

Evaluating the output

9. Will the report include context, or just findings?

A list of findings without context is just a to-do list with no instructions. The report should explain why each issue matters, in terms a non-technical stakeholder can understand, and what happens if it's not addressed. If the report is written for an IT audience only, it won't drive the decisions that actually need to happen at the leadership level.

A list of findings without context is just a to-do list with no instructions. The report should explain why each issue matters, in terms a non-technical stakeholder can understand.

10. How are recommendations sequenced?

Remediation guidance that treats everything as equally urgent is guidance that nobody follows. Ask whether recommendations will be sequenced: what to do in the first 30, 60, 90 days, and what's a longer-term initiative. Ask whether they'll account for your budget cycle, your internal capacity, and any existing projects already in flight.

11. Will you explain the findings to our leadership team, not just our IT contact?

The value of an assessment doesn't end when the report lands in someone's inbox. The findings should be walkable — something you can sit through with your leadership team and understand without an IT background. If the firm only presents to your IT lead, the findings tend to stop there. A CISO-grade report your COO can't engage with doesn't actually change anything.

12. What does success look like six months from now?

This is the question that separates firms doing assessments from firms doing audits-for-hire. A good firm should be able to answer this with specifics: what metrics would change, what decisions would be better-informed, what risks would be reduced. If the answer is vague or circular ("you'd have a better understanding of your environment"), that's a signal.

A word on free assessments

Free assessments exist. Some are genuinely useful. MSPs often do a surface-level review during an onboarding process to understand what they're inheriting, and that's honest work. When we bring on a new client, we do a version of this: we need to understand your environment before we can support it well.

But a free, comprehensive assessment from a firm with no existing relationship and nothing else on the table almost always has a model behind it. The assessment is the sales process. That doesn't mean the findings are wrong (sometimes they're accurate), but it means the framing will push toward the outcome that closes a deal.

A free IT assessment from a firm you've never worked with almost always has a model behind it. The assessment is the sales process. Know what you're getting before you let someone inside your environment.

What a real assessment leaves you with

When an IT assessment is done right, you walk away with a clear picture of where your environment actually stands, not where a vendor wants it to stand. You have a prioritized set of recommendations you can act on, a roadmap you can take into your next budget conversation, and documentation you can hand to an auditor, a cyber insurance underwriter, or a new IT partner without embarrassment.

You also understand what you don't know: which gaps exist, which systems fall outside what was assessed, and what questions to ask next.

The best assessments don't just answer your current questions. They help you ask better ones.
// Start a Blueprint

Want a straight answer to a question you've been sitting on?

A Technology Blueprint is three to four weeks across four phases (Kickoff & Discovery, Scan & Data Collection, Analysis & Peer Review, and Blueprint Report Delivery). The output is yours to keep, prioritized, and mapped to risk reduction, cost savings, and efficiency gains.

Start a Blueprint
Written by Zachary Will
arrow_back All Insights