Twelve sections, matching the proposal we issue. Each one lists the must-have documents and the nice-to-haves that let us go deeper.
Section 1 — Firewalls
Lets us size the appliance, licence tier and rule-set migration effort, and evidence the before/after risk position.
Required Current firewall make, model and firmware version Support and licence expiry dates Existing rule base export or screenshot summary List of inbound published services (VPN, mail, web, RDP) Number of sites and site-to-site tunnels in use Helpful if available Most recent vulnerability scan or insurance questionnaire Any known outage or breach history in the last 24 months Download Firewalls & Perimeter Security templateSection 2 — Networking
Confirms port counts, PoE budget and VLAN design so the LAN uplift can be quoted and documented as a case study.
Required Switch inventory: make, model, port count, age Existing network diagram or cabling schedule IP addressing and VLAN list Comms room photos (front and rear of rack) Count of PoE devices (phones, cameras, access points) Helpful if available Structured cabling test results Floor plans in PDF or DWG Download Networking & Switching templateSection 3 — Wireless
Drives access point counts, heat-map modelling and captive portal requirements.
Required Floor plans with rough dimensions for each site Existing access point make, model and quantity Coverage problem areas (warehouse, outdoor, mezzanine) Guest Wi-Fi requirements and expected concurrent users Helpful if available Existing wireless survey Branding assets for the guest splash page Download Wireless & Public Wi-Fi templateSection 4 — Server Support
Determines the server plan tier, backup sizing and virtualisation work required.
Required Server list: role, OS version, physical or virtual, age Hypervisor platform and licensing (VMware, Hyper-V, Proxmox) Storage capacity used and free per server Current backup product, schedule and last successful restore test Line-of-business applications hosted and their vendors Helpful if available Warranty status per host Disaster recovery plan or RTO/RPO targets Download Server Support & Infrastructure templateSection 5 — Managed IT Support
Sets per-user pricing, onboarding effort and the baseline metrics we report improvement against.
Required Staff headcount by site, and count of shared or kiosk devices Device inventory with age and operating system Microsoft 365 licence report (or tenant admin export) Current ticket volumes and incumbent provider's SLA List of third-party IT vendors we would coordinate with Helpful if available Last 3 months of IT invoices Onboarding/offboarding process notes Download Managed IT Support templateSection 6 — Internet & ISP
Confirms available carriage, contract exit dates and failover design per site.
Required Current internet service type and speed per site Carrier, account numbers and contract end dates Site addresses for serviceability checks Static IP requirements and current public IP ranges Bandwidth-heavy workloads (cloud backup, VoIP, CAD, video) Helpful if available Recent speed or latency reports Existing SD-WAN configuration details Download Internet & Connectivity templateSection 7 — CCTV
Sizes camera counts, storage retention and door hardware for the security build.
Required Camera count and locations (internal, external, carpark) Existing NVR/DVR brand, model and retention period Required retention in days and who needs remote viewing Doors to be access-controlled and current lock hardware Site photos of key coverage areas Helpful if available Insurance or regulator camera requirements Privacy or surveillance policy Download CCTV & Access Control templateSection 8 — VoIP
Confirms extension counts, number porting and call-flow design for the 3CX build.
Required Extension count and handset models in use Current phone provider, plan and contract end date List of phone numbers to port (including fax and 1300) Current call flow: greetings, menus, queues, after-hours Monthly call volumes and average concurrent calls Helpful if available Recorded greetings and on-hold audio CRM or PMS integration requirements Download VoIP & Unified Comms templateSection 9 — Cyber Security
Establishes the security baseline we measure uplift against, and evidences the case study outcome.
Required Current endpoint security and email filtering products MFA coverage: which users and which applications Admin account list and how privileged access is managed Patching approach for servers, endpoints and third-party apps Any incident, phishing or ransomware history Helpful if available Cyber insurance policy and questionnaire Most recent penetration test or vulnerability report Download Cyber Security templateSection 10 — Governance
Shows what documentation exists so the gap and remediation plan can be written.
Required Existing IT policies (acceptable use, password, access control) Asset and licence register Current change management or approval process Register of administrator credentials and where they are stored Board or management reporting currently received Helpful if available Risk register Business continuity plan Download IT Governance & Documentation templateSection 11 — vCIO / CTO
Feeds the technology roadmap, budget model and quarterly business review agenda.
Required Three-year business plan or growth targets Current IT operating and capital budget Hardware refresh dates and lease or finance end dates Known upcoming projects (moves, acquisitions, new sites) Key stakeholders and how decisions are approved Helpful if available Previous IT strategy documents Vendor contracts under review Download Virtual CIO / CTO templateSection 12 — Audits & Compliance
Defines audit scope, the standard being targeted and the evidence pack we must produce.
Required Standard being targeted (Essential Eight, SMB 1001, ISO 27001, NIST) Any customer, tender or regulator deadline Scope: entities, sites, systems and data in scope In-scope IP ranges, domains and applications for testing Existing evidence: policies, registers, prior audit reports Helpful if available Statement of Applicability if ISO 27001 is already underway Data classification or privacy impact assessments Download Audits, Compliance & Pentesting template