You can’t improve what you haven’t measured, and you can’t justify what you can’t explain to the board. The Assess pillar delivers a structured, benchmarked view of your current posture — people, process and technology — and a prioritised plan to close the gaps that matter most.
Where are we actually exposed? How do we compare to similar organisations? And what are the two or three things that, done this quarter, would most reduce our risk? The Assess pillar answers those with evidence, not opinion — in a fixed scope and a predictable timescale.
A structured four-week engagement that baselines your security operation against CIS Controls and the continuous SecOps model. Delivers a prioritised remediation list, a board-ready summary and a 90-day plan.
Focused testing of specific systems or applications by UK-based testers. Reports written for the people who act on them — technical detail for engineers, executive summary for the board.
A broader review against ISO 27001, Cyber Essentials Plus or a custom control set — for when procurement, an auditor or a board risk committee has asked for independent assurance.
A baseline. Four weeks, fixed scope, board-ready output — and a 30-minute scoping call before you commit to anything.