Skip to main content

ResnSec360 assessment platform

Assessment evidence your board can act on.

ResnSec360 runs 22 assessments across cybersecurity, resilience, governance, and emerging technology. One six-phase method, from scoping and evidence collection through control testing to executive reporting.

Aligned with NIST CSF 2.0, ISO 27001, CIS Controls, and Zero Trust architecture principles.

02 / 05

Core Cybersecurity

Security baseline and control assurance.

The portfolio in numbers

22

Assessments

Across the full resilience lifecycle.

4

Categories

From core cybersecurity to emerging technology.

6

Phases

In every engagement, scoping to reporting.

7

Deliverables

Board-ready, in every assessment.

5

Maturity levels

One scale across the whole portfolio.

The assurance gap

Point tools find issues. An assessment proves resilience.

Scanners and dashboards surface individual weaknesses. A structured assessment connects them: evidence is collected, controls are tested, findings are validated with their owners, and the result is a maturity picture the board can defend.

Control assurance

Controls tested for design and operating effectiveness, not just documented.

Recovery readiness

Continuity, recovery, and crisis capability validated through evidence and exercises.

Board governance

Findings translated into owned actions, maturity targets, and board-level reporting.

The portfolio

Four categories, one maturity journey

The portfolio follows a practical sequence: establish control assurance, validate continuity and recovery, strengthen governance and compliance, then address emerging technology risk.

How every assessment runs

  1. Phase 1 of 6

    Scope and Planning

    Activity

    Confirm business units, systems, locations, vendors, assessment objectives, stakeholders, and success criteria.

    Output

    Approved scope, stakeholder list, assessment plan, and document request list.

  2. Phase 2 of 6

    Evidence Collection

    Activity

    Review policies, procedures, system configurations, audit logs, architecture diagrams, contracts, recovery plans, and prior audit findings.

    Output

    Evidence inventory and initial control observations.

  3. Phase 3 of 6

    Interviews and Workshops

    Activity

    Conduct interviews with IT, security, risk, compliance, business continuity, legal, procurement, and business process owners.

    Output

    Validated process understanding, control ownership, and dependency mapping.

  4. Phase 4 of 6

    Control and Maturity Testing

    Activity

    Evaluate design effectiveness, operating effectiveness, maturity level, risk exposure, and control gaps.

    Output

    Assessment results, maturity ratings, and risk-ranked findings.

  5. Phase 5 of 6

    Validation

    Activity

    Discuss findings with control owners to confirm accuracy, context, root cause, and remediation feasibility.

    Output

    Management-validated findings and agreed action owners.

  6. Phase 6 of 6

    Executive Reporting

    Activity

    Prepare a board-level summary, heatmap, roadmap, risk themes, and priority decisions.

    Output

    Final board report, action plan, and implementation roadmap.

Read the full methodology

The continuous assurance loop

From detection to verified recovery—continuously.

ResnSec360 connects discovery, evidence, control testing, remediation priorities and executive assurance through one defensible assessment process.
01 / 06

Discover

Establish the operational context

Identify critical services, material risks, dependencies and the outcomes leadership needs the assessment to prove.

02 / 06

Scope

Focus assurance where it matters

Translate business priorities into clear boundaries, stakeholders, systems, control objectives and evidence requirements.

03 / 06

Evidence

Build a traceable body of proof

Collect policies, configurations, records and interviews once, then map every artefact to the controls it supports.

04 / 06

Test

Verify design and operation

Challenge whether controls are appropriately designed, consistently performed and effective against the stated risk.

05 / 06

Prioritize

Turn findings into owned action

Rank validated gaps by business impact and effort, with accountable owners, target dates and measurable outcomes.

06 / 06

Assure

Give the board a defensible view

Confirm progress, refresh maturity, preserve the evidence trail and report whether resilience is improving over time.

An engagement in action

From first call to board pack

  1. Step 1: Scoping call

    Objectives, stakeholders, and systems agreed up front, with a document request list so nothing is collected twice.

  2. Step 2: Evidence and interviews

    Policies, configurations, and logs reviewed; process owners interviewed; dependencies mapped.

  3. Step 3: Testing and validation

    Controls tested for design and operation; every finding confirmed with the people who own it.

  4. Step 4: Board pack

    Maturity scorecard, risk heatmap, remediation roadmap, and an action plan with owners and dates.

How maturity is scored

1 Initial / Ad Hoc
Controls are informal, inconsistent, undocumented, or dependent on individual effort.
2 Developing
Some controls exist, but coverage, ownership, testing, or evidence is incomplete.
3 Defined
Controls are documented, assigned, and implemented across most relevant areas.
4 Managed
Controls are monitored, tested, measured, and supported by regular reporting.
5 Optimized
Controls are continuously improved, automated where practical, and aligned with risk appetite and business resilience objectives.

What every assessment delivers

Deliverables included with each assessment
Deliverable Purpose
Executive Summary Board-level view of current state, major risks, priority actions, and decisions required.
Assessment Report Detailed findings, evidence reviewed, control gaps, maturity scores, and observations.
Risk Heatmap Visual prioritization of high, medium, and low risks by likelihood and impact.
Maturity Scorecard Capability rating by domain, category, or control area.
Remediation Roadmap Prioritized action plan with owners, timelines, dependencies, and expected risk reduction.
Management Action Plan Agreed corrective actions, accountable owners, target dates, and a tracking mechanism.
Board Dashboard Concise metrics for ongoing oversight, trend monitoring, and investment decisions.

Framework alignment

  • NIST CSF 2.0
  • ISO 27001
  • CIS Controls
  • PCI DSS
  • GDPR
  • Zero Trust architecture principles

Where clients typically begin

Every engagement is scoped to your context. When clients ask where to start, this is the sequence we most often recommend.

  1. 1

    ITCA (IT Controls Assessment)

    Establishes the IT control baseline.

  2. 2

    BCDR Assessment

    Confirms business continuity and technology recovery readiness.

  3. 3

    Business Impact Analysis

    Defines critical services, dependencies, RTO, and RPO.

  4. 4

    Cyber Resilience Assessment

    Connects cyberattack scenarios with business recovery capability.

  5. 5

    NIST CSF 2.0 and Cybersecurity Maturity

    Provide recognized cyber maturity scoring and executive reporting.

  6. 6

    Zero Trust Assessment

    Strengthens identity, access, segmentation, and continuous verification.

  7. 7

    IT Risk and Third-Party Risk

    Translate technical and supplier gaps into business risk and accountability.

  8. 8

    AI Risk, AI Security, and GenAI Readiness

    Control modern AI adoption risks before they become unmanaged exposure.

Could you evidence your resilience to the board tomorrow?

A scoping conversation is the fastest way to find out. Tell us your organisation, your role, and the assessments you are considering; we will come back with a proposed scope, stakeholder list, and document request list.