Cybersecurity Assessment

Know your risks. Know what to fix.

We assess your security controls, identify the risks that matter to your business, and give you a prioritised roadmap showing what to fix first, why it matters, and what it will take.

Who this is for

You probably need this if…

These are the situations we hear most often in scoping calls.

You don't have a current inventory of your systems, data, and who has access to what.

MFA is not confirmed on every account that could be used to reach your business data or systems.

Your last security review was over 12 months ago, or you have never had a structured one done externally.

You have never tested whether your backups restore to a usable state under time pressure.

You don't know if NIS2 or other regulations apply to your organisation, or what they'd require you to do.

A customer, insurer, or board member has asked for evidence of your security posture and you don't have it.

Your IT team spends most of its time on support tickets, with no capacity to step back and assess security as a whole.

You have no documented incident response plan and no one has documented who does what when something goes wrong.

Why this is different

Not another cybersecurity questionnaire

Most assessment tools ask you to answer a questionnaire, then score your answers against a framework. The gaps in self-reported data are exactly the gaps you cannot see from inside.

We verify that controls work, not just that they exist

If MFA is listed as enabled, we identify the accounts it is not covering. If backups run nightly, we check whether they restore to a usable state under time pressure. The gap between the two shows up in every risk register we produce.

Findings are ranked by business impact, not framework position

Every gap is scored by the risk reduction it delivers for your specific environment. The roadmap reflects what matters for your business.

Every recommendation names a system, an action, and a sequence

We name the specific accounts, the system, what needs to change, and in what order. Every item in the roadmap has a named owner and a realistic effort estimate.

One team from scoping call to roadmap delivery

The consultant on the first call conducts the assessment, writes the findings, and presents the roadmap. The same person throughout, so context carries across every stage.

MFA

Do you have MFA?

Which accounts are not covered, and why?

Backups

Do you have backups?

Can you restore to a usable state under time pressure?

Access

Do you have access controls?

Who has privileged access right now, and does the business still need all of it?

Scope

What we assess

Six areas, assessed in sequence. Together they provide a structured picture of your current security position: where controls are working, where gaps create genuine exposure, and what to address first.

01

Business and critical assets

We start by understanding what matters to the business: critical services, sensitive data, key systems, and the dependencies between them. This establishes what a security incident would actually cost you, which drives every risk ranking that follows.

02

Threat and risk profile

We identify the threat patterns most relevant to your organisation and score their likelihood and potential impact against your specific environment: ransomware, business email compromise, credential theft, supply chain exposure. Each assessed against your actual assets and business context.

03

Security maturity

We evaluate your controls across people, process, and technology: access management, patching cadence, endpoint protection, backup integrity, logging and detection, and security awareness. We assess maturity against practical benchmarks, not theoretical ideals.

04

Identity and access

Most breaches start with a compromised credential. We review your MFA coverage, privileged access controls, joiners/movers/leavers process, and third-party access. These determine how far an attacker can move once they are inside.

05

Resilience and response

We assess your backup integrity and recovery capability, monitoring and detection coverage, and incident response readiness. We test whether these would work under real conditions, not whether they are documented.

06

Third-party and supply chain

Which suppliers and partners have access to your systems or data, what security requirements you place on them, and whether your contracts reflect your actual exposure. Supply chain attacks now account for one in four breach entry points. We identify the third-party relationships that carry the most risk.

Compliance and gap analysis

We map the findings from all six areas against the frameworks relevant to your sector: NIS2, ISO 27001, Cyber Essentials, DORA, PCI DSS, GDPR. We identify which obligations you currently meet, which you do not, and which deadlines are closest. The findings drive your prioritised roadmap.

Deliverables

What you leave with

Four deliverables, each ready to use from day one by your IT team, your board, and any auditor or insurer who asks for evidence of your security posture.

Current state report

A written assessment of your environment, controls, and maturity across all six areas. Specific findings with evidence behind each one, ready to share with a board or an auditor.

Prioritised risk register

Every identified risk logged with likelihood, impact, and a treatment recommendation. Ranked so your team knows what to fix first and why. Formatted to meet ISO 27001 and NIS2 documentation requirements.

12-month phased roadmap

Every item has a priority, an owner, a dependency, a target date, an effort estimate, and a success measure. Your team can act on it from the first week.

Executive summary

A concise board-ready summary: current risk exposure, the three to five issues that need immediate attention, and what the roadmap achieves. Clear enough for a board, accurate enough for a technical team to verify.

