Network Assessment  ·  Texas

Network Assessment for Texas Businesses

A network assessment is a documented review of every device, link and rule on your network, delivered as a ranked findings report you keep. Uprite runs one at no charge for Texas businesses.

Read-only throughout. Nothing on your network changes while we are looking at it. The report is yours whether the fixes come to us or not.

Book a Network AssessmentSee Network Security Services

Serving Texas Business Since 1999  |  Sub-10-Minute Triage SLA  |  Houston · Dallas · San Antonio · Austin

Book Your Network Assessment

Recognized Across Texas for Managed IT, Networking and Security

The Data

What an Assessment Finds Is Usually Years Older Than the Business Expects

Owners brace for something dramatic. A clever new attack, a zero day, a thing nobody could have seen coming. That is almost never what turns up. What we find is normally a switch nobody has logged into since 2019, a firewall running firmware two major versions behind, and a VPN account belonging to somebody who left. Old. Boring. Still open. And documented nowhere.

We can put a number on how old. We pulled CISA’s Known Exploited Vulnerabilities catalog on 8 September 2026, catalog version 2026.09.04, and filtered its 1,695 entries down to the 323 that live in firewalls, VPN gateways, routers, switches, wireless controllers and network storage. Then we compared the year each vulnerability was published against the year CISA actually flagged it as exploited.

How old the flaw was when CISA listed itPerimeter entriesShare of the 323
Same year the CVE was published14845.8%
One year later4814.9%
Two to four years later7824.1%
Five years or more later4915.2%
All perimeter entries323100%

Read those bottom rows again. For 127 of the 323, two full years or more passed between the vulnerability being public and CISA confirming somebody was using it. The record holder is a Cisco IOS flaw published in 2008 and added to the catalog on 13 July 2026, eighteen years later. Eighteen. In every one of those cases the exposure sat in somebody’s comms room the whole time, patchable, unpatched, and invisible because nobody had a current list of what was in the rack.

127 of the 323 perimeter entries in CISA’s catalog were confirmed as exploited two or more years after the vulnerability went public. The median deadline CISA then gives federal agencies to fix one is 21 days, and 104 of the 323 carry a deadline of 14 days or less. You cannot hit a 14-day clock on hardware you have not counted.

None of this is an enterprise-only problem. 92 of those 323 entries sit in gear a 40-person company buys without thinking twice: D-Link, SonicWall, Zyxel, QNAP, TP-Link, DrayTek, Ubiquiti. Roughly one in four of the 323 is flagged for known ransomware use. And the pace has not slowed, with 40 of the 211 entries CISA added during 2026 landing in network equipment. Those deadlines come from CISA Binding Operational Directive 26-04, which binds federal agencies rather than your business, but insurers and auditors increasingly quote the same clock. The hardware is ordinary. The exposure is not.

Definitions

Assessment, Audit and Penetration Test Are Three Different Purchases

These three words get used as if they were interchangeable. They are not. The price gap between them is large. A network health check, by the way, is the same product as an assessment wearing a friendlier name. So is an IT network assessment. Before you accept any quote, get the provider to say which of the three they are actually selling you.

Quickest way to tell them apart: ask what lands on your desk at the end. Three different documents. Three different jobs.

Network assessment

An assessment answers what have I got and where is it weak. We inventory every device, pull the firewall rule set, map what can reach what, check firmware against known exploited vulnerabilities, and walk the wiring closets. Nothing is attacked and nothing is changed. Out comes a diagram, an asset register, a ranked list of findings and a costed plan. This is the one most Texas businesses actually need first, and the one we run at no charge. Start there.

Network audit

An audit answers a narrower question: does this network match a written standard. The standard might be HIPAA, PCI DSS, CMMC, a cyber insurance application or your own policy document. An auditor is not looking for the best design. They are looking for evidence against a checklist, and they will fail you for a missing document even where the technical control is sound. Evidence, not elegance. An assessment usually has to happen first, because you cannot evidence a control on a device you have not inventoried.

