Independent Review
Independent IT Environment Review
A read-only review of how your technology environment is actually operated — risk, Microsoft 365 posture, backup and recovery, documentation, ownership, security controls and provider-transition exposure — producing written observations and a prioritized sequence of next actions. You keep the findings regardless of what you do with them.
Most organizations that ask for one are not unhappy with their current provider. The usual trigger is a question somebody outside the organization asked — a customer, an insurer, an auditor, an acquirer — that nobody internally could answer from records. This exists to answer that question honestly, including in the case where the honest answer is that the environment is in good order.
The Output
Eight areas, and what you actually receive for each
Stated as what is examined and what you get, never as what will be found. A review that promises adverse findings in advance is not a review.
Material risk observations
- What is examined
- Single points of failure, equipment past vendor end-of-support, undocumented dependencies, and concentration of knowledge or access in one person.
- What you receive
- A written list of observations, each with the condition that produces it — not a severity score generated by a questionnaire.
Microsoft 365 posture
- What is examined
- Privileged access and who holds it, MFA and Conditional Access coverage, external sharing and guest access, retention and audit-log configuration, licensing against actual use.
- What you receive
- Current-state findings against a documented baseline, with the gap stated in terms of what it would let happen.
Backup and recovery
- What is examined
- What is actually covered versus assumed, retention windows against your obligations, isolation of backups from the production administrative boundary, and whether a restore has ever been performed end to end.
- What you receive
- Coverage findings and the specific question of whether your stated recovery objectives are achievable with what currently exists.
Documentation
- What is examined
- Whether a current topology, asset register, IP plan, change history, access-review record and recovery runbook exist, and whether they describe the environment as it is now.
- What you receive
- A gap list against the published IT KORR operating standard, so the comparison is to a stated standard rather than to our opinion.
Ownership and accountability
- What is examined
- Who holds domain registration, tenant Global Administrator, licensing relationships, DNS, certificates and the backup platform — and whether your organization can reach each of them without a third party.
- What you receive
- An ownership map. This is the single most common finding, and the one organizations are most surprised by.
Security controls
- What is examined
- Endpoint protection coverage, patch currency, segmentation, administrative access review, and email authentication posture.
- What you receive
- Observed control coverage, stated as coverage rather than as a score. Where a control is absent, what it would ordinarily prevent.
Provider-transition exposure
- What is examined
- What would and would not transfer if your current arrangement ended — tooling licensed to the provider, backup history, documentation held in a provider-owned platform, and contractual notice terms.
- What you receive
- A transition-risk list. Useful whether or not you ever change provider, because it is the same list as your continuity exposure.
Prioritized next actions
- What is examined
- Everything above, sequenced.
- What you receive
- An ordered list of what to address first and why, including the items you can do yourself without engaging anyone — those are marked as such.
The documentation baseline used in area four is published in full — see the operating standard. You can read what will be looked for before agreeing to anything, which is the point of publishing it.
Boundaries
What this is not
Five things stated plainly, because every one of them is routinely blurred in this category.
- Not an audit, and not a certification. Nobody is certified at the end of this, and any provider telling you otherwise about a free review is describing something that is not an audit either. This produces observations against a documented baseline.
- Not an assessment against a named framework. If you need a SOC 2, HIPAA or NIST gap assessment, that is a different, scoped engagement and we will say so rather than approximating it here.
- Not a penetration test or vulnerability scan. No exploitation, no intrusive testing. This is a review of how the environment is operated and governed.
- Not conditional on switching provider. You keep the findings whether you engage IT KORR, take them to your current provider, or act on them yourself. That is what makes the word "independent" mean anything.
- Not a sales call with a report attached. If the honest finding is that your environment is well run and your current provider is doing the job, that is what the review says.
How It Runs
Five steps, nothing changed in your environment
A scoping conversation
What you actually want to know, what prompted the question, and which parts of the environment are in scope. Some reviews are whole-environment; many are triggered by one specific concern and should stay focused on it.
