obviously take all your tools with you, scanners, sniffers, virus software the lot.

fully update and patch all their systems, scan for trojans, ensure once you have patched and cleaned the systems that all passwords are changed. If it is being attacked from within the company then ensure the physical security of everything. no passwords lying around, rooms unlocked etc.

People should not have access to anything they dont need so check groups etc.

you can sit a sniffer on the network and listen for anything abnormal, check all logs and if not already ensure logging is set up correctly. Make sure when you get there you get a full background on everything (the network setup, the reasons why they think they are being attacked, the proof, full OS and software details .. the lot)

you can never have to much information