An assessment is only useful if management knows what to do with the results. We would rather identify ten findings in the right order than hand a business a hundred-page report with no clear priority.
What we look for
A flat list of findings is not a roadmap. We rank issues by business impact, likelihood, exposure and dependencies so management can separate what needs attention now from what belongs in the next quarter or the next budget cycle.
A cybersecurity assessment creates a current-state picture of how a business protects technology and information.
The assessment should identify meaningful risk and produce a prioritized improvement plan.
Asset Inventory
Review computers, servers, network equipment, cloud systems and other business-connected assets.
Software Inventory
Identify operating systems and major applications.
Look for unsupported software and applications that are no longer required.
Identity and Access
Review:
- User accounts
- Administrative accounts
- MFA
- Shared accounts
- Former employees
- Password and authentication policy
- Privileged access
- Remote access
Microsoft 365
Review tenant security, administrative roles, authentication, email protections, sharing, applications, logs and device access.
Endpoints
Review patching, endpoint security, disk encryption, local administrators and security configuration.
Network
Review firewalls, wireless, remote access, internet exposure, segmentation and management interfaces.
Data Protection
Identify sensitive information and how access, storage, retention and disposal are managed.
Backup and Recovery
Review what is protected, retention, isolation, administration, recovery priorities and restore testing.
Logging and Monitoring
Determine whether important security events are collected, retained and reviewed.
Vendor Risk
Identify vendors with access to systems or sensitive data.
Document access and offboarding procedures.
Incident Response
Review whether the business has a written response plan, cyber-insurance information, legal contacts and recovery priorities.
Policies and Evidence
Assess whether technical controls are supported by written policies and evidence.
Risk Prioritization
Not every issue has the same importance.
Findings should be prioritized according to likelihood, business impact, exposure and effort required to remediate.
What Should the Final Report Include?
A useful assessment should include:
- Executive summary
- Current strengths
- Critical risks
- High-priority findings
- Medium and long-term recommendations
- Owners
- Target timelines
- Estimated project dependencies
- Framework mapping where appropriate
Assessment Versus Penetration Test
A cybersecurity assessment evaluates controls and risk broadly.
A penetration test actively tests whether defined systems can be exploited.
Both can be valuable, but they answer different questions.
Sources and further reading
This guide references current primary-source material. Requirements and product capabilities can change, so verify current source guidance before implementation.