Penetration test

A penetration test answers can somebody get in, by trying. A tester actively exploits what they find, which means scope, timing and a signed authorization letter all matter. It is genuinely valuable and it is a separate paid engagement, typically several thousand dollars. Booking one before an assessment is the expensive way round. Order matters. You pay a specialist to discover the unpatched firewall a free inventory would have handed you in week one.

Network architect comparing a discovered network topology map against an annotated floor plan

What Is Included

The Eight Things a Network Assessment Actually Checks

Eight items. This is the whole scope, written out, so you can hold a competing quote next to it. Each one below is followed by the kind of finding it usually produces, because a scope list on its own tells you very little.

Every device, counted

Active and passive discovery across every subnet, cross-checked against DHCP leases and a physical walk of the comms rooms. Typical finding: a client expects 180 devices and we document 240. Those extra 60 are printers, cameras, a door controller, two forgotten access points and somebody’s home router bridged onto the office LAN. That gap is normal.

Firmware age and end-of-support dates

Every internet-facing device checked against its vendor’s advisories and against the CISA catalog above, with the manufacturer’s end-of-support date recorded next to it. Typical finding: a FortiGate or SonicWall still passing traffic three years after the vendor stopped shipping security updates for it.

Firewall rules, read line by line

The full rule set exported and read, not summarized. We flag any-any rules, rules with no comment, rules referencing hosts that no longer exist, and port forwards nobody can explain. Typical finding: an RDP port forward opened for a 2021 project, still live, pointed at a decommissioned server’s old IP. Nobody remembers approving it.

Remote access and who holds it

Every VPN account, every remote support tool, every vendor tunnel, checked for multi-factor authentication and matched against your current staff list. Typical finding: active credentials belonging to two people who left, plus a permanently open tunnel for a line-of-business vendor nobody in the building can name.

What can reach what

The real segmentation, tested rather than assumed. We check whether guest Wi-Fi truly reaches nothing, whether a workstation can open a management port on a switch, and whether clinical or plant equipment shares a VLAN with the front desk. Typical finding: one flat broadcast domain wearing four VLAN names. Names are not boundaries.

Switch ports, wireless and capacity

Port utilization, uplink saturation, PoE budget, spanning tree health, wireless channel overlap and access point density against floor plan and headcount. Typical finding: a single gigabit uplink carrying a whole floor, and the complaint people describe as “the internet is slow” turning out to be a saturated switch stack.

Outbound traffic and DNS

Where your network talks to when nobody is watching. Resolver configuration, outbound port policy, and a review of destinations against newly registered and known malicious domains. Typical finding: every device on the network resolving DNS through a consumer service with no filtering and no logging.

What is documented, and what is not

Existing diagrams, IP schemes, credential storage, warranty and support contract status, backup coverage for network configs. Typical finding: the only network diagram is four years old, drawn by a provider who no longer holds the contract, and the firewall admin password lives in one person’s head. Ask who else knows it.

The Money

What It Costs, and Exactly Where Free Stops

Our network assessment is free. That deserves an explanation rather than an exclamation mark, because free assessments have a deserved reputation for being a scan and a sales call. Here is precisely what is included at no charge, and where the line sits.

  • Discovery and inventory. Every device found, identified, and recorded with model, firmware version and end-of-support date.
  • Firewall and remote access review. Full rule set read by an engineer, remote access accounts reconciled against your staff list.
  • The four documents. Network diagram, asset register, ranked findings list and a costed remediation plan. Yours to keep.
  • A walkthrough. An hour with the engineer who did the work, not a salesperson reading the summary page.

Where free stops

Three things sit outside it, and we would rather say so here than in a meeting. A penetration test is a separate paid engagement, because it involves active exploitation and a different skill set. A formal compliance audit against HIPAA, PCI DSS or CMMC is separate too, since that is evidence-gathering against a standard rather than a technical review. And the remediation work is quoted, because fixing a network takes engineer hours and sometimes new hardware. That is the whole list.

Our remediation quote is itemized by finding, so you can hand it to another provider or to your own IT person and have them do the work. Take it elsewhere if you like. Plenty of clients do exactly that with the low-hanging items and bring us in for the awkward ones. If you would rather see what an ongoing arrangement costs before you book anything, our Texas managed IT pricing page carries real numbers, and network security services covers what continuous management of the layer looks like.

