Cybersecurity Assessment
We assess your security controls, identify the risks that matter to your business, and give you a prioritised roadmap showing what to fix first, why it matters, and what it will take.
Who this is for
These are the situations we hear most often in scoping calls.
You don't have a current inventory of your systems, data, and who has access to what.
MFA is not confirmed on every account that could be used to reach your business data or systems.
Your last security review was over 12 months ago, or you have never had a structured one done externally.
You have never tested whether your backups restore to a usable state under time pressure.
You don't know if NIS2 or other regulations apply to your organisation, or what they'd require you to do.
A customer, insurer, or board member has asked for evidence of your security posture and you don't have it.
Your IT team spends most of its time on support tickets, with no capacity to step back and assess security as a whole.
You have no documented incident response plan and no one has documented who does what when something goes wrong.
Why this is different
Most assessment tools ask you to answer a questionnaire, then score your answers against a framework. The gaps in self-reported data are exactly the gaps you cannot see from inside.
If MFA is listed as enabled, we identify the accounts it is not covering. If backups run nightly, we check whether they restore to a usable state under time pressure. The gap between the two shows up in every risk register we produce.
Every gap is scored by the risk reduction it delivers for your specific environment. The roadmap reflects what matters for your business.
We name the specific accounts, the system, what needs to change, and in what order. Every item in the roadmap has a named owner and a realistic effort estimate.
The consultant on the first call conducts the assessment, writes the findings, and presents the roadmap. The same person throughout, so context carries across every stage.
MFA
Do you have MFA?
↓
Which accounts are not covered, and why?
Backups
Do you have backups?
↓
Can you restore to a usable state under time pressure?
Access
Do you have access controls?
↓
Who has privileged access right now, and does the business still need all of it?
Scope
Six areas, assessed in sequence. Together they provide a structured picture of your current security position: where controls are working, where gaps create genuine exposure, and what to address first.
01
We start by understanding what matters to the business: critical services, sensitive data, key systems, and the dependencies between them. This establishes what a security incident would actually cost you, which drives every risk ranking that follows.
02
We identify the threat patterns most relevant to your organisation and score their likelihood and potential impact against your specific environment: ransomware, business email compromise, credential theft, supply chain exposure. Each assessed against your actual assets and business context.
03
We evaluate your controls across people, process, and technology: access management, patching cadence, endpoint protection, backup integrity, logging and detection, and security awareness. We assess maturity against practical benchmarks, not theoretical ideals.
04
Most breaches start with a compromised credential. We review your MFA coverage, privileged access controls, joiners/movers/leavers process, and third-party access. These determine how far an attacker can move once they are inside.
05
We assess your backup integrity and recovery capability, monitoring and detection coverage, and incident response readiness. We test whether these would work under real conditions, not whether they are documented.
06
Which suppliers and partners have access to your systems or data, what security requirements you place on them, and whether your contracts reflect your actual exposure. Supply chain attacks now account for one in four breach entry points. We identify the third-party relationships that carry the most risk.
Compliance and gap analysis
We map the findings from all six areas against the frameworks relevant to your sector: NIS2, ISO 27001, Cyber Essentials, DORA, PCI DSS, GDPR. We identify which obligations you currently meet, which you do not, and which deadlines are closest. The findings drive your prioritised roadmap.
Deliverables
Four deliverables, each ready to use from day one by your IT team, your board, and any auditor or insurer who asks for evidence of your security posture.
A written assessment of your environment, controls, and maturity across all six areas. Specific findings with evidence behind each one, ready to share with a board or an auditor.
Every identified risk logged with likelihood, impact, and a treatment recommendation. Ranked so your team knows what to fix first and why. Formatted to meet ISO 27001 and NIS2 documentation requirements.
Every item has a priority, an owner, a dependency, a target date, an effort estimate, and a success measure. Your team can act on it from the first week.
A concise board-ready summary: current risk exposure, the three to five issues that need immediate attention, and what the roadmap achieves. Clear enough for a board, accurate enough for a technical team to verify.
