Where to start
A wireless assessment, scoped for a small firm.
The wireless your staff and clients connect to every day is the easiest thing to overlook and one of the easiest ways in, sometimes from no closer than the parking lot. For most small practices, this is the assessment I'd recommend before anything bigger.
I look at every wireless network you're running, how they're separated, and what someone nearby could actually reach. Captured traffic gets triaged with AI-assisted tooling so I chase what matters first. I'm still the one deciding what's worth chasing. You get a plain-language report of what's exposed and what to close first, not a 60-page scan dump.
Radio doesn't travel over a VPN. How far past your walls the signal actually carries, whether the guest network is really separated from the one your files live on, whether there's an access point in a ceiling tile nobody remembers installing. Those get answered from inside the building, by someone standing in it.
It's also increasingly what your cyber insurer asks about. Underwriters now expect evidence that a firm has actually tested its environment, and a clean, documented assessment is something you can put in front of your broker at renewal.
Just as important: when a cyber claim gets denied, it's usually because a control the firm swore it had wasn't really in place. An assessment tells you what you actually have, not what you hoped you had.