Cybersecurity Assessment

Find out exactly where your security stands.

A structured review of your IT and security environment, delivered as a written report and prioritised action plan. Remote or on-site. Scoped to your sector and regulatory obligations.

The starting point

The same gaps sit behind most incidents.

Before we can fix anything, we need to know where your programme actually stands. These are the gaps we find in almost every assessment.

No complete picture
You cannot protect what you do not know you have. Unmanaged devices, forgotten SaaS applications, and unclassified data are the most common sources of breach exposure, and the hardest to see without a dedicated review.
Controls that exist on paper only
Policies, MFA, and backups documented and deployed, but never tested. Compliance paperwork without verification creates a false sense of security while real gaps stay open. Auditors and attackers both notice.
No clear starting point
When an IT team makes time for security, the first problem is knowing what to tackle first. Without a baseline, effort goes to visible or familiar problems while critical gaps stay unaddressed.
No security strategy
Security tools without a strategy are expensive noise. Most businesses accumulate endpoint protection, email filtering, and MFA without ever defining what they are protecting against, in what priority order, with what resources. A strategy answers that.
No compliance framework mapped
GDPR, NIS2, ISO 27001, PCI DSS: the regulations that apply to your business do not wait for you to notice them. Most organisations discover the gap during a customer audit, an insurer questionnaire, or an incident report. The assessment maps your obligations before one of those forces it.
Policies that have never been tested
An incident response plan, a backup procedure, a password policy: all documented, all untested. The gap between what the policy says and what actually happens under pressure is the most consistently underestimated risk we find. Documentation is not the same as capability.
Scope of assessment

Six areas. Every one a potential blind spot.

We work through each area via structured interviews and document review. The depth in each area matches your sector, your size, and which regulatory obligations apply to you.

Area 01
Identity & Access Management
Who can access which systems, at what privilege level. We verify MFA coverage, review stale and shared accounts, and check for privilege creep across your user base, including admin access and service accounts that are often left unreviewed.
Area 02
Network & Infrastructure
What you expose to the internet, how your internal network is segmented, and whether firewall rules, DNS configurations, and remote access controls match your intended security posture. Common findings include open management ports and flat networks with no east-west controls.
Area 03
Endpoints & Device Security
Which devices connect to your environment, their patch and configuration status, and whether unmanaged or personal devices create gaps your current endpoint tooling misses. BYOD and contractor devices are consistently the source of blind spots.
Area 04
Data Classification & Compliance
What personal and sensitive data you hold, where it lives, how it is protected at rest and in transit, and which frameworks apply: GDPR, NIS2, ISO 27001, PCI DSS, or sector-specific requirements. We map your current posture against each applicable standard.
Area 05
Incident Response Readiness
Whether you have a tested response plan, verified and restorable backups, a breach notification procedure, and clear escalation paths for the first hours of an incident. We check the plan against the actual environment, not just the document.
Area 06
Third-Party & Supply Chain Risk
Which suppliers access your systems or data, what security requirements you place on them, and whether your vendor contracts and data processing agreements reflect your actual exposure. Supply chain compromise is now one of the top three breach vectors across every sector.
Process

From brief call to roadmap in four steps.

The assessment runs remote or on-site depending on your preference. Most organisations complete it within two to three weeks of the initial brief call.

1
Step One
Brief call
30 minutes. We understand your environment, sector, team size, and what you are trying to protect. We scope the assessment to your business, not a generic template.
2
Step Two
Assessment
One to two days. Structured interviews, document and configuration review, and evidence gathering across all six areas. Remote workshops or an on-site visit.
3
Step Three
Written report
Findings for each assessed area, risk-rated by likelihood and impact. Each finding includes what we found, why it matters, and what to do about it. No jargon.
4
Step Four
Roadmap & debrief
A prioritised action plan structured so your IT team or board can act on it immediately. We walk through findings and next steps in a debrief session with your leadership team.
Deliverables

Two documents you can act on immediately.

The output is practical, not decorative. Your IT team picks up the roadmap directly. Your board reads the report without needing a cybersecurity background.

Deliverable 1
Security Assessment Report
A written document covering all six assessed areas. Each section contains what we found, the risk rating, and the rationale. Structured for both a technical reader and a board member who needs to understand exposure without the detail.
Findings across all six assessment areas
Risk ratings by likelihood and business impact
Compliance gap mapping to applicable frameworks
Written for technical teams and board-level readers
Deliverable 2
Prioritised Cybersecurity Roadmap
A structured cybersecurity roadmap covering what to fix first, the effort involved, and which risks each action closes. Sequenced so you tackle the highest-impact items early, regardless of budget. Your IT team picks this up and works from it directly.
Actions ranked by risk reduction and implementation effort
Scoped to your budget, team, and regulatory context
Quick wins separated from longer-term programme items
Ready to hand to your IT team or an external delivery partner
What sets Cyvra apart

Every company gets breached eventually. The ones that recover fast prepared for it.

Most cybersecurity firms focus entirely on prevention. Prevention matters, and we invest heavily in it. But the businesses that suffer the smallest damage from an incident are not the ones with the most tools. They are the ones who built a readiness plan before they needed it.

Every assessment we run includes an incident readiness review. Where gaps exist, we build out the plan. That means your team knows exactly what to do in the first hour of an incident, who calls who, what gets communicated to whom, and how fast you can be back online. Read the full guide to building an incident response plan.

The average time to identify a breach without a plan in place is 194 days. With a tested response procedure, the same incident takes hours to contain.

What an incident readiness plan covers
Step-by-step response playbook
Documented procedures for the most likely incident types: ransomware, data breach, account compromise, supply chain attack.
Escalation paths and contact lists
Who calls who, in what order, at what hour. Leadership, IT, legal, insurers, and regulators: all defined before the incident.
Regulatory notification timelines
GDPR requires 72-hour ICO notification. NIS2 has its own timelines. We document your obligations so you are not researching them during an active incident.
Verified backup and recovery procedures
Documented RTO and RPO targets, tested restore procedures, and immutable backup verification. Tested, not assumed.
Pre-drafted communications
Internal staff notices, customer breach notifications, regulator statements, and media lines: drafted and approved before an incident forces you to write them under pressure.
Is this for you?

You probably need this assessment if…

These are the eight situations we most commonly hear from organisations that come to us. One of them is usually enough. Several of them together suggests the assessment is overdue.

Your last formal security review was more than 12 months ago, or has never happened.
You do not have a confirmed, complete inventory of your systems, devices, and data.
MFA is not verified across all staff accounts and access to critical systems.
You have backups, but have not tested a restore in the past six months.
You are not certain which regulations apply: NIS2, ISO 27001, PCI DSS, GDPR, or sector-specific requirements.
A customer, insurer, or partner has asked for evidence of your security controls and you are not sure what to send them.
You have had a security incident or a near-miss, and you do not fully understand how it happened.
Security gets handled reactively by your IT team: it gets attention after incidents but rarely gets scheduled time or a dedicated budget.
Get started

Book a brief call to scope your assessment.

Tell us about your environment and we will explain exactly what the assessment covers, how it runs, and what you walk away with.