Example extract from a roadmap

Priority Finding Action Owner Target
Critical 37 user accounts lack MFA Enforce MFA via conditional access policy on all user accounts IT 30 days
High Backup restores never tested Run full recovery test from backup; verify recovery time IT 45 days
High Privileged accounts undocumented and unmanaged Audit all privileged accounts; implement PAM controls IT / Security 90 days
Medium No incident response plan exists Draft, review and tabletop-test an IR playbook IT / Security 60 days

Illustrative example. Findings and timelines vary by scope and environment.

Process

How it works

Three stages, built around your schedule. The same senior consultant runs every stage.

1

Scoping call

We understand your business, your infrastructure, your regulatory obligations, and your priorities. You tell us your biggest concerns. We tell you what the assessment will cover and where its scope ends.

30 minutes
2

Assessment

Structured review of your environment, controls, documentation, and access posture. Conducted remotely or on-site depending on your setup. We work with your IT team directly, without disrupting operations.

3 to 10 days
3

Roadmap delivery

We deliver all four documents and walk you through the findings in a 90-minute session. You leave with a clear picture of your position, a prioritised plan, and the evidence to answer any question your board or insurer might raise.

1 week after assessment

Who conducts it

Senior consultant, start to finish

Your assessment is run by a senior Cyvra consultant from the scoping call to roadmap delivery. The same person throughout.

RD

Ryland Deakin

Lead Consultant, Cyvra

Ryland has 20 years of experience in IT and cybersecurity, working with organisations in financial services, hospitality, and regulated industries across the UK, Netherlands, and Brazil. He leads all assessment and advisory engagements at Cyvra.

CISM CompTIA Security+ Microsoft Certified
Full profile

Scope of work

How a cybersecurity assessment differs from a scan, a test, or an audit

These engagements are often confused. Each one answers a different question.

Not a vulnerability scan

A vulnerability scan identifies software versions and known CVEs. It tells you what is present in your environment. An assessment tells you what that exposure means for your business, how it ranks against other risks, and what to do about it.

Not a penetration test

A penetration test simulates an active attack against a specific target: can an attacker breach this system or network? An assessment asks a broader question: where is your overall security exposure, and what should you prioritise to reduce it?

Our cybersecurity services

Not a compliance audit

Framework alignment is part of what we assess, but it does not drive the prioritisation. We use NIS2, ISO 27001, and Cyber Essentials as reference points. Risk to your business determines what goes first on the roadmap.

NIS2 compliance guide

Not a generic questionnaire

We do not ask whether a control exists and take your word for it. Where appropriate, we look for evidence that it functions as intended. That difference is what makes findings actionable rather than aspirational.

Cybersecurity roadmap guide

What comes next

After the assessment

You leave with a 12-month roadmap ready to act on. If you need help delivering it, we offer two options.

01

Take the plan and run

Your IT function can run the roadmap without external support. Every item has an owner, an effort estimate, and a clear success measure. We stay available for questions after delivery.

02

Managed delivery programme

We run priority items alongside your team, picking up specific security workstreams while your IT function handles business as usual. This works well when the roadmap has more in it than your team can run alongside regular operations.

03

Ongoing virtual CISO

For organisations without a dedicated security function, we can own the programme end to end: attending board meetings, managing third-party reviews, and building internal capability until you no longer need us.

Learn about our vCISO service

Common questions

What people ask before booking

How long does the assessment take?

The assessment takes three to ten working days, depending on the size of your environment, the number of systems in scope, and how much documentation already exists. We agree the exact scope on the scoping call, so you know the timeline before we start. See the cybersecurity roadmap guide for an overview of what a typical programme looks like after the assessment.

Do you come on-site, or is it done remotely?

Either works. We conduct most of it remotely using secure access to your environment and structured interviews with your IT team. We can come on-site for specific sessions if that suits your setup, and the roadmap delivery session is often better in person.

What do we need to prepare before you start?

Very little. After the scoping call we share a short checklist: a few hours of your IT team's time, any security documentation you have, and access credentials for the systems in scope. Sparse documentation is itself useful data: it tells us something about your current posture.

Will it disrupt our operations?

No. The assessment is read-only. We review your environment and work with your IT team, but we make no changes to systems or configurations during the process. The main time commitment on your side is a few hours spread across the assessment period.

What size of organisation do you work with?

We work with organisations of all sizes. Scope is determined by the complexity of your environment: the systems you run, the data you hold, your third-party integrations, and your existing documentation. The free scoping call establishes what an assessment would cover and whether it is the right fit.

How much does it cost?

Pricing depends on the scope agreed on the scoping call: number of systems, locations, and regulatory frameworks in play. The scoping call itself is free and carries no obligation. We quote once we understand what the assessment needs to cover.

Get started

Understand your security position
before someone else finds it for you.

In 30 minutes we understand your environment and tell you honestly whether an assessment makes sense. No fee, no obligation.

Book a free 30-minute scoping call