The request came in like so many others: “We need a proposal to manage our infrastructure.” What we found was not what the client expected to hear. But it was exactly what they needed to know.
The initial engagement
A 45-employee professional services firm contacted us to explore outsourcing their IT support. Their previous provider had stopped responding with the same agility as the early years. Before signing any contract, we proposed a technical audit. Without an audit there is no baseline, and without a baseline there is no way to measure whether the work we do generates real value. The client agreed.
What we found in the first four hours
The first finding: 1 TB of SharePoint storage with no productive use — duplicate files, outdated document versions, folders from projects completed three years ago left unarchived. The company was paying Microsoft 365 licenses for that storage without using or managing it properly. The second finding: external backups configured by the previous provider 18 months earlier had been silently failing for eleven months. Eleven months of critical data without verified backup.
The other layers of the problem
- 17 active user accounts belonging to people who no longer worked at the company, three with access to SharePoint and internal systems.
- Two machines running Windows 7 connected to the corporate network, without Microsoft support since January 2020.
- The perimeter router had factory firmware from 2021 with no updates. The admin interface was accessible from the internet with default credentials.
- No network segmentation: guest WiFi, employee laptops, and internal servers were all on the same subnet.
How companies get to this point
The client was not negligent. They had an IT provider. They paid monthly support. But without periodic audits, the relationship had become “we call when something breaks.” Many of the most serious vulnerabilities do not manifest as visible failures until it is too late.
The remediation plan
The audit report included findings classified by criticality, estimated impact, and remediation cost. The most urgent actions — the exposed router and the active accounts of former employees — were resolved within 48 hours. The complete plan was executed in 60 days.
How long has it been since your infrastructure had a formal technical review? AVN Networks conducts technical audits with executive report and prioritized remediation plan. Request yours today.