See the infrastructure risks before they become expensive
A focused point-in-time review of infrastructure risk, resilience, supplier dependency, and operational exposure for business clients that need an independent senior view.
Fixed-fee assessment
£3,750 fixed fee (exclusive of VAT)
Fixed-fee audit, payable 100% upfront. Exact scope, access requirements, assumptions, exclusions, and deliverables are confirmed in a Statement of Work.
Best used when
You need a clear baseline before approving spend, accepting supplier recommendations, planning technical change, or carrying infrastructure risk forward.
Keystone focuses on the infrastructure risks that affect resilience, supportability, supplier dependency, operational clarity, and future change. The output is designed to be understood and acted on.
What the audit is for
The Infrastructure Risk Audit gives leadership teams and internal IT teams an independent view of where infrastructure risk exists, what matters most, and what should be addressed next.
Risk visibility
Identify weak points, unclear ownership, resilience gaps, dependency risks, and operational exposure.
Supplier assurance
Understand where MSP, carrier, cloud, vendor, or third-party arrangements may create risk or ambiguity.
Decision support
Give senior decision-makers a clearer technical basis before committing budget, change, or risk acceptance.
What is reviewed
The exact scope is defined in the Statement of Work, but the audit can cover the areas where infrastructure risk commonly hides.
Core infrastructure
Network, connectivity, firewalls, routing, switching, VPN, remote access, and related infrastructure arrangements.
Resilience
Single points of failure, recovery assumptions, supportability concerns, ownership gaps, and operational exposure.
Suppliers
MSP, carrier, cloud provider, vendor, and third-party dependency risk, including unclear boundaries or responsibilities.
Change readiness
Planned changes, migrations, modernisation activity, technical direction, and the risks attached to current assumptions.
Typical deliverables
- Infrastructure risk summary.
- Prioritised findings and observations.
- Resilience and supportability concerns.
- Supplier dependency and ownership observations.
- Practical recommendations and next steps.
- Executive-level summary for leadership discussion.
What is not included
Unless specifically agreed in a Statement of Work, the audit does not include:
- Remediation or implementation work.
- Hands-on configuration changes.
- Formal penetration testing or application security testing.
- Continuous monitoring.
- Managed support, helpdesk, or service desk activity.
- Verification of every system, asset, vulnerability, or dependency.
How the audit works
The audit is structured to stay focused, proportionate, and useful.
Conversation
We discuss your infrastructure concerns, supplier context, known issues, and reason for the audit.
Scope
The Statement of Work defines audit scope, assumptions, exclusions, access needs, and deliverables.
Assessment
Keystone reviews the available evidence, documentation, dependencies, supplier inputs, and technical context.
Findings
You receive clear findings, prioritised risks, practical recommendations, and suggested next steps.
Point-in-time assessment
The audit is based on the information, access, documentation, interviews, observations, and evidence available during the audit period.
No guarantee every issue will be found
The audit does not guarantee that every issue, vulnerability, configuration problem, dependency, weakness, or risk will be identified.
Findings depend on available information
The quality of findings depends on the degree and quality of information provided and assessed, with collaboration required where clarification is needed.
Designed to support better decisions
The audit should be used as an informed senior infrastructure view, not as a guarantee that all possible risks have been discovered or removed.
Client responsibilities
- Provide accurate and timely information.
- Share relevant diagrams, documentation, supplier details, and known issues where available.
- Arrange access to appropriate people, teams, suppliers, or systems where needed.
- Clarify incomplete, unclear, or conflicting information.
- Confirm appropriate internal approval for information sharing and supplier involvement.
Commercial terms
- Fee: £3,750 fixed fee.
- Payment: 100% upfront for fixed-fee work.
- Scope: always defined in a Statement of Work.
- Expenses: normal and fair expenses are generally included unless outside a fair or reasonable amount.
- VAT: fees are exclusive of VAT where VAT is applicable.
Who it suits
- SMBs with limited senior infrastructure capability in-house.
- Leadership teams relying heavily on MSPs or suppliers.
- Internal IT teams that need an independent senior review.
- Organisations preparing for infrastructure change, supplier review, migration, or modernisation.
- Businesses that want risk visibility before approving spend or accepting supplier direction.
Why Keystone
Keystone provides calm, independent judgement. The audit is not designed to create fear, sell tools, or push a supplier-led solution.
The value is in seeing the risk clearly before it turns into downtime, cost, confusion, or avoidable technical debt.
Need an independent infrastructure risk view?
Start with a focused conversation about your current infrastructure concerns, supplier dependencies, resilience questions, or planned technical change.
Contact Keystone