Board-ready reporting on IT and cyber risk
We assess the foundations of your IT environment so you can work off a strong base with confidence.
So you can stop firefighting and focus on growing the business
Board-ready reporting on IT and cyber risk
We assess the foundations of your IT environment so you can work off a strong base with confidence.
Comprehensively assess eight critical domains
The Lumenas IT Check comprehensively assesses your tech and IT risk across eight critical domains. These are the fundamental building blocks of any IT environment, and require a clear allocation of responsibilities between the business and their external IT provider (MSP).
Infrastructure & Network
It’s like the wiring in a building. Nobody looks at it until the lights go out, or someone finds a way to plug into it who shouldn’t.
Business: sets direction on cloud adoption and reviews service quality.
MSP: keeps the technical backbone running day to day, for example making sure your internet connection, wifi and firewall are set up properly and someone’s watching for problems.
Strategy & Governance
It’s like the business’s financial plan for technology. You don’t need to know how the engine works, just where the money’s going, and be able to explain it when the board asks.
Business: owns budget, investment decisions, MSP contract governance and risk appetite.
MSP: gives technical input into your future plans and follows an agreed process before making changes, for example flagging when it’s time to replace ageing equipment or upgrade a system.
Compliance & Risk
It’s like a seatbelt: nobody wants to think about the crash, but if a regulator or an insurer comes asking, the business is the one who has to answer.
Business: owns compliance obligations, continuity planning and third-party risk decisions.
MSP: keeps the technical records that prove compliance when you’re asked, for example showing who accessed a system and when.
Applications & Systems
Sometimes a SaaS subscription can be a bit like an impulse buy shoved in a drawer. It looks harmless on its own, until you’re paying for six tools nobody uses and one of them has a key to your customer data.
Business: decides which applications and SaaS tools are used, and owns training.
MSP: keeps the software you use updated and secure, and manages changes carefully, for example installing a security update to your accounting software without breaking it.
Cybersecurity
It’s like the business’s immune system. It’s had to get more sophisticated because the threats have too, and it only takes one gap, one phishing email or one unpatched login, to put a small business offline for weeks.
Business: sets risk appetite, drives staff awareness, and decides on things like penetration testing and cyber insurance.
MSP: runs most of the day-to-day technical defences, for example the antivirus on your laptops, the spam filter on your email, and the alerts that flag anything suspicious.
Data & Backup
A backup is like the spare tyre you’ve never actually checked. Ransomware goes after backups first these days, so an untested one gives you nothing but false confidence.
Business: decides what data matters most and where it needs to reside.
MSP: runs the actual backups and checks they work, for example restoring a test file each month to prove your data could be recovered if it was ever lost.
People & Capability
It’s like owning the best car in the world and still needing a driver who knows where it’s going. This is the internal knowledge, culture and relationships that decide whether everything above actually gets used well.
Business: owns this domain almost entirely: internal capability, decision rights, culture and the MSP relationship.
MSP: writes up how systems work and gives staff a heads-up before something changes, for example letting everyone know ahead of a scheduled software update.
End User Computing
It’s like the front of house in a restaurant. It’s the only part of IT most staff ever see, helpdesk, laptops, patching, onboarding, so however good the kitchen is, this is what they’ll judge the whole business by.
Business: measures end-user satisfaction and is involved in onboarding and offboarding.
MSP: handles the everyday tech requests from staff, for example setting up a new starter’s laptop or fixing a printer through the helpdesk.
FAQs
How do I know if my MSP is doing these things?
You often don’t. That’s the point of the check: it compares what your MSP says they’re delivering against what you believe you’re getting, so any gap between the two shows up in black and white rather than staying a mutual assumption. The check also clears up genuine confusion. Your IT provider may simply not know you need something we include in the check, and running the process helps get everyone on the same page.
What if we don’t have the skills internally to do this work?
You don’t need technical skills to run the check. The survey is written in plain language, not IT jargon. Where you do lack internal capability, the report tells you clearly, so you can decide whether to build it, contract it out, or lean more heavily on your MSP for that domain.
Do we need to cover all eight domains equally?
No. Cybersecurity and data carry more risk for most businesses and deserve more attention than the rest. The check is designed to show you where to focus first, not to suggest every domain needs the same investment.
What happens if a responsibility falls to neither of us?
That’s the most common finding, and usually the most important one. When neither you nor your MSP is clearly accountable for something, it tends to stay unaddressed until it becomes a problem. The report flags these gaps specifically so you can assign an owner.
How often should we run the check again?
We suggest making that call after you’ve completed the check the first time. If it comes back clean, you probably don’t need to run it again for a while, or until something significant changes. But if the result leads to a change to your MSP agreement or how you operate internally, it’s worth repeating the check sooner to make sure everything’s on track, for instance in 12 months.
Will this create friction with our MSP?
Good MSPs welcome it. An independent check validates the work they’re already doing well and gives both sides a shared, objective reference point, instead of a conversation built on assumptions.
Executive education for accidental IT leaders
A free webinar series for the leaders who’ve inherited IT and cyber risk without a manual for it. It’s built to help you lead the conversation with your business and your MSP, not just sit in on it. Places are limited to keep the discussion useful.
Reserve your seatHow we prioritise your recommendations
Every recommendation in your report is ranked by expected impact, not by cost or technical complexity. Cybersecurity and data-related gaps come first, because a lapse there is the most likely to interrupt or seriously damage a business.
Fix first: cybersecurity & data
A lapse here is the most likely to interrupt or seriously damage a business, and most of these gaps are inexpensive to close once someone has pointed them out.
Then, where you’ll see the greatest benefit
We rank everything else by the size of the gap between where you are and where you should be, regardless of domain. Closing the biggest gaps first brings the whole business up to roughly the same level, instead of making one area excellent while others lag behind.
We provide prioritised recommendations to keep follow-up work manageable and ensure you get maximum benefit for the time spent on improvements.
Build confidence in your IT with an independent assessment
“Lumenas’ independent oversight gave us greater confidence in our governance of outsourced IT and technology support, while identifying focused opportunities for continuous improvement.”
Read the full customer story →
Board-ready reporting in under 30 minutes
Four simple steps, no technical expertise required. You’ll come away with a board-ready picture of your IT and cyber risk.
This provides the basis for your Managed Service Provider’s current scope of work. This step is optional.
A guided, plain-English questionnaire captures how your organisation experiences its IT today. No jargon, no preparation needed.
Your MSP answers their questionnaire, which includes technical considerations. Capturing both sides helps us provide you with a complete picture.
A board-ready report shows where you’re aligned, where the gaps are, and exactly what to fix first.