Home / Services / Security & risk assessments
Service

Security & Risk Assessments

An honest read of where your security actually stands — measured against a recognized baseline, and translated into a prioritized list of what to fix first.

What it is

We assess your organization against the CIS Controls v8.1 Implementation Group 1 baseline — the set of safeguards recognized as essential cyber hygiene for smaller organizations. Rather than handing you a 200-page data dump, we identify what’s in place, what’s missing, and what matters most, then give you a remediation roadmap you can work through in order.

What’s included

  • Structured review against the CIS Controls v8.1 IG1 baseline
  • Interviews with the people who actually run your systems
  • Review of existing documentation, configurations, and practices
  • Risk-rated findings with clear business impact explained
  • Prioritized remediation roadmap sequenced by risk and effort
  • Optional mapping to HIPAA, CMMC/NIST SP 800-171, PCI DSS, or other frameworks

Who it’s for

  • Businesses that have never had a formal security assessment
  • Companies facing a client, insurer, or regulator asking about their security posture
  • Organizations preparing for a compliance requirement and unsure where they stand
  • Leadership that wants a straight answer to “how exposed are we?”
Engagement
Starting at $1800
Final pricing depends on the size of your organization and scope. We’ll quote before any work begins.
Request a quote
FormatRemote or on-site
Typical length1–2 days
BaselineCIS Controls v8.1 IG1
DeliverableWritten report + debrief

How It Works

A bounded engagement with a clear start and finish.

  1. Scope

    We agree on what’s in scope — systems, locations, and any compliance frameworks you need mapped.

  2. Discovery

    Short interviews and documentation review with your team. No disruption to daily operations.

  3. Analysis

    We evaluate findings against the baseline and rate each gap by real business risk.

  4. Report

    You receive a written assessment with risk-rated findings and a prioritized roadmap.

  5. Debrief

    A walkthrough session so your team understands the findings and knows what to tackle first.

What You Get

Everything is delivered in plain language, written for owners and managers as well as technical staff.

Common questions

Will this disrupt our operations?

No. An assessment is interviews and document review — we don’t scan, test, or touch production systems as part of this engagement.

Do we need to be technical to get value from it?

Not at all. The report is written so an owner or office manager can act on it, with technical detail available for whoever needs it.

Can you map this to our compliance requirement?

Yes. We can map findings to HIPAA, CMMC/NIST SP 800-171, PCI DSS, and other common frameworks as part of the engagement.

Next step

Let’s scope it together.

Tell us a little about your business and we’ll come back with a clear scope and a fixed quote — no obligation.

Request a quote