Infrastructure Risk Audit

See the infrastructure risks before they become expensive

A focused point-in-time review of infrastructure risk, resilience, supplier dependency, and operational exposure for business clients that need an independent senior view.

Fixed-fee assessment

£3,750 fixed fee (exclusive of VAT)

Fixed-fee audit, payable 100% upfront. Exact scope, access requirements, assumptions, exclusions, and deliverables are confirmed in a Statement of Work.

Best used when

You need a clear baseline before approving spend, accepting supplier recommendations, planning technical change, or carrying infrastructure risk forward.

A practical risk view, not a generic checklist.

Keystone focuses on the infrastructure risks that affect resilience, supportability, supplier dependency, operational clarity, and future change. The output is designed to be understood and acted on.

What the audit is for

The Infrastructure Risk Audit gives leadership teams and internal IT teams an independent view of where infrastructure risk exists, what matters most, and what should be addressed next.

Risk visibility

Identify weak points, unclear ownership, resilience gaps, dependency risks, and operational exposure.

Supplier assurance

Understand where MSP, carrier, cloud, vendor, or third-party arrangements may create risk or ambiguity.

Decision support

Give senior decision-makers a clearer technical basis before committing budget, change, or risk acceptance.

What is reviewed

The exact scope is defined in the Statement of Work, but the audit can cover the areas where infrastructure risk commonly hides.

1

Core infrastructure

Network, connectivity, firewalls, routing, switching, VPN, remote access, and related infrastructure arrangements.

2

Resilience

Single points of failure, recovery assumptions, supportability concerns, ownership gaps, and operational exposure.

3

Suppliers

MSP, carrier, cloud provider, vendor, and third-party dependency risk, including unclear boundaries or responsibilities.

4

Change readiness

Planned changes, migrations, modernisation activity, technical direction, and the risks attached to current assumptions.

Typical deliverables

  • Infrastructure risk summary.
  • Prioritised findings and observations.
  • Resilience and supportability concerns.
  • Supplier dependency and ownership observations.
  • Practical recommendations and next steps.
  • Executive-level summary for leadership discussion.

What is not included

Unless specifically agreed in a Statement of Work, the audit does not include:

  • Remediation or implementation work.
  • Hands-on configuration changes.
  • Formal penetration testing or application security testing.
  • Continuous monitoring.
  • Managed support, helpdesk, or service desk activity.
  • Verification of every system, asset, vulnerability, or dependency.

How the audit works

The audit is structured to stay focused, proportionate, and useful.

1

Conversation

We discuss your infrastructure concerns, supplier context, known issues, and reason for the audit.

2

Scope

The Statement of Work defines audit scope, assumptions, exclusions, access needs, and deliverables.

3

Assessment

Keystone reviews the available evidence, documentation, dependencies, supplier inputs, and technical context.

4

Findings

You receive clear findings, prioritised risks, practical recommendations, and suggested next steps.

Point-in-time assessment

The audit is based on the information, access, documentation, interviews, observations, and evidence available during the audit period.

No guarantee every issue will be found

The audit does not guarantee that every issue, vulnerability, configuration problem, dependency, weakness, or risk will be identified.

Findings depend on available information

The quality of findings depends on the degree and quality of information provided and assessed, with collaboration required where clarification is needed.

Designed to support better decisions

The audit should be used as an informed senior infrastructure view, not as a guarantee that all possible risks have been discovered or removed.

Client responsibilities

  • Provide accurate and timely information.
  • Share relevant diagrams, documentation, supplier details, and known issues where available.
  • Arrange access to appropriate people, teams, suppliers, or systems where needed.
  • Clarify incomplete, unclear, or conflicting information.
  • Confirm appropriate internal approval for information sharing and supplier involvement.

Commercial terms

  • Fee: £3,750 fixed fee.
  • Payment: 100% upfront for fixed-fee work.
  • Scope: always defined in a Statement of Work.
  • Expenses: normal and fair expenses are generally included unless outside a fair or reasonable amount.
  • VAT: fees are exclusive of VAT where VAT is applicable.

Who it suits

  • SMBs with limited senior infrastructure capability in-house.
  • Leadership teams relying heavily on MSPs or suppliers.
  • Internal IT teams that need an independent senior review.
  • Organisations preparing for infrastructure change, supplier review, migration, or modernisation.
  • Businesses that want risk visibility before approving spend or accepting supplier direction.

Why Keystone

Keystone provides calm, independent judgement. The audit is not designed to create fear, sell tools, or push a supplier-led solution.

The value is in seeing the risk clearly before it turns into downtime, cost, confusion, or avoidable technical debt.

Need an independent infrastructure risk view?

Start with a focused conversation about your current infrastructure concerns, supplier dependencies, resilience questions, or planned technical change.

Contact Keystone