Example extract from a roadmap
| Priority | Finding | Action | Owner | Target |
|---|---|---|---|---|
| Critical | 37 user accounts lack MFA | Enforce MFA via conditional access policy on all user accounts | IT | 30 days |
| High | Backup restores never tested | Run full recovery test from backup; verify recovery time | IT | 45 days |
| High | Privileged accounts undocumented and unmanaged | Audit all privileged accounts; implement PAM controls | IT / Security | 90 days |
| Medium | No incident response plan exists | Draft, review and tabletop-test an IR playbook | IT / Security | 60 days |
Illustrative example. Findings and timelines vary by scope and environment.
Process
Three stages, built around your schedule. The same senior consultant runs every stage.
We understand your business, your infrastructure, your regulatory obligations, and your priorities. You tell us your biggest concerns. We tell you what the assessment will cover and where its scope ends.
30 minutesStructured review of your environment, controls, documentation, and access posture. Conducted remotely or on-site depending on your setup. We work with your IT team directly, without disrupting operations.
3 to 10 daysWe deliver all four documents and walk you through the findings in a 90-minute session. You leave with a clear picture of your position, a prioritised plan, and the evidence to answer any question your board or insurer might raise.
1 week after assessmentWho conducts it
Your assessment is run by a senior Cyvra consultant from the scoping call to roadmap delivery. The same person throughout.
Lead Consultant, Cyvra
Ryland has 20 years of experience in IT and cybersecurity, working with organisations in financial services, hospitality, and regulated industries across the UK, Netherlands, and Brazil. He leads all assessment and advisory engagements at Cyvra.
Scope of work
These engagements are often confused. Each one answers a different question.
A vulnerability scan identifies software versions and known CVEs. It tells you what is present in your environment. An assessment tells you what that exposure means for your business, how it ranks against other risks, and what to do about it.
A penetration test simulates an active attack against a specific target: can an attacker breach this system or network? An assessment asks a broader question: where is your overall security exposure, and what should you prioritise to reduce it?
Our cybersecurity servicesFramework alignment is part of what we assess, but it does not drive the prioritisation. We use NIS2, ISO 27001, and Cyber Essentials as reference points. Risk to your business determines what goes first on the roadmap.
NIS2 compliance guideWe do not ask whether a control exists and take your word for it. Where appropriate, we look for evidence that it functions as intended. That difference is what makes findings actionable rather than aspirational.
Cybersecurity roadmap guideWhat comes next
You leave with a 12-month roadmap ready to act on. If you need help delivering it, we offer two options.
Your IT function can run the roadmap without external support. Every item has an owner, an effort estimate, and a clear success measure. We stay available for questions after delivery.
We run priority items alongside your team, picking up specific security workstreams while your IT function handles business as usual. This works well when the roadmap has more in it than your team can run alongside regular operations.
For organisations without a dedicated security function, we can own the programme end to end: attending board meetings, managing third-party reviews, and building internal capability until you no longer need us.
Learn about our vCISO serviceCommon questions
The assessment takes three to ten working days, depending on the size of your environment, the number of systems in scope, and how much documentation already exists. We agree the exact scope on the scoping call, so you know the timeline before we start. See the cybersecurity roadmap guide for an overview of what a typical programme looks like after the assessment.
Either works. We conduct most of it remotely using secure access to your environment and structured interviews with your IT team. We can come on-site for specific sessions if that suits your setup, and the roadmap delivery session is often better in person.
Very little. After the scoping call we share a short checklist: a few hours of your IT team's time, any security documentation you have, and access credentials for the systems in scope. Sparse documentation is itself useful data: it tells us something about your current posture.
No. The assessment is read-only. We review your environment and work with your IT team, but we make no changes to systems or configurations during the process. The main time commitment on your side is a few hours spread across the assessment period.
We work with organisations of all sizes. Scope is determined by the complexity of your environment: the systems you run, the data you hold, your third-party integrations, and your existing documentation. The free scoping call establishes what an assessment would cover and whether it is the right fit.
Pricing depends on the scope agreed on the scoping call: number of systems, locations, and regulatory frameworks in play. The scoping call itself is free and carries no obligation. We quote once we understand what the assessment needs to cover.
Get started
In 30 minutes we understand your environment and tell you honestly whether an assessment makes sense. No fee, no obligation.
Book a free 30-minute scoping call