Skip to content
Back to Health Check
Sample Deliverable

Infrastructure Health Check Report

ID: HC-2025-01-EXAMPLE | Status: Finalized | Prepared for: [Client Name Redacted]

Executive Summary

The environment is functional but fragile. While core services are currently operational, several critical gaps in backup immutability, identity synchronization, and lifecycle management represent significant risks to business continuity.

Critical Risks

3 Findings

Drift Status

MODERATE

Recovery Readiness

LOW

Environment Snapshot

Infrastructure Overview

VMs / Workloads

48

Hypervisor

3 ESXi 6.7/7.0 hosts

Cloud

1 Azure subscription (East US 2)

Backup

Veeam Backup & Replication v12

Identity

Active Directory (2 DCs, single forest)

Storage

Dell PowerStore 500T (iSCSI)

System Tier Classification
Tier-1 Business-critical (revenue-impacting)
12 VMs
Tier-2 Supporting services (internal ops)
22 VMs
Tier-3 Development / test / sandbox
14 VMs

Tier assignments are based on business-impact analysis conducted during intake. A dependency diagram is included in the full client report.

Findings Matrix

6 Items Identified
AreaTierFindingRiskRecommendationEvidence
Backup & RecoveryTier-1Backup immutability is not enforced on primary repository.CriticalEnable S3 Object Lock or hardened Linux repository for immutable storage.Veeam B&R Console → Backup Infrastructure → Repositories (screenshot 2025-01-12)
IdentityTier-1Domain Controller time drift exceeding 5 minutes (NTP skew).CriticalRe-sync PDC Emulator to reliable external stratum-1 source.w32tm /monitor output on DC01 (log capture 2025-01-11)
VirtualizationTier-1vSphere 6.7 hosts remaining in production (End of General Support).HighAccelerate hardware refresh or migrate to vSphere 8.0.vCenter Inventory → Hosts & Clusters view (screenshot 2025-01-10)
Azure FoundationTier-2Missing Resource Locks on 'Production-Core' networking resources.MediumApply 'CanNotDelete' locks to critical VNets and Gateways.Azure Portal → Resource Group → Locks blade (screenshot 2025-01-12)
StorageTier-2SAN firmware is 3 versions behind manufacturer baseline.MediumSchedule rolling controller updates during next maintenance window.Dell PowerStore Manager → System → Software (screenshot 2025-01-09)
DocumentationTier-3Site Recovery Plan (SRP) has not been tested in >12 months.MediumExecute a non-disruptive DR drill for Tier-1 applications.SRP document revision history — last update 2023-11-14 (PDF metadata)

Recovery Evidence Checklist

Restore tests, runbooks, logs
SystemTierLast Restore TestResultRunbook CurrentNotes
AD Domain ControllersTier-12024-09-15Bare-metal restore to isolated VLAN verified.
SQL Production ClusterTier-12024-06-22Database integrity check passed. Runbook references deprecated SAN.
File Server (DFS)Tier-2NeverNo documented restore procedure exists.
Azure App ServicesTier-22025-01-05Deployment slot swap verified; geo-failover untested.
Legacy ERP (VM)Tier-12023-11-02Restore boot failed — missing SCSI driver in backup image.

Recovery evidence is verified against actual restore job logs and operator confirmation. Systems marked "untested" have no documented restore attempt on record.

Prioritized Remediation

01

Immediate

Fix NTP skew and verify identity synchronization.

Reversible

Non-destructive; previous NTP source can be restored.

02

Q1

Implement immutable backup tier for ransomware protection.

Reversible

Additive change; existing repositories remain untouched.

03

Q1

Decommission or upgrade vSphere 6.7 legacy hosts.

Maintenance window

Requires maintenance window. VMs can be migrated back if needed.

04

Q2

Execute full DR test and update recovery runbooks.

Reversible

Non-disruptive drill in isolated network; production unaffected.

Get this clarity for your environment.

Stop guessing about drift and recovery. Get a fixed-scope Health Check that provides evidence, not just opinions.

Request Health Check Download PDF (Client Only)

Operator Handoff Notes

Operational Context — Redacted

Primary Operator

[Redacted] — sole administrator for vSphere and Veeam. On-call rotation is informal.

Escalation Path

No documented escalation matrix. Hardware issues go directly to Dell ProSupport; Azure issues default to Microsoft Premier.

Tribal Knowledge Risk

Firewall rules on the Fortigate were last modified by a former contractor. No change log exists. Current operator inherited the configuration.

Credential Management

Service accounts use shared credentials stored in a local KeePass file on the admin workstation. No PAM or vault solution in place.

Full handoff documentation includes credential inventory, vendor contact list, and infrastructure decision log. Provided to client in the finalized report package.