Trustpilot Score 4.5

Speak to an expert 03333 233 981

Speak to an expert 03333 233 981

When you need an ITHC

PSN connection


Mandatory for Public Services Network access, annual renewal required

Ministry of Justice assurance  


Required for justice sector service delivery

Board or audit committee request 


Evidence-based security posture validation

Post-incident assurance 


Comprehensive review after security events

Annual security validation 


Periodic assessment of controls and configurations

Major system changes


Re-assessment when infrastructure changes significantly

What we assess in an IT Health Check

IT Health Checks are multi-phase assessments tailored to your organisation’s environment and assurance requirements. Depending on your scope, we assess:

External perimeter
  • Internet-facing web servers and applications
  • Email infrastructure and mail security controls
  • VPN and remote access solutions
  • Firewall configurations and external exposure

 

Internal environment
  • Internal network segmentation and access controls
  • Desktop and server security configurations
  • Patch management effectiveness
  • Wireless network security
  • Active Directory and identity management controls
  • Cloud environment configurations

Each assessment combines technical testing, vulnerability scanning, and configuration review to give you a complete picture of security posture and control effectiveness.

Abstract design featuring a vibrant gradient background with overlapping circuit patterns in orange and pink on a black backdrop.

What you receive after your ITHC

Comprehensive report

Detailed risk ratings, evidence, scenarios and remediation steps.

Executive summary

Non-technical overview for boards and senior stakeholders.

Remediation roadmap

Prioritised action plan so you can focus on high-impact vulnerabilities first.

Post-assessment support

Debrief session for findings, technical questions and remediation support.

Why choose Citation Cyber?

CHECK-assured

Consultants hold NCSC CHECK credentials. ITHCs align to PSN Code of Connection requirements and government assurance standards.

Structured methodology

Approach combines technical testing, configuration review, and vulnerability analysis. Scope defined through PSN-aligned scoping questions.

UK-based security team

Work directly with our consultants – all UK-based, no outsourcing. Clear communication throughout engagement.

Pricing and engagement

ITHC pricing depends on scope complexity, number of systems, and environment size. Typical engagements range from five to ten days.

Our approach:

1

Initial scoping call to understand your environment

2

Detailed proposal with fixed scope and pricing

3

Testing scheduled around your operational requirements

4

Report delivery and debrief after test completion

Simple solutions to secure your business

Expert protection against cyber threats.

Penetration Testing

Identify risks with expert-led simulated attacks to protect your data and systems.

Cyber Essentials Certification

Achieve Cyber Essentials certification to defend against common threats, whatever your business size. 

Employee Awareness Training

Empower your team to be your first line of defence with easy, interactive training.  

Phishing Simulator & Bespoke Campaigns

Simulations to teach your staff how to spot and stop phishing scams easily.

Intelligent Monitoring & Vulnerability Scanning

Stay protected between pen tests with continuous scanning and real-time breach alerts.

Cyber Security Consultancy

Tailored advice for compliance, ransomware plans, and board-level cyber support.

Cyber Security Compliance  

Simplify policies with NCSC-approved templates and hassle-free management tools.

Cyber Liability Insurance

Show insurers your safeguards and enjoy peace of mind with reduced premiums.

Defence Cyber Certification

Certify your cyber resilience to bid for MoD contracts, with expert support from readiness to certification.

Common questions

How long does an ITHC take?


Typical engagements are 5-10 days depending on scope and environment complexity. Testing is scheduled to minimise business disruption and doesn’t require downtime.

Is an ITHC pass/fail?


For PSN connection, there are specific requirements that must be met. Critical findings must be remediated before PSN approval. For non-PSN ITHCs, it’s risk-based assessment — not pass/fail — with prioritised remediation guidance.

How often should we conduct an ITHC?


PSN Code of Connection requires annual ITHC for continued network access. Many organisations conduct ITHCs annually or when systems change significantly.

What's the difference between ITHC and penetration testing?


ITHC is broad security posture assessment across external and internal systems, compliance focused. Penetration testing is deep adversarial testing of specific applications or infrastructure. ITHC provides breadth, pen testing provides depth.

What's the difference between ITHC and vulnerability scanning?


Vulnerability scanning is automated tooling that identifies known vulnerabilities. ITHC includes vulnerability scanning plus manual penetration testing, configuration reviews, and assessment of security controls. More comprehensive than scanning alone.

What preparation is required?


We handle scoping through an initial call. You’ll need to provide network diagrams, system inventory, and access credentials via secure transfer. Our team coordinates directly with your IT staff for technical queries during testing.