When you need an ITHC
PSN connection
Mandatory for Public Services Network access, annual renewal required
Ministry of Justice assurance
Required for justice sector service delivery
Board or audit committee request
Evidence-based security posture validation
Post-incident assurance
Comprehensive review after security events
Annual security validation
Periodic assessment of controls and configurations
Major system changes
Re-assessment when infrastructure changes significantly

What we assess in an IT Health Check
IT Health Checks are multi-phase assessments tailored to your organisation’s environment and assurance requirements. Depending on your scope, we assess:
- Internet-facing web servers and applications
- Email infrastructure and mail security controls
- VPN and remote access solutions
- Firewall configurations and external exposure
- Internal network segmentation and access controls
- Desktop and server security configurations
- Patch management effectiveness
- Wireless network security
- Active Directory and identity management controls
- Cloud environment configurations
Each assessment combines technical testing, vulnerability scanning, and configuration review to give you a complete picture of security posture and control effectiveness.


What you receive after your ITHC
Comprehensive report
Detailed risk ratings, evidence, scenarios and remediation steps.

Executive summary
Non-technical overview for boards and senior stakeholders.

Remediation roadmap
Prioritised action plan so you can focus on high-impact vulnerabilities first.
Post-assessment support
Debrief session for findings, technical questions and remediation support.

Why choose Citation Cyber?
CHECK-assured
Consultants hold NCSC CHECK credentials. ITHCs align to PSN Code of Connection requirements and government assurance standards.
Structured methodology
Approach combines technical testing, configuration review, and vulnerability analysis. Scope defined through PSN-aligned scoping questions.
UK-based security team
Work directly with our consultants – all UK-based, no outsourcing. Clear communication throughout engagement.
Pricing and engagement
ITHC pricing depends on scope complexity, number of systems, and environment size. Typical engagements range from five to ten days.

Our approach:
Initial scoping call to understand your environment
Detailed proposal with fixed scope and pricing
Testing scheduled around your operational requirements
Report delivery and debrief after test completion
Simple solutions to secure your business
Expert protection against cyber threats.
Penetration Testing
Identify risks with expert-led simulated attacks to protect your data and systems.
Cyber Essentials Certification
Achieve Cyber Essentials certification to defend against common threats, whatever your business size.
Employee Awareness Training
Empower your team to be your first line of defence with easy, interactive training.
Phishing Simulator & Bespoke Campaigns
Simulations to teach your staff how to spot and stop phishing scams easily.
Intelligent Monitoring & Vulnerability Scanning
Stay protected between pen tests with continuous scanning and real-time breach alerts.
Cyber Security Consultancy
Tailored advice for compliance, ransomware plans, and board-level cyber support.
Cyber Security Compliance
Simplify policies with NCSC-approved templates and hassle-free management tools.
Cyber Liability Insurance
Show insurers your safeguards and enjoy peace of mind with reduced premiums.
Common questions
Typical engagements are 5-10 days depending on scope and environment complexity. Testing is scheduled to minimise business disruption and doesn’t require downtime.
For PSN connection, there are specific requirements that must be met. Critical findings must be remediated before PSN approval. For non-PSN ITHCs, it’s risk-based assessment — not pass/fail — with prioritised remediation guidance.
PSN Code of Connection requires annual ITHC for continued network access. Many organisations conduct ITHCs annually or when systems change significantly.
ITHC is broad security posture assessment across external and internal systems, compliance focused. Penetration testing is deep adversarial testing of specific applications or infrastructure. ITHC provides breadth, pen testing provides depth.
Vulnerability scanning is automated tooling that identifies known vulnerabilities. ITHC includes vulnerability scanning plus manual penetration testing, configuration reviews, and assessment of security controls. More comprehensive than scanning alone.
We handle scoping through an initial call. You’ll need to provide network diagrams, system inventory, and access credentials via secure transfer. Our team coordinates directly with your IT staff for technical queries during testing.




