Cybersecurity Assessment
Control coverage against NIST CSF 2.0 and CIS v8.1, judged on evidence rather than on policy documents, with gaps ranked by exposure rather than by effort.
| How it is bought | Fixed fee |
| Duration | 3 weeks |
| Written for | CISOs and infrastructure leaders who need an evidenced position rather than a framework score |
The gap that matters is between a control that exists and a control you can show operated on a given day against a given asset. Assessors, insurers and attackers all treat the second kind as the only kind.
What you receive
Named artifacts, not activities. If one of these is not delivered, the engagement is not complete.
- Control coverage mapped to NIST CSF 2.0 and CIS Critical Security Controls v8.1
- An evidence position per control: operating and evidenced, claimed but unevidenced, or absent
- Your measured time from CVE publication to remediation on internet-facing systems, or a statement that it cannot currently be measured
- A third-party access inventory: who holds live credentials into your estate, with an owner per integration
- Gaps ranked by exposure rather than by effort, with the recommended control for each
How it runs
- Week 1: scope, asset and identity inventory, evidence collection.
- Week 2: control testing against evidence rather than against policy documents.
- Week 3: ranking, recommendations and readout.
What this deliberately does not include
Published with the same prominence as the deliverables. A scope with no stated exclusions is a scope that will be argued about later, and the argument always happens at the worst possible moment.
- Penetration testing or red teaming. Different engagement, and we will say if you need one instead.
- Remediation. This finds and ranks; fixing is separate or moves to Managed Security.
- Certification. We map to the frameworks; we are not a certification body.
How you know it is finished
For every control claimed, you can produce the evidence, or you know that you cannot and it is on the ranked list.
What you need ready
Read access for evidence collection, your current control documentation, and the name of whoever owns each control.
Every engagement starts with a written scope confirmation before any invoice is raised. Nothing here is a click-to-buy: we confirm what you need, agree the scope in writing, then invoice. If the scoping conversation shows that a smaller engagement, or none at all, is the right answer, we say so before anything is signed.
We use privacy-friendly analytics by default. Optional analytics cookies load only if you accept.