The honest test of a free assessment is whether the report survives you saying no. Ours does. You keep the diagram, the asset register, the findings and the costed plan whether the remediation comes to us, goes to somebody else, or sits in a drawer until budget season.

See Managed IT Pricing in Texas

The Timeline

How Long a Network Assessment Takes

Anybody promising a complete assessment by Friday afternoon is selling you an automated scan. A scan is a component, not the product. The ranges below are what the work genuinely takes, measured from the scoping call rather than from the contract date. They are typical durations, not a contractual commitment, and the variable that moves them most is not user count. It is site count. Plan around that.

What your network looks likeTypical discovery windowReport and walkthrough
One site, under 50 users, a single firewall3 to 5 business daysInside 2 weeks of the scoping call
One site, 50 to 250 users, several VLANs1 to 2 weeksInside 3 weeks
Two to five sites joined by site-to-site VPN2 to 3 weeksInside 4 to 5 weeks
Six or more sites, or a plant or clinical network3 to 4 weeksInside 6 weeks

Two things stretch a timeline in practice, and neither is technical. One is access. If nobody currently holds the firewall admin credentials, recovering them from a previous provider can take longer than the entire assessment. Start that early. The other is the site walk. A manufacturing floor in Houston or a multi-building campus in San Antonio needs somebody physically in the room with a torch and a clipboard, and that has to be scheduled around production. Tell us on the scoping call and we plan around both. For the wider picture of what a full engagement looks like after the assessment, see network security services.

The Deliverables

The Four Documents You Receive, and the Walkthrough

Ask any provider what you will be holding when the assessment finishes. Most say “a report”. Ask for specifics. Here is ours, and it is worth knowing that these map directly onto published CIS Critical Security Controls safeguards, so the paperwork does double duty at your next insurance renewal.

The network diagram

A current logical and physical diagram: every firewall, switch, access point, server and site link, with VLANs and trust boundaries drawn in. Delivered as a PDF and as the editable source file, because a diagram you cannot update is a diagram that is wrong in six months. This is CIS Safeguard 12.4, Establish and Maintain Architecture Diagrams. Most businesses we assess have never had one. Not one.

The asset register

A spreadsheet, one row per device. Model, serial, firmware version, IP, physical location, warranty status, vendor end-of-support date and owner. Sortable. This is CIS Safeguard 1.1, Establish and Maintain Detailed Enterprise Asset Inventory, and it is the document that makes every later security decision cheap instead of speculative.

The ranked findings list

Every finding written as a plain sentence, then ranked by exploitability and blast radius rather than by a vendor severity score. Each row carries what we found, where, why it matters here specifically, and what fixing it involves. A typical single-site report runs 20 to 40 findings. No padding. Usually three or four are urgent, a dozen matter this quarter, and the rest are housekeeping.

The remediation plan, with prices

Findings turned into a sequenced plan, with hours and hardware costed line by line and split into what to fix this month, this quarter and this year. It is itemized deliberately. Take the whole thing to another provider if you want to, or hand the easy half to your internal IT person and only pay for the rest.

The walkthrough

An hour, with the engineer who actually did the work. Not a salesperson reading the executive summary aloud. Bring questions. Bring whoever signs off on IT spend and whoever answers the phone when it breaks, because those are usually different people and they need to hear the same version. We record it if you want it recorded.

IT consultant walking a Texas business owner through the ranked findings list in a printed network assessment report

Everything above is yours on delivery, in editable formats, with no watermark and no clause that says it stays ours. We take over existing networks regularly and we know how often a previous provider held the diagram hostage. That is a business model we have no interest in copying.

How It Runs

Five Steps, and What We Need From You at Each One

Nobody wants strangers plugging things into their network. Fair enough. So here is the sequence in full, including the parts that need you, because the third column is where assessments actually stall. Read-only throughout steps one to three. We change nothing without a written approval.

