Discover
Establish the operational contextIdentify critical services, material risks, dependencies and the outcomes leadership needs the assessment to prove.
ResnSec360 assessment platform
ResnSec360 runs 22 assessments across cybersecurity, resilience, governance, and emerging technology. One six-phase method, from scoping and evidence collection through control testing to executive reporting.
Aligned with NIST CSF 2.0, ISO 27001, CIS Controls, and Zero Trust architecture principles.
Core Cybersecurity
Security baseline and control assurance.The portfolio in numbers
22
Assessments
Across the full resilience lifecycle.
4
Categories
From core cybersecurity to emerging technology.
6
Phases
In every engagement, scoping to reporting.
7
Deliverables
Board-ready, in every assessment.
5
Maturity levels
One scale across the whole portfolio.
The assurance gap
Scanners and dashboards surface individual weaknesses. A structured assessment connects them: evidence is collected, controls are tested, findings are validated with their owners, and the result is a maturity picture the board can defend.
Controls tested for design and operating effectiveness, not just documented.
Continuity, recovery, and crisis capability validated through evidence and exercises.
Findings translated into owned actions, maturity targets, and board-level reporting.
The portfolio
The portfolio follows a practical sequence: establish control assurance, validate continuity and recovery, strengthen governance and compliance, then address emerging technology risk.
Security baseline and control assurance.
Checks whether the organization has the basic cybersecurity and IT control foundation needed to protect systems, users, data, and networks.
Business survival, recovery readiness, and operational resilience.
Checks whether the business can continue operating and recover critical services during disruption, outage, cyberattack, disaster, or crisis.
Accountability, oversight, compliance evidence, and risk-informed decisions.
Checks whether technology and cyber risks are properly owned, measured, reported, governed, and aligned with regulations, contracts, and business risk appetite.
Future readiness and controlled innovation.
Checks whether new technologies such as AI, GenAI, IoT, and OT are adopted safely, securely, ethically, and under proper governance.
Phase 1 of 6
Activity
Confirm business units, systems, locations, vendors, assessment objectives, stakeholders, and success criteria.
Output
Approved scope, stakeholder list, assessment plan, and document request list.
Phase 2 of 6
Activity
Review policies, procedures, system configurations, audit logs, architecture diagrams, contracts, recovery plans, and prior audit findings.
Output
Evidence inventory and initial control observations.
Phase 3 of 6
Activity
Conduct interviews with IT, security, risk, compliance, business continuity, legal, procurement, and business process owners.
Output
Validated process understanding, control ownership, and dependency mapping.
Phase 4 of 6
Activity
Evaluate design effectiveness, operating effectiveness, maturity level, risk exposure, and control gaps.
Output
Assessment results, maturity ratings, and risk-ranked findings.
Phase 5 of 6
Activity
Discuss findings with control owners to confirm accuracy, context, root cause, and remediation feasibility.
Output
Management-validated findings and agreed action owners.
Phase 6 of 6
Activity
Prepare a board-level summary, heatmap, roadmap, risk themes, and priority decisions.
Output
Final board report, action plan, and implementation roadmap.
The continuous assurance loop
Identify critical services, material risks, dependencies and the outcomes leadership needs the assessment to prove.
Translate business priorities into clear boundaries, stakeholders, systems, control objectives and evidence requirements.
Collect policies, configurations, records and interviews once, then map every artefact to the controls it supports.
Challenge whether controls are appropriately designed, consistently performed and effective against the stated risk.
Rank validated gaps by business impact and effort, with accountable owners, target dates and measurable outcomes.
Confirm progress, refresh maturity, preserve the evidence trail and report whether resilience is improving over time.
Assurance feeds the next assessment cycle—keeping evidence, priorities and board oversight current as risks change.
An engagement in action
Objectives, stakeholders, and systems agreed up front, with a document request list so nothing is collected twice.
Policies, configurations, and logs reviewed; process owners interviewed; dependencies mapped.
Controls tested for design and operation; every finding confirmed with the people who own it.
Maturity scorecard, risk heatmap, remediation roadmap, and an action plan with owners and dates.
| Deliverable | Purpose |
|---|---|
| Executive Summary | Board-level view of current state, major risks, priority actions, and decisions required. |
| Assessment Report | Detailed findings, evidence reviewed, control gaps, maturity scores, and observations. |
| Risk Heatmap | Visual prioritization of high, medium, and low risks by likelihood and impact. |
| Maturity Scorecard | Capability rating by domain, category, or control area. |
| Remediation Roadmap | Prioritized action plan with owners, timelines, dependencies, and expected risk reduction. |
| Management Action Plan | Agreed corrective actions, accountable owners, target dates, and a tracking mechanism. |
| Board Dashboard | Concise metrics for ongoing oversight, trend monitoring, and investment decisions. |
Framework alignment
Every engagement is scoped to your context. When clients ask where to start, this is the sequence we most often recommend.
ITCA (IT Controls Assessment)
Establishes the IT control baseline.
BCDR Assessment
Confirms business continuity and technology recovery readiness.
Business Impact Analysis
Defines critical services, dependencies, RTO, and RPO.
Cyber Resilience Assessment
Connects cyberattack scenarios with business recovery capability.
NIST CSF 2.0 and Cybersecurity Maturity
Provide recognized cyber maturity scoring and executive reporting.
Zero Trust Assessment
Strengthens identity, access, segmentation, and continuous verification.
IT Risk and Third-Party Risk
Translate technical and supplier gaps into business risk and accountability.
AI Risk, AI Security, and GenAI Readiness
Control modern AI adoption risks before they become unmanaged exposure.
A scoping conversation is the fastest way to find out. Tell us your organisation, your role, and the assessments you are considering; we will come back with a proposed scope, stakeholder list, and document request list.