Skip to content

Security Posture Assessment

A gap analysis against the CIS Controls: where you stand, what an attacker would actually use, and a remediation roadmap in priority order.

Duration2–3 weeks
Your timeAbout 4 hours
Changes to your environmentNone
PricingSet on the scope call

What you get

  • CIS Controls gap analysisYour environment mapped against the controls that matter for an organization your size, with the honest state of each.
  • External attack surface reviewWhat of yours is visible from the internet, what it advertises, and which of it should not be there.
  • Identity and access reviewMFA coverage, privileged accounts, stale access, and the service accounts nobody remembers creating.
  • Ransomware readinessBackup isolation, restore capability, and segmentation, assessed against how these incidents actually unfold.
  • A remediation roadmap in priority orderRanked by risk reduced per dollar of effort, split into this-month, this-quarter, and this-year.

What we need from you

  • Read-only access to identity, endpoint, and network management consoles, or exports from them.
  • Two working sessions with IT (about three hours total) and one with leadership on business priorities.
  • Any prior assessments, cyber-insurance questionnaires, or audit findings you want mapped.

Timeline

Week 1

Kickoff, access, external surface review, and identity collection.

Week 2

Internal posture review, ransomware readiness, and control mapping. Critical exposures get raised immediately.

Week 3

Roadmap, written report, and walkthrough with IT and leadership (shorter estates finish in two weeks).

Who it's for, and who it isn't

A fit if
  • Cyber insurance renewal is asking questions you cannot answer confidently.
  • You have never had an outside set of eyes on the environment.
  • Leadership wants a security budget grounded in findings, not fear.
Not a fit if
  • You need a penetration test. This is a posture assessment; a pentest is a different engagement we can help you scope with the right specialist.
  • You need a certified audit (SOC 2, ISO 27001). We prepare you for those; we do not issue them.

Sample deliverable: table of contents

  1. 1 · Executive summary and risk overview
  2. 2 · External attack surface findings
  3. 3 · Identity and access findings
  4. 4 · Endpoint and network posture
  5. 5 · Ransomware readiness
  6. 6 · CIS Controls gap map
  7. 7 · Remediation roadmap (month / quarter / year)

Common questions

Is this a penetration test?

No, and we say that plainly. This is a posture assessment: configuration, identity, surface, and readiness, mapped to the CIS Controls. A pentest attempts exploitation and is a different engagement; if the findings justify one, we help you scope it properly.

Will it disrupt our users or systems?

No. The work is read-only review and passive external observation. Nothing is exploited, stress-tested, or changed.

Will it help with our cyber insurance renewal?

The findings map to the domains those questionnaires ask about, so you answer from evidence instead of optimism. It is not a certification, and no assessment that takes three weeks honestly could be.

Our IT team is nervous about being graded. Should they be?

The report is written to make your team stronger, not to assign blame; most gaps we find are resourcing decisions, not competence failures, and the roadmap is theirs to execute. We have watched these engagements improve an IT team’s standing with leadership more often than damage it.

Related

Connect with us about your security posture.

Fifteen minutes to scope the environment and set the fixed fee. The roadmap you get is one your own team can execute.