Case study · Software & Technology
Security review closes 23 gaps at a tax advisory office in Höchst
A 16-person tax advisory office in Frankfurt Höchst received a perimeter scan, a configuration review and a prioritised fix list for €2,900.
A realistic, anonymised scenario showing what this engagement delivers. Not a client engagement.
Results
23, of which 5 high priority
Findings
from about 40% to 100% of accounts within 3 weeks
Multi-factor sign-in coverage
3 found and closed
Former-staff accounts still active
first ever, passed after one fix
Backup restore test
Situation
A tax advisory office in Frankfurt Höchst, 16 staff, about €1.9 million in annual revenue, holding payroll and bank data for roughly 400 client companies. The IT was looked after by a local provider on a monthly contract, and the office had no reason to doubt it. Then a client’s own auditor asked for evidence of the office’s security practice, and the partners realised they had none.
They did not want a certificate and could not use a 40-page penetration test report. They wanted to know whether the basics were in place, in a list they could hand to their IT provider.
Approach
The review at €2,900 covers four things: a scan of everything visible from the internet, a configuration review of the cloud tenant and the office network, a look at accounts, backups, access rights and update practice, and a fix list sorted by priority. Certified penetration testing is a separate service delivered by accredited partners and was not part of this engagement.
Week one: the external scan of the office’s domain, mail setup and two public IP addresses, then a half-day on site with read-only admin access to the Microsoft 365 tenant, the file server and the firewall. We checked which accounts had multi-factor sign-in, who could read which client folder, when the last update had been installed, and whether anyone had ever restored a file from backup.
Week two: a two-hour session with the partners and the IT provider on a video call, walking through every finding and agreeing who does what by when. The fix list names the finding, the risk in one sentence, the fix, the owner and a due date.
Result
In this scenario the review produced 23 findings, 5 of them high priority. Three accounts of former staff were still active, one with access to the whole client archive. Multi-factor sign-in was switched on for about 40% of accounts and off for the partners themselves. The nightly backup ran, and nobody had ever tested a restore, which failed on the first attempt because of a permissions setting and passed after the fix. Mail lacked the two records that stop others sending mail in the office’s name. Twelve workstations were more than 90 days behind on updates.
The IT provider closed the five high-priority items within three weeks and the rest within two months. The office now has a one-page statement of its security practice for client auditors and a review date in twelve months.
What it cost
€2,900 fixed price, quoted before the work started, for the perimeter scan, configuration review and prioritised fix list. Work by the client’s IT provider to close the findings, and any licence they add, are third-party costs excluded from the guarantee. The review is covered by our 100% money-back guarantee: full refund on request within 14 days of delivery, and for a monthly retainer the first month is refundable in full.
Every fixed-price engagement carries the 100% money-back guarantee. How the guarantee works →
Bring us your version of this
Describe your situation in a few sentences. You get a written proposal with scope and a fixed price, at no cost, and the guarantee is written into it.