First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Services/Rapid Cyberattack Assessment Workshop (Full - On-site)
Training

Rapid Cyberattack Assessment Workshop (Full - On-site) — Ransomware Readiness Roadmap

The Rapid Cyberattack Assessment Workshop (Full - On-site) is a three-week assessment and two-day on-site workshop for organizations that want to evaluate their cybersecurity posture and preparedness for rapid cyberattacks such as ransomware. IT Partner reviews pre-assessment questionnaires and Rapid Cyberattack Assessment tool results, facilitates on-site workshops to analyze gaps and Microsoft technology opportunities, and delivers findings, recommendations, and a tailored Rapid Cyberattack Roadmap.

Timeline 3 weeksService owner Mike MackeyOffice 365microsoft 365

What this engagement is

This workshop helps your organization assess cybersecurity readiness against rapid cyberattacks, including ransomware. Over three weeks, IT Partner works with your team to review questionnaire responses and RCA tool results, identify vulnerabilities and critical gaps, and develop a roadmap for strengthening defenses using Microsoft technologies where appropriate. The engagement culminates in a two-day on-site workshop focused on findings, gap analysis, priorities, roadmap delivery, solution briefings, and technical readiness presentations. SKU: ITPWW155TRNOT. Price: $2,250. Duration: 3 weeks. Manager: Mike Mackey.

Success criteria

01A completed Rapid Cyberattack Roadmap tailored to the customer’s environment.
02Detailed documentation of findings and actionable recommendations.
03A clear understanding of Microsoft technologies and their implementation.

What you receive

A prioritized Rapid Cyberattack Roadmap tailored to your environment.
Comprehensive documentation of findings and actionable recommendations.
RCA tool reports highlighting vulnerabilities and gaps in your current setup.
A workshop summary and next steps to take your cybersecurity strategy to the next level.
Kickoff presentation.
Pre-assessment documentation.
Initial findings and gap analysis.

How the work unfolds

Week 1 – Kickoff

Activities: Kickoff meeting to align goals and expectations. Provide pre-assessment questionnaire and RCA tool guidance. Deliverables: Kickoff presentation. Pre-assessment documentation.

Week 2 – Assessment

Activities: Complete the pre-assessment questionnaire and run the RCA tool. Analyze tool outputs and begin roadmap planning. Deliverables: Initial findings and gap analysis.

Week 3 – On-Site Workshop, Day 1

Review findings from questionnaires and RCA tool. Conduct a gap analysis and identify customer priorities. Develop a preliminary roadmap.

Week 3 – On-Site Workshop, Day 2

Finalize and deliver the roadmap. Conduct solution briefings and technical readiness presentations.

Prerequisites

Appropriate Microsoft security licensing (e.g., Microsoft Defender for Endpoint, Microsoft Sentinel).
A dedicated machine to run the RCA tool.
Stable internet connectivity for tool installation and data sharing.
Availability of security architects, IT administrators, and other relevant stakeholders.

Who does what

IT Partner

  • Planning: Conduct a kickoff meeting to establish objectives and governance.
  • Planning: Provide a pre-assessment questionnaire and guidance for the Rapid Cyberattack Assessment (RCA) tool.
  • Implementation: Review completed questionnaires and RCA tool results.
  • Implementation: Facilitate on-site workshops to analyze findings, conduct a gap analysis, and identify opportunities to leverage Microsoft technologies.
  • Implementation: Develop and deliver a comprehensive, actionable roadmap tailored to customer requirements.
  • Post-Implementation Support: Provide post-engagement documentation, including workshop findings and roadmap recommendations.
  • Post-Implementation Support: Offer guidance on next steps and additional services if required.

Your team

  • Information: Complete the pre-assessment questionnaire accurately and on time.
  • Information: Ensure RCA tool outputs are ready before the scheduled workshops.
  • Access: Grant access to IT administrators, security architects, and relevant personnel.
  • Access: Provide a dedicated machine for running the RCA tool.
  • Participation: Attend all scheduled meetings and workshops.
  • Participation: Actively engage in roadmap discussions and approve necessary actions.

What's not included

Implementation of roadmap recommendations (available as an add-on service).
Extended post-engagement support beyond the defined scope.
Custom configurations or advanced integrations outside standard recommendations.

Frequently asked questions

What is the Rapid Cyberattack Assessment Workshop (Full - On-site)?

The Rapid Cyberattack Assessment Workshop (Full - On-site) is a three-week cybersecurity assessment and two-day on-site workshop focused on preparedness for rapid cyberattacks such as ransomware. IT Partner reviews pre-assessment questionnaire responses and Rapid Cyberattack Assessment tool results, analyzes gaps, identifies Microsoft technology opportunities, and delivers findings, recommendations, and a tailored Rapid Cyberattack Roadmap.

Who is this workshop designed for?

This workshop is designed for organizations that want to evaluate their cybersecurity posture and readiness for rapid cyberattacks, including ransomware. It is especially relevant when security architects, IT administrators, and other stakeholders can participate in assessment activities, workshop discussions, and roadmap planning.

How long does the Rapid Cyberattack Assessment Workshop take?

The engagement is delivered over three weeks. Week 1 is kickoff and pre-assessment preparation, Week 2 is questionnaire and RCA tool assessment, and Week 3 includes the two-day on-site workshop for findings review, gap analysis, roadmap finalization, solution briefings, and technical readiness presentations.

