Recommendations Before Licenses: How a Fixed-Scope Cyber Health Check Should Work


Too many “security conversations” with small Philippine teams start with a license quote. That order is backwards. If you do not yet know which devices exist, whether MFA is on for finance mailboxes, whether a restore has been tested, or who still has admin rights after a freelancer left, buying another endpoint product will not fix the underlying gaps — it will only add another console nobody watches.

This Insights piece explains how a fixed-scope cyber health check should work at ARA Industries: inventory and posture first, written recommendations second, and only then an optional conversation about WithSecure Elements if a unified control plane fits. Method over theater. Recommendations before licenses.

What does a fixed-scope cyber health check include?

A fixed-scope check reviews five areas: device inventory, identity and email (MFA and offboarding), backups and tested restore, admin access, and SaaS or incident basics. You get Green, Yellow, Red findings and written recommendations prioritised for a 20–40 seat reality. Boundaries are agreed before work starts, and licences are discussed only afterwards — never as the deliverable.

Who this method is for

Use this framing if you run (or advise) a local organization with roughly 20–40 people on endpoints — clinics and outpatient practices, law / CPA / professional firms, creative or digital agencies, logistics or dispatch offices, and lean schools or learning centers.

Typical fit: enough surface area to matter; lean or outsourced IT; real consequences if email, files, or a shared PC goes wrong; budget that can buy a scoped review and a sensible next step.

Not the primary fit: banks and heavily regulated institutions with dedicated security teams; large BPOs with 100+ seats and an existing SOC or MSSP (see enterprise cybersecurity architecture); teams that already have a full program and only want a vendor bake-off.

Why fixed scope matters

Small teams abandon open-ended “assessments” that sprawl for weeks. A fixed-scope health check should tell you, up front:

  • What we will look at
  • What we will not look at
  • What you receive in writing
  • How product talk is sequenced (after recommendations)

That clarity is part of the product. You should know the boundary before work starts.

What we review (the five spines)

ARA’s SME health-check spine mirrors the workbook we publish for self-assessment. In a paid review, we walk these areas with whoever owns IT or ops — evidence-led, practical language, Philippine lean-IT constraints in mind.

1. Inventory (endpoints and who uses them)

You cannot protect what you cannot name. We establish a rough but honest picture of company devices, shared machines, and BYOD that touches company email or files. We look for “we think antivirus is on” without a reporting console, shared logins that erase accountability, and contractor access that never ended.

Outcome: a named fleet picture — not a perfect CMDB theater piece.

2. Identity and email posture

For 20–40 seat PH teams, email is often the front door for fraud and account takeover. We check MFA for admins and for users who touch finance or sensitive systems; ownership of shared mailboxes; offboarding habit; and whether staff have a path to report suspicious mail. Ambient threat volume in the Philippines is real enough that identity hygiene is not optional — Kaspersky findings covered by Newsbytes (15 April 2025) put PH business ransomware detections in the regional top three for 2024 — but we do not lead this conversation with breach logos. We lead with your MFA and offboarding reality.

Outcome: clear Green / Yellow / Red on identity, with near-term fixes called out first.

3. Backups and recovery

Security without recovery is incomplete. We ask the recovery question in plain language: If something bad hits Tuesday morning, what do we restore by Wednesday? We look for named critical data locations, a known backup schedule, an offline or hard-to-reach copy, and whether anyone has tested restore in the last year — even a small file test. Backup credentials that match everyday admin are a common Red.

Outcome: a recovery gap list you can act on without waiting for a new license.

4. Admin access and privilege

Privilege concentrates in small orgs — often in one inbox and one laptop. We want a named list of people with admin rights across Microsoft 365 / Google, firewall, and hosting; separation of admin from everyday email where practical; and vendor remote-access tools that are known and limited. Former freelancers still on VPN or hosting panels are a recurring Red flag.

Outcome: a one-page admin truth, plus revocations you can explain in one sentence.

5. SaaS and “who do we call?”

Most teams this size run on SaaS. We want a core SaaS list, clarity on who can invite guests or share links, and a half-page incident basics card: primary contact, backup contact, first-hour actions, and offline emergency contacts for banks and payment gateways. You do not need a 40-page incident response plan. You need a phone tree that works when email is the outage.

Outcome: SaaS inventory marks plus a usable first-hour card.

What is in scope vs out of scope

In scope (typical paid health check):

  • Conversation and review across endpoints, identity/email, backups, admin access, and incident basics / SaaS hygiene
  • Traffic-light style findings (Green / Yellow / Red) tied to your environment
  • Written recommendations prioritized for a 20–40 seat reality — what to fix now vs later
  • Clear next-step options, including “do these three things yourselves” when that is the honest answer

Out of scope (unless separately agreed):

  • Full penetration testing or red-team exercises
  • Regulatory certification audits (ISO, PCI, and similar)
  • Bank / insurer / large-enterprise SOC design
  • Endless re-scoping into every SaaS curiosity without a boundary
  • A forced product purchase as the “deliverable”

Exact commercial package, fee, and seat band for your quote: [NEED AARON].

Where WithSecure Elements fits (after recommendations)

After the written recommendations, some teams want one sensible control plane for endpoints and related protections instead of five overlapping tools. That is when we discuss WithSecure Elements — modular pieces, partner-supported deployment, aimed at fleets like yours rather than bank-scale SOCs.

Elements is optional. The health check earns its fee whether or not you adopt it. It does not replace MFA discipline, tested backups, or an admin list. It is not a substitute for knowing your gaps.

ARA’s Elements practice is book-building honest: we lead with method and scoped recommendations, not borrowed logos we do not have. Public capability overview stays at the vendor’s own materials; we do not invent module pricing in Insights copy.

What you should expect from us — and what we will not do

Expect: evidence-led language; recommendations before product; regional awareness of lean IT and mixed devices; clear in/out scope before work starts.

We will not: pretend we have a wall of closed logos we do not have; push unrelated digital marketing services into a cyber conversation; oversell “enterprise XDR theater” to a 25-seat clinic or firm; use seminar or webinar registration as the next step.

Schedule an exploratory call with us if you think we are able to take care of this part of your business – USAP TAYO