Resources

Business Cybersecurity Assessment Guide

What a business cybersecurity assessment should review: assets, identities, Microsoft 365, endpoints, networks, backups, logging, vendors, policies and incident readiness.

An assessment is only useful if management knows what to do with the results. We would rather identify ten findings in the right order than hand a business a hundred-page report with no clear priority.

What we look for

A flat list of findings is not a roadmap. We rank issues by business impact, likelihood, exposure and dependencies so management can separate what needs attention now from what belongs in the next quarter or the next budget cycle.

A cybersecurity assessment creates a current-state picture of how a business protects technology and information.

The assessment should identify meaningful risk and produce a prioritized improvement plan.

Asset Inventory

Review computers, servers, network equipment, cloud systems and other business-connected assets.

Software Inventory

Identify operating systems and major applications.

Look for unsupported software and applications that are no longer required.

Identity and Access

Review:

  • User accounts
  • Administrative accounts
  • MFA
  • Shared accounts
  • Former employees
  • Password and authentication policy
  • Privileged access
  • Remote access

Microsoft 365

Review tenant security, administrative roles, authentication, email protections, sharing, applications, logs and device access.

Endpoints

Review patching, endpoint security, disk encryption, local administrators and security configuration.

Network

Review firewalls, wireless, remote access, internet exposure, segmentation and management interfaces.

Data Protection

Identify sensitive information and how access, storage, retention and disposal are managed.

Backup and Recovery

Review what is protected, retention, isolation, administration, recovery priorities and restore testing.

Logging and Monitoring

Determine whether important security events are collected, retained and reviewed.

Vendor Risk

Identify vendors with access to systems or sensitive data.

Document access and offboarding procedures.

Incident Response

Review whether the business has a written response plan, cyber-insurance information, legal contacts and recovery priorities.

Policies and Evidence

Assess whether technical controls are supported by written policies and evidence.

Risk Prioritization

Not every issue has the same importance.

Findings should be prioritized according to likelihood, business impact, exposure and effort required to remediate.

What Should the Final Report Include?

A useful assessment should include:

  • Executive summary
  • Current strengths
  • Critical risks
  • High-priority findings
  • Medium and long-term recommendations
  • Owners
  • Target timelines
  • Estimated project dependencies
  • Framework mapping where appropriate

Assessment Versus Penetration Test

A cybersecurity assessment evaluates controls and risk broadly.

A penetration test actively tests whether defined systems can be exploited.

Both can be valuable, but they answer different questions.

Sources and further reading

This guide references current primary-source material. Requirements and product capabilities can change, so verify current source guidance before implementation.

Ready to move forward?

Want help applying this to your business?

We can look at your current environment and tell you which parts of this guide matter most for you.

Talk With Huff Data