How much does the Rapid Cyberattack Assessment Workshop cost?

The listed price for the Rapid Cyberattack Assessment Workshop (Full - On-site) is $2,250. The service SKU is ITPWW155TRNOT, and any items outside the stated scope, such as implementation of roadmap recommendations, should be confirmed separately with IT Partner.

What deliverables are included in the workshop?

The workshop includes a prioritized Rapid Cyberattack Roadmap tailored to your environment, comprehensive documentation of findings and actionable recommendations, RCA tool reports highlighting vulnerabilities and gaps, and a workshop summary with next steps. It also includes a kickoff presentation, pre-assessment documentation, and initial findings and gap analysis.

What happens during Week 1 of the engagement?

During Week 1, IT Partner conducts a kickoff meeting to align goals, expectations, and governance. IT Partner also provides the pre-assessment questionnaire and guidance for using the Rapid Cyberattack Assessment tool, with the kickoff presentation and pre-assessment documentation as deliverables.

What happens during Week 2 of the engagement?

During Week 2, the customer completes the pre-assessment questionnaire and runs the Rapid Cyberattack Assessment tool on a dedicated machine. IT Partner analyzes the tool outputs and questionnaire information, then begins roadmap planning and prepares initial findings and gap analysis.

What happens during the two-day on-site workshop?

On Day 1 of the on-site workshop, IT Partner reviews the questionnaire and RCA tool findings, conducts gap analysis, identifies customer priorities, and develops a preliminary roadmap. On Day 2, IT Partner finalizes and delivers the roadmap and provides solution briefings and technical readiness presentations.

What is the Rapid Cyberattack Roadmap?

The Rapid Cyberattack Roadmap is a prioritized plan tailored to the customer’s environment for improving readiness against rapid cyberattacks. It is based on questionnaire responses, RCA tool results, identified vulnerabilities, gap analysis, and opportunities to use Microsoft technologies where appropriate.

Does this service include implementation of the roadmap recommendations?

No, implementation of the roadmap recommendations is not included in the standard workshop scope. The service provides assessment, findings, recommendations, and a tailored roadmap; implementation is available as an add-on service and should be scoped separately with IT Partner.

What is not included in the Rapid Cyberattack Assessment Workshop?

The workshop does not include implementation of roadmap recommendations, extended post-engagement support beyond the defined scope, or custom configurations and advanced integrations outside standard recommendations. These items may require additional services and should be confirmed with IT Partner before the engagement.

What prerequisites are required before starting the workshop?

Prerequisites include appropriate Microsoft security licensing, such as Microsoft Defender for Endpoint or Microsoft Sentinel where applicable, a dedicated machine to run the RCA tool, and stable internet connectivity for tool installation and data sharing. The customer must also make security architects, IT administrators, and other relevant stakeholders available for the engagement.

Do we need Microsoft Defender for Endpoint or Microsoft Sentinel for this workshop?

The service lists appropriate Microsoft security licensing, such as Microsoft Defender for Endpoint and Microsoft Sentinel, as a prerequisite. Exact licensing needs can depend on your environment and assessment goals, so customers should confirm their current licensing and any gaps with IT Partner before the workshop begins.

What are IT Partner’s responsibilities during the engagement?

IT Partner is responsible for planning and running the kickoff, providing the pre-assessment questionnaire and RCA tool guidance, reviewing completed questionnaires and tool results, and facilitating the on-site workshops. IT Partner also develops and delivers the tailored roadmap, provides post-engagement documentation, and offers guidance on next steps or additional services if required.

What are the client’s responsibilities during the engagement?

The client is responsible for accurately completing the pre-assessment questionnaire on time, ensuring RCA tool outputs are ready before the workshops, and providing a dedicated machine for the RCA tool. The client must also make IT administrators, security architects, and relevant personnel available, attend scheduled meetings and workshops, participate in roadmap discussions, and approve necessary actions.

Will the assessment cause downtime or disrupt business operations?

The service description does not specify planned downtime or production changes because the scope is assessment, analysis, and roadmap development rather than implementation. However, the RCA tool requires a dedicated machine, internet connectivity, and data sharing, so any operational considerations should be confirmed with IT Partner during kickoff.

What information does IT Partner review during the assessment?

IT Partner reviews the customer’s completed pre-assessment questionnaire and Rapid Cyberattack Assessment tool results. These inputs are used to identify vulnerabilities, document critical gaps, analyze priorities, and develop a tailored roadmap for improving cyberattack readiness.

What happens after the workshop is completed?

After completion, the customer receives post-engagement documentation that includes workshop findings, roadmap recommendations, and suggested next steps. Extended post-engagement support and implementation of the recommendations are not included in the base scope, but IT Partner can provide guidance on additional services if required.

Can the workshop identify opportunities to use Microsoft security technologies?

Yes, the workshop includes analysis of opportunities to leverage Microsoft technologies where appropriate. The goal is not only to identify gaps, but also to help the customer understand relevant Microsoft technologies and implementation considerations through roadmap delivery, solution briefings, and technical readiness presentations.

Who should attend the on-site workshop?

Security architects, IT administrators, and other relevant stakeholders should attend because the workshop depends on technical context, operational knowledge, and decision-making input. Client participation is required for reviewing findings, prioritizing gaps, discussing the roadmap, and approving necessary actions.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$2,250
3 weeks
Book a meeting