Skip to content
Assessment Services

Security Assessment

Independent assessment of your security posture: control effectiveness testing, framework gap analysis, third-party risk review and a board-ready report with a prioritized remediation plan.

What we deliver

  1. A review of your security controls, architecture and processes, benchmarked against industry frameworks (ISO 27001, NIST, Cyber Essentials) and your specific risk profile.

  2. Beyond reviewing documents, we test whether your security controls actually work, through technical validation, process walkthroughs and evidence review.

  3. Assess alignment with Cyber Essentials, ISO 27001, NIST CSF, CIS Controls or industry-specific frameworks, with a gap analysis and remediation roadmap prioritized by risk.

  4. Review the security posture of your most critical third parties and supply chain partners, identifying risks that exist outside your own perimeter.

  5. Board- and executive-ready security assessment report, presenting findings in business risk terms, with clear severity ratings and recommended actions ranked by impact and effort.

  6. Prioritized remediation roadmap with effort estimates and quick wins, and optional hands-on support to close the gaps identified in your assessment.

Operational architecture

How it works

Every engagement follows the same five steps: baseline the current state, design the target model, roll out in stages, operate it, and improve against measurements.

01

Assess

Baseline the current state, name the gaps and put the success criteria in writing.

02

Design

Architect the target operating model and the toolchain it needs.

03

Deploy

Implement, configure and validate in a staged rollout.

04

Operate

24/7 management with contracted response times and proactive monitoring.

05

Improve

Continuous improvement driven by metrics, incidents and changes in the business.

Contracted service levels

Every engagement runs under a written SLA: a commitment, not a best-effort promise.

Run by engineers

Dedicated engineers who know your stack. No generalist help-desk tier in between.

Continuous improvement

Service reviews every two weeks, roadmap updates every quarter.

01Is a security assessment the same as a penetration test?

No. An assessment is broad: policy, configuration, process and technical controls. A penetration test takes an attacker's view and tests whether specific targets can be reached. They complement each other; neither replaces the other.

02Does it put production at risk?

An assessment is largely reading and review, so the risk is very low. For any active testing, we agree on the scope and time window in writing beforehand and define an emergency stop procedure.

03Which areas does it cover?

Identity and access, network architecture and segmentation, endpoint protection, patch status, logging and monitoring, backup and recovery, supplier security, and incident response readiness.

04Is the report written for technical staff or for management?

Both. The executive summary is written in the language of risk; the technical appendix gives finding-level detail. Purely technical reports go unread by management and do not win budget.

05How often should a security assessment be repeated?

Annually, and after any significant architectural change or serious incident. A year-old assessment does not cover the environment you run today.

Let's work out where to start

Within two weeks you get it in writing: what works, what carries risk, and a prioritized roadmap.

Request a conversation