StepWhat happensWhat we need from you
1. Scoping callThirty minutes. Sites, rough user count, firewall brand, what is already hurting, and who owns which credentials.One person who knows how the business runs. Not necessarily technical.
2. Read-only accessA read-only account on the firewall and switch stack, plus a temporary collector on the LAN for passive discovery.Read-only credentials, and a named contact for questions.
3. Discovery and site walkPassive and active discovery, firewall rule export, wireless survey, then a physical walk of every comms room and closet.Building access, and a window that does not clash with production.
4. Analysis and draftingFindings verified by hand, ranked, and written up. Firmware cross-checked against CISA and vendor advisories.Nothing. This part is on us.
5. WalkthroughOne hour with the engineer. Findings explained, priorities agreed, remediation plan handed over.An hour, and whoever signs off on IT spend.

That collector in step two is worth a word, because it is the part people ask about. It listens. That is all it does. It does not scan aggressively, it does not touch production servers, and it comes off the network the day discovery ends. On networks with fragile legacy equipment, a clinical imaging system or an older PLC on the plant floor, we run discovery entirely passively and say so up front, which adds a few days and removes the risk argument completely. That caution is the same one we apply to live managed security operations.

Technician photographing a wiring closet and recording firmware versions during a network assessment site walk

Who It Fits

Who Should Book a Network Assessment

Book one now

Something has already told you the network is the problem. Repeated slowdowns nobody can explain. A firewall past its support date, or one whose brand nobody in the building is certain about. A provider who has gone quiet, or an internal IT person who just resigned and took the passwords with them. Wi-Fi that drops in the same corner every day. A cyber insurance form asking whether remote access sits behind multi-factor authentication, and nobody being sure of the answer. Any one is enough.

Book one before you sign

You are about to commit money. Facts first. A new lease, a second office, a plant expansion. An acquisition where you inherit somebody else’s network and nobody has looked at it yet. A proposal from an IT provider quoting hardware you cannot verify you need. A HIPAA, PCI DSS or CMMC deadline where the auditor will ask for an asset inventory on day one. An assessment costs you an hour and a set of read-only credentials, and it turns every one of those conversations into a factual one.

If the assessment finds your network in good shape, we will say so plainly and the report will be short. Short is fine. That happens more often than the industry admits, and it is a perfectly good outcome. We would rather write a two-page report and earn the next conversation than manufacture urgency for a business that does not have any. The same reasoning drives how we scope managed IT across Texas.

What Clients Say

★★★★★4.8Houston · 60 reviews★★★★★4.9San Antonio · 44 reviews
★★★★★

Hector and Kareem are super helpful! They are always willing to take on my computer problems even if its small. I had my mouse disappear off my screen, it was an user issue but Hector didn't make me feel small or "dumb" for this error. We love uprite!

Starla Lawhon -DyerGoogle review · Houston
★★★★★

Gerardo Sanchez was very helpful & professional. Uprite Services has great customer service and outstanding technicians. We have used them for several years and will continue our business with them.

Belle CardenasGoogle review · San Antonio
★★★★★

I had been having trouble with an IT matter that I didn't think would be fixed but Arvin Ebueng from Upright took his time with me and worked with me until we were able to resolve the issue. The issue was an internal issue with the way the program was written, but Arvin came up with a great work around so that I am now able to do what I need to do at my job. Long story short, he got me access to both things that I need access to simultaneously and daily. Thanks 😊 Arvin, you are much appreciated 👏 💐 🥳.

Sheila SpencerGoogle review · Houston
★★★★★

I’ve been extremely satisfied with Uprite Services and would recommend them without hesitation. They consistently deliver reliable, high-quality work and truly feel like a true partner rather than just another vendor. A special thank you goes to Arvin Ebueng, he is always quick to respond to our needs and incredibly easy to communicate with. No matter how busy things get, Arvin makes sure we’re taken care of promptly and with a smile. His responsiveness and clear communication have made every interaction smooth and stress-free. Thank you, Arvin and the entire Uprite team, Peerless Equipment is a customer for life!

james caswellGoogle review · San Antonio
★★★★★

I'm am not a "tech" person, however the team at Uprite gets me through the technological side of computers and software so that I can function on a daily basis... but the most enduring quality is that they care. Special shoot out to Mary, Sergio, Eufemio, Hector, and Jeff just to name a few... I appreciate each of you and the help you give me.

