A structured, fixed-scope engagement that baselines your current security operation against CIS Controls and the 3Gi Continuous Security Framework. You get a prioritised remediation list, a board-ready summary and a 90-day plan. It is how almost every Managed Security engagement with us begins.
Four weeks, four stages, one outcome you can take straight to the board. No open-ended discovery, no generic audit template we run on every client — scoped to your environment, your risk profile and your leadership team’s actual questions.
Structured interviews with your IT, security and operations leads. Review of existing documentation, tooling, policies and incident history. Technical data collection from Entra ID, Defender, Sentinel and your key SaaS platforms.
Gap analysis against the 18 CIS Controls and the continuous SecOps model. Review of detection coverage, automation maturity, governance completeness and incident-response readiness.
Comparison against comparable UK mid-market organisations. Identification of the two or three interventions that would most reduce your risk this quarter.
A 30-page report, a 10-slide board summary and a 90-day plan with owners and dependencies. A two-hour findings workshop with your leadership team. And no hard sell — if what you need isn’t us, we’ll tell you.
The Readiness Assessment is a fixed-scope, fixed-fee engagement. Pricing depends on organisation size and complexity, and is shared before you book. It is not a free teaser — and it is not a generic audit template. It is scoped to your environment, your risk profile and your leadership team’s questions.
A 30-minute scoping call first, no obligation. Then four weeks to a baselined view of your posture and a practical plan to improve it.