Enterprise Services

Cybersecurity Assessment

Control coverage against NIST CSF 2.0 and CIS v8.1, judged on evidence rather than on policy documents, with gaps ranked by exposure rather than by effort.

Cybersecurity Assessment
How it is boughtFixed fee
Duration3 weeks
Written forCISOs and infrastructure leaders who need an evidenced position rather than a framework score

The gap that matters is between a control that exists and a control you can show operated on a given day against a given asset. Assessors, insurers and attackers all treat the second kind as the only kind.

What you receive

Named artifacts, not activities. If one of these is not delivered, the engagement is not complete.

  • Control coverage mapped to NIST CSF 2.0 and CIS Critical Security Controls v8.1
  • An evidence position per control: operating and evidenced, claimed but unevidenced, or absent
  • Your measured time from CVE publication to remediation on internet-facing systems, or a statement that it cannot currently be measured
  • A third-party access inventory: who holds live credentials into your estate, with an owner per integration
  • Gaps ranked by exposure rather than by effort, with the recommended control for each

How it runs

  • Week 1: scope, asset and identity inventory, evidence collection.
  • Week 2: control testing against evidence rather than against policy documents.
  • Week 3: ranking, recommendations and readout.

What this deliberately does not include

Published with the same prominence as the deliverables. A scope with no stated exclusions is a scope that will be argued about later, and the argument always happens at the worst possible moment.

  • Penetration testing or red teaming. Different engagement, and we will say if you need one instead.
  • Remediation. This finds and ranks; fixing is separate or moves to Managed Security.
  • Certification. We map to the frameworks; we are not a certification body.

How you know it is finished

For every control claimed, you can produce the evidence, or you know that you cannot and it is on the ranked list.

What you need ready

Read access for evidence collection, your current control documentation, and the name of whoever owns each control.

Start this engagement

Every engagement starts with a written scope confirmation before any invoice is raised. Nothing here is a click-to-buy: we confirm what you need, agree the scope in writing, then invoice. If the scoping conversation shows that a smaller engagement, or none at all, is the right answer, we say so before anything is signed.

Request this engagement Run the free self-assessment first

Browse enterprise services