An MSP just emailed you offering a free network security assessment, which could be great, but before you hand over credentials to your firewall, you deserve to know whether you're getting a genuine vulnerability analysis or a 45-minute sales pitch dressed up in a PDF. Here's how to tell the difference before you let anyone onto your network.
In This Article
A "Free Assessment" Is Not Always an Assessment
Three distinct service types get called a "network security assessment," and they are not interchangeable. Knowing which one an MSP is actually offering, before the appointment, tells you almost everything about whether the engagement is built to help you or to close you.
The Three Tiers: Vulnerability Scan, Risk Assessment, Penetration Test
| Tier | What It Does | What You Get | Right for Louisville SMBs? |
|---|---|---|---|
| Vulnerability Scan | Runs automated tool (e.g., Nessus or Nmap) against your IP ranges to enumerate open ports and known CVEs | Raw findings list; no business context, no prioritization | Useful as one input, not as a standalone deliverable |
| Risk Assessment | Combines scan data with manual review of controls, access policies, and compliance exposure | Prioritized findings report mapped to your actual risk and regulatory obligations | Yes, this is what a pre-contract MSP evaluation should deliver |
| Penetration Test | Authorized simulated attack; attempts to exploit vulnerabilities to prove impact | Proof-of-exploitation report; scoped separately and priced accordingly | Useful after remediation, not as an entry-level assessment |
Most "free assessments" are a Nessus or Nmap scan output reformatted into a branded PDF. A raw vulnerability scan hands you a list of CVE numbers with severity scores. It does not tell you which finding will get you fined, which one an attacker is most likely to hit first, or what fixing it will cost. That gap is where the sales pitch lives.
When an MSP offers you a free network security assessment, ask them outright: "Is this a vulnerability scan, a risk assessment, or a penetration test?" If they hesitate or treat those terms as synonyms, that answer is enough.
What a Legitimate Network Security Assessment Actually Covers
A real network security assessment for a small business produces five concrete deliverables. Each one requires human judgment, not just automated tooling, and each one is routinely omitted from cut-rate scans.
The Five Deliverables a Real Assessment Must Include
- Asset Discovery (on-prem, cloud, and shadow IT): A scan that only touches your declared IP ranges misses cloud workloads, personal devices accessing company resources, and unmanaged SaaS accounts, the assets most likely to be exploited first. A real asset discovery phase enumerates all of these.
- Firewall and Access-Control Review: Automated scans do not read your firewall ruleset. A legitimate assessment includes manual review of inbound and outbound rules, network segmentation, and whether any rules have drifted from their original intent over time.
- Credential and Privilege Audit: This is the check that surfaces stale admin accounts, shared credentials, and over-privileged service accounts, a frequent cause of lateral movement after an initial breach. No scan tool catches this without a reviewer pulling Active Directory or Entra ID data.
- Patch-Gap Analysis: Beyond open ports, a patch-gap analysis identifies which operating systems, firmware versions, and third-party applications are running behind on security updates, and maps that gap to known active exploits.
- Written Risk-Prioritized Findings Report: This is the deliverable that separates a risk assessment from a scan. The report ranks findings by exploitability and business impact, not just CVSS score, and assigns a remediation roadmap with sequenced action items.
Generic MSPs hand buyers a templated scan report and call it an assessment. Argentum IT delivers a structured findings document mapped to your actual compliance exposure, HIPAA, PCI DSS, CMMC, or the CIS Controls v8 framework, so Louisville businesses know not just what is broken, but what it costs them to leave it broken. That is what managed cybersecurity services in Louisville should look like when the engagement starts, not just after you sign.
The Louisville-Specific Risks Most Assessments Miss
Generic national MSP assessments are scoped for a generic business. Louisville's dominant industries, healthcare, manufacturing, and logistics, carry compliance obligations and attack surfaces that surface-level scans are not designed to find.
Healthcare Vendor Ecosystem Exposure
Louisville's concentration of major health systems, Baptist Health, UofL Health, and Norton Healthcare, means a large share of local SMBs handle protected health information (PHI) as vendors, billing partners, or referral networks. Any business that touches PHI is subject to HIPAA compliance requirements, including the Security Rule's technical safeguard mandates. A scan that does not ask about your data flows with these health systems will not surface this exposure.
Manufacturing and Logistics OT/IT Convergence
Bourbon production, automotive suppliers, and third-party logistics firms in the Louisville area increasingly run operational technology (OT) (production line controllers, warehouse management systems, fleet telematics) on networks that were never designed to be connected to the internet. OT/IT convergence, the merging of these previously isolated operational systems with standard IT infrastructure, creates attack paths a standard Nessus scan will not enumerate. Defense contractors in the regional automotive supply chain also face CMMC supply-chain requirements that require assessment methodology beyond a port scan.
Remote-Work Endpoint Sprawl
The post-pandemic hybrid workforce left a long tail of endpoints (home routers, personal laptops used for VPN access, unmanaged mobile devices) that were provisioned quickly and never fully enrolled in device management. These endpoints rarely appear in a surface-level scan because they connect intermittently and may not be in scope for the assessor's declared IP ranges. A real assessment explicitly inventories remote endpoints and flags those outside your mobile device management (MDM) platform.
Seven Questions to Ask Any MSP Before the Assessment Begins
The questions you ask before an MSP touches your network tell you more than the report they hand you afterward. These seven questions are the ones a thorough provider answers without hesitation, and a sales-first provider will fumble.
- What scanning tools and methodology will you use? A credible answer names specific tools (Nessus, Nmap, Bloodhound for AD enumeration) and describes a manual review component. Red flag: "We use our proprietary platform" with no further detail.
- Will the report map findings to a recognized framework? Look for NIST CSF, the CIS Controls v8 framework, PCI DSS, or HIPAA. Red flag: "We use our own scoring system."
- Who owns the credentials and data collected during the assessment? You should. The MSP should have a written data-handling policy. Red flag: Vague answer, no written policy offered.
- Will you test both internal and external attack surfaces? External scanning covers your perimeter; internal scanning (run from inside your network or via agent) finds lateral movement paths. Red flag: "We scan your external IPs" — full stop.
- Does the report include a prioritized remediation roadmap? A findings list without sequenced action items is not a roadmap. Red flag: "We'll give you a full report and you can decide what to fix."
- What certifications do your assessors hold? Relevant credentials include CISSP (Certified Information Systems Security Professional), CEH (Certified Ethical Hacker), and CompTIA Security+. Red flag: No named certifications, or only vendor-specific credentials.
- How do your recommendations tie to an ongoing managed security engagement? A legitimate assessment surfaces findings that require sustained remediation: patch management, access control reviews, and endpoint monitoring. If the MSP cannot connect the assessment output to a defined ongoing service, ask yourself what you are actually buying. Your IT compliance services should start from the assessment findings, not restart from scratch six months later.
Not Sure If Your Last "Assessment" Actually Found Anything? Let's Find Out.
When you book Argentum IT's free 15-minute discovery call, we'll tell you exactly what a proper network security assessment for your Louisville business should cover and whether what you've already been shown holds up.
Book Your Free 15-Minute Discovery Call