Originally adapted from The Technology Press. Substantially reviewed and updated 15 September 2026.
A report is the start of the work
A useful security review explains what was examined, against which criteria and with what evidence. It should help your business decide what to fix first and how to confirm the improvement.
An assessment, penetration test and formal audit serve different purposes. Agree the scope and any independence requirements before work begins. A general review is not a certification or a guarantee that an incident cannot occur.

Agree the systems, risks and criteria.
Before the reviewShow how the finding was established.
During the reviewAssign ownership and verify the fix.
After the reviewPractical checkpoints, not a guarantee of security or compliance.
What to check
Set the question
Start with the business decisions the review should support.
What to check
Identify important services, sensitive information, dependencies and required standards. Record exclusions so nobody assumes untested systems were covered.
Collect useful evidence
Look beyond whether a tool has been purchased.
What to check
Check implementation, coverage and operation. Evidence may include settings, access reviews and recovery exercises. Handle sensitive findings through an agreed secure channel.
Close the loop
Turn findings into a prioritised improvement plan.
What to check
Assign an owner and target date, document accepted exceptions and retest significant changes. Review whether the risk has actually reduced, not just whether a ticket is closed.
Sources & further reading
Make the next step practical
Talk to ITFR about your business, priorities and the controls that fit.