Evan HurleyGoogle review · Houston
★★★★★

Great service by Juan and Jacob. Always helping us out at Alamo City Trailer Sales. We have been using this company for over 10 years and always happy with the work they do.

Tess WhiteGoogle review · San Antonio

Common Questions

Network Assessment FAQ

What is a network assessment?

A network assessment is a documented, read-only review of every device, connection and rule on a business network, producing a current diagram, an asset register, a ranked list of findings and a costed remediation plan. Nothing is attacked and nothing is changed during it. It answers two questions an owner cannot otherwise answer with confidence: what do we actually own, and which parts of it are exposed. A network health check is the same product under a softer name. So is an IT network assessment.

Is a free network assessment really free?

Uprite’s network assessment is free, and you keep all four deliverables whether or not the remediation work comes to us. What sits outside the free scope is stated plainly: penetration testing, formal compliance audits and the remediation work itself are quoted separately. Ask any provider offering a free assessment to name those boundaries in writing before you book. If the report only exists inside a sales presentation, it is a sales presentation.

How long does a network assessment take?

A single-site network of under 50 users takes three to five business days of discovery, with the report and walkthrough inside two weeks of the scoping call. Multi-site networks take longer. Two to five sites joined by site-to-site VPN typically run four to five weeks end to end, and six or more sites, or a plant or clinical network, run to about six weeks. Site count decides it. It moves the timeline far more than user count does.

What do I get at the end of a network assessment?

Four documents, plus an hour with the engineer who did the work. Those documents are a current network diagram in PDF and editable form, a device-by-device asset register with firmware and end-of-support dates, a findings list ranked by exploitability and blast radius, and an itemized remediation plan with prices. The diagram satisfies CIS Safeguard 12.4 and the asset register satisfies CIS Safeguard 1.1, which is useful evidence at a cyber insurance renewal.

What is the difference between a network assessment and a network audit?

An assessment asks what you have and where it is weak. An audit asks whether what you have matches a written standard such as HIPAA, PCI DSS, CMMC or a cyber insurance questionnaire. The assessment is a technical review; the audit is evidence-gathering against a checklist. Assessment first. An auditor will open by asking for an asset inventory and a network diagram, and both of those are assessment outputs rather than audit outputs.

Will the assessment slow down or disrupt our network?

No. Discovery is read-only throughout, and nothing is changed without a written approval from you. The temporary collector we place on the LAN listens rather than probing aggressively, and it is removed the day discovery ends. On networks carrying fragile legacy equipment, clinical imaging or plant-floor controllers, we run discovery entirely passively. That adds a few days and removes the risk argument.

What access do you need to run a network assessment?

A read-only account on the firewall and switch stack, one named contact who can answer questions, and building access for the site walk. That is the whole list. If nobody currently holds the firewall admin credentials, tell us on the scoping call, because recovering them from a previous provider is the single most common reason an assessment runs long, and it is much easier to start early.

How often should a business run a network assessment?

Annually as a baseline, and immediately after any event that changes the shape of the network: a new site, an acquisition, a change of IT provider, or a significant hardware refresh. The catalog data explains why annual is the floor rather than the ceiling. CISA added 40 network-equipment vulnerabilities to its exploited catalog during 2026 alone, and the median deadline it sets for fixing one is 21 days, so a twelve-month-old inventory is already stale when the next one lands.

Related

What to Read Next, and Where We Work

Start With What You Actually Own

Book Your Network Assessment

Tell us how many sites you run and what brand of firewall is in the rack. Not sure of the brand? That is a useful answer too, and it is a more common one than you would think. We will scope it on a thirty-minute call, run it read-only, and hand you a diagram, an asset register, a ranked findings list and a costed plan you keep either way. Uprite has been doing this for Texas businesses since 1999, across Houston, Dallas, Fort Worth, San Antonio and Austin, and everything we take on carries a sub-10-minute triage SLA and a 120-day satisfaction guarantee.

Book a Network AssessmentSee Network Security Services