Cybersecurity assessment

Who it is for

Companies that have grown their IT without a review, that are asked security questions by customers or auditors, or that want to know where to spend first.

Cybersecurity assessment

What is in scope

Network perimeter

  • Firewall configuration and rules
  • Remote-access arrangements
  • Separation between networks, as built

Devices

  • Endpoint protection coverage and status
  • Patch status of operating systems
  • Administrator rights on devices

Backups

  • What is backed up and where the copies are kept
  • Whether copies are separate from the live systems
  • Whether a restore has been tested

Access control

  • User and administrator accounts
  • Multi-factor authentication, where it is available
  • How leavers are removed, and shared accounts
Cybersecurity assessment

What you receive

  • A written report with findings in priority order and the evidence for each
  • A remediation list with the effort and the order
  • A walk-through of the findings with your team
Cybersecurity assessment

What we need from you

  • Read-only access to configurations, or screen-shares
  • A contact in IT, or whoever knows the history of the set-up
  • The list of critical systems and where they run
  • Any framework you are held to, so findings can be written against it
Cybersecurity assessment

How it is quoted

Custom and itemised by what is in scope.

What shapes the quote

  • Number of sites
  • Firewalls and network equipment
  • Number of endpoints and servers
  • Systems and accounts in scope
Cybersecurity assessment

Questions about the assessment

Will you fix what you find?

The findings come first. Fixing is scoped separately, and you can use us or your own team.

Do you test our systems from the internet?

Not as part of this assessment, which reviews configuration and practice. If you need external testing, tell us, and the proposal says whether we do it or whether you need a specialist.

Can you assess against a framework we are held to?

Tell us which one before scoping, for example the National Cybersecurity Authority’s Essential Cybersecurity Controls. The proposal says how far findings can be written against it.

Will you need administrator access?

We ask for read-only access, or a screen-share with someone who has it. We do not change anything during the assessment.

What do we get at the end?

A written report in priority order, a remediation list and a walk-through with your team.