Every network assessment we run follows the same underlying checklist, adapted to however many sites and how much infrastructure a business has. Sharing it here isn’t giving away the “secret sauce” — the value of an assessment isn’t the checklist itself, it’s having someone experienced actually run through it, verify findings, and tell you what matters most for your specific environment. But knowing what’s being checked helps you have a more informed conversation with any provider.

Wired Infrastructure

  • Switches: firmware version and patch status, default credentials, VLAN configuration and segmentation, spanning tree configuration, port security settings
  • Routers: routing table sanity, redundancy/failover configuration, management access restrictions
  • Firewalls: rule review (looking specifically for overly broad allow rules), logging configuration, firmware currency, whether the platform is still vendor-supported at all

Wireless Infrastructure

  • Encryption standard in use (WPA2 vs WPA3, personal vs enterprise)
  • SSID segmentation — are guest, IoT, and corporate networks actually isolated, or just labeled differently on paper
  • Access point firmware and default credential status
  • Signal coverage and rogue access point detection

WAN and Connectivity

  • Number and type of internet circuits per site
  • Failover behavior — does secondary connectivity actually activate automatically, or does it require manual intervention
  • Site-to-site VPN configuration and encryption standards
  • Bandwidth utilization trends versus available capacity

Physical Security (On-Site Sites Only)

  • Physical access to network closets and server rooms
  • Whether unmanaged or unauthorized devices are present
  • Cable management and labeling — not cosmetic, since poor labeling directly slows down incident response

Documentation and Asset Inventory

  • Does a current network diagram exist, and does it match reality
  • Is there a maintained asset inventory with owner, location, and firmware version for every device
  • Change management process — is there any record of what’s been modified and when

Logging and Monitoring

  • Centralized logging coverage across switches, routers, and firewalls
  • Alerting thresholds for the events that actually matter (not just volume-based noise)
  • Retention period versus what’s needed for incident investigation or compliance

What Makes This Different From a Checklist You Run Yourself

The checklist is the easy part to publish. What’s harder to replicate internally is context — knowing that a particular firewall rule looks fine in isolation but becomes a critical issue combined with the VLAN configuration two steps earlier, or recognizing that a “temporary” default credential has actually been in place for three years based on the last configuration change timestamp. That pattern recognition is what a third-party assessment adds beyond a self-audit.

Want to see how these checklist items translate into an actual findings report? Our sample network assessment report walks through real (fictionalized) examples of each category above.