Skip to content

Security assessment and remediation

Gap analysis against CIS Controls, with a prioritized remediation roadmap, then the fixes themselves.

Security work that never gets past the spreadsheet

Most mid-market companies have some security work sitting in a spreadsheet: findings from a past audit, a cyber insurance questionnaire that surfaced gaps nobody has closed, a vague sense that MFA coverage isn't what it should be. The list exists. Almost nothing on it gets fixed, because there's no owner and no sequence.

Security remediation fails most often not from lack of awareness but from lack of prioritization: everything looks urgent, so nothing gets done first, and the list just grows.

We assess against the CIS Controls specifically because they're built for prioritization: the first few controls matter more than the last few, and a remediation roadmap should reflect that instead of treating every finding as equally urgent.

What's included

  • External attack surface reviewWhat is visible from the internet, what it advertises about your environment, and what shouldn't be exposed at all.
  • Identity and access reviewMFA coverage, privileged accounts, and the stale access nobody remembers granting.
  • Endpoint and network posturePatch levels, EDR coverage, and segmentation checked against what a real incident would exploit.
  • Ransomware readinessBackup isolation and the specific question of whether your backup credentials would fall with the rest of the domain.
  • CIS Controls gap mappingYour environment mapped against the controls, with the honest state of each one.
  • Remediation executionNot just the roadmap. We do the fixes too, in the priority order the assessment established.

How the engagement runs

  1. 01AssessmentA structured review across identity, endpoint, network, and external surface. Often the right starting point is our Security Posture Assessment.
  2. 02Prioritized roadmapFindings ranked by risk reduced per dollar of effort, not just listed.
  3. 03RemediationThe highest-priority fixes executed first, with progress visible against the roadmap.

Technologies and platforms

  • CIS Controls
  • Microsoft Defender
  • CrowdStrike
  • Entra ID Conditional Access

Proof

We build the roadmap the same way we'd want one built for our own environment: ranked by what actually reduces risk, not by what looks most impressive on a slide.

Security Posture AssessmentA fixed-scope gap analysis against the CIS Controls, with a remediation roadmap your own team can execute.See what the assessment includes

Common questions

Is this a penetration test?

No. This is a posture and configuration assessment against the CIS Controls, not an exploitation exercise. If findings justify a pentest, we'll help you scope one with the right specialist.

Will remediation disrupt our users?

Some changes, like enforcing MFA, involve a short adjustment period. We sequence rollouts to minimize disruption and communicate changes in advance.

Do you just hand us the roadmap, or do you do the fixes?

Both are available. The roadmap stands alone if you want to execute internally; we also do the remediation work directly if you'd rather we handle it.

How does this help with cyber insurance renewal?

The findings map to the domains insurance questionnaires usually ask about, so you answer from evidence rather than guesswork.

Related services

Bring the findings list that's been sitting untouched.

Most security backlogs just need a real sequence, not more findings.