Read-only access, scoped and time-bounded
Reviewer-level visibility into what is being examined — typically a Microsoft 365 reader role, read access to monitoring or backup consoles, and whatever documentation exists. Nothing is changed, and access is yours to revoke.
Review against a documented baseline
The baseline is published, not proprietary. You can read what will be looked for before agreeing to anything.
Written findings
Observations by area, each tied to the condition that produces it, with the prioritized sequence at the end. Written down, not delivered verbally on a call you have to take notes during.
A conversation about the findings — optional
Useful, and not required. Some organizations want to walk through it; some want to read it and decide internally. Both are fine.
Before You Ask
Several of these questions you can answer yourself, today
The self-service assessments below run entirely in your browser and send nothing anywhere. Running one first makes a review better scoped, and sometimes makes it unnecessary.
Backup Readiness Assessment
Coverage, retention, isolation and restore testing.
Microsoft 365 Security Checklist
Identity, Conditional Access, mailbox security and backup.
Documentation Readiness
Whether the records an auditor asks for actually exist.
Disaster Recovery Readiness
Recovery objectives against actual tested capability.
Vendor Risk Assessment
Third-party inventory, due diligence and offboarding.
Operational Governance
Change control, configuration standards and asset governance.
FAQ
Common Questions
What is an independent IT review?
An independent IT environment review is a read-only examination of how an organization’s technology environment is operated and governed, performed by a party that does not currently run it. It produces written observations across risk, Microsoft 365 posture, backup and recovery, documentation, ownership, security controls and provider-transition exposure, with a prioritized sequence of next actions. It is not an audit and it is not a certification — it produces observations against a documented baseline, not an attestation.
Do we have to be unhappy with our current IT provider?
No, and most organizations asking for one are not. The common triggers are a customer or insurer asking for evidence nobody can produce, an acquisition or diligence process, a change of internal leadership, or simply having never had anyone outside the arrangement look at it. A review where the finding is "this is well run" is a useful outcome and we will say so plainly.
Does this require changing providers?
No. You keep the findings regardless of what you do with them — engage IT KORR, take them to your current provider as a work list, or act on them internally. A review that only produces value if you switch is not an independent review, and we would rather be the firm that says that than the firm that proves it the hard way.
What access does IT KORR need?
Read-only, scoped to what is being reviewed, and time-bounded. In practice that usually means a reader-level role in Microsoft 365, read access to monitoring or backup consoles where they exist, and whatever documentation is available. Nothing is changed during a review, no agents are deployed, and the access is yours to revoke at any point.
Will this interfere with our current provider?
It does not need to. Read-only access can be granted by your organization without the incumbent’s involvement, because the tenant and the environment belong to you rather than to them. Whether you tell them is your decision, and there are sensible reasons to go either way depending on what prompted the review.
Is this a security audit or a penetration test?
Neither. There is no exploitation and no intrusive testing. It is a review of how the environment is operated — what is configured, what is documented, who owns what, and what has been tested. If you need a penetration test or a formal framework gap assessment, those are separate scoped engagements and we will tell you that rather than approximating one here.
What do we receive at the end?
Written findings organized by the eight areas set out on this page, each observation tied to the condition that produces it, plus a prioritized sequence of next actions with the items you can address yourself marked as such. Not a score, and not a traffic-light dashboard — a score compresses away the reasoning, which is the part that is actually useful.
Can we run a self-assessment first?
Yes, and it is a sensible starting point. The free assessment tools on this site cover backup readiness, Microsoft 365 security, documentation readiness and several compliance frameworks, and they run entirely in your browser. They will tell you where your own uncertainty is, which makes a subsequent review better scoped and shorter.
Independent Review
Request an Independent IT Environment Review
Tell us what prompted the question and which parts of the environment matter. If a scoped self-assessment would answer it faster, we will point you at that instead.
No commitment required — we respond within one business day, or call (848) 200-9669 now.