The assessment portfolio
22 assessments in four categories, covering the full lifecycle from scoping and evidence collection through interviews, control testing, and validation to executive reporting.
Core Cybersecurity
5 assessments
Checks whether the organization has the basic cybersecurity and IT control foundation needed to protect systems, users, data, and networks.
-
NIST CSF 2.0 Assessment
Creates a structured view of cyber risk management capability using a globally recognized framework.
-
Cybersecurity Maturity Assessment
Assesses how mature the organization is across governance, asset management, identity, protection, detection, response, and recovery.
-
Zero Trust Assessment
Determines whether the organization verifies every user, device, application, and access request before granting access.
-
Vulnerability Assessment
Identifies technical weaknesses in systems, applications, networks, endpoints, cloud platforms, and exposed services.
-
Penetration Testing
Simulates controlled attack scenarios to validate whether vulnerabilities can be exploited and what business impact they may create.
Resilience & Continuity
9 assessments
Checks whether the business can continue operating and recover critical services during disruption, outage, cyberattack, disaster, or crisis.
-
ITCA (IT Controls Assessment)
Determines whether the IT control environment is properly designed, implemented, and operating effectively.
-
BCDR Assessment
Determines whether critical business operations and technology services can be recovered within acceptable time and data-loss limits.
-
Business Impact Analysis (BIA)
Defines what must be recovered first, how quickly, and what resources are required.
-
Cyber Resilience Assessment
Assesses whether the organization can withstand, respond to, and recover from cyberattacks.
-
Incident Response Assessment
Determines whether the organization can detect, contain, investigate, communicate, and recover from incidents effectively.
-
Crisis Management Assessment
Determines whether the organization can lead, decide, and communicate effectively when a disruption escalates beyond routine incident handling.
-
Continuity & Recovery Strategy Assessment
Determines whether recovery strategies match the recovery priorities and tolerances the business has defined.
-
Plan Development Assessment
Determines whether continuity, recovery, and response plans are complete, current, actionable, and aligned with the agreed strategy and BIA outputs.
-
Testing, Exercises & Validation Assessment
Determines whether continuity and recovery capability has been proven through realistic testing rather than assumed from documentation.
Governance, Risk & Compliance
4 assessments
Checks whether technology and cyber risks are properly owned, measured, reported, governed, and aligned with regulations, contracts, and business risk appetite.
-
IT Risk Assessment
Creates a risk register with likelihood, impact, existing controls, residual risk, and treatment actions.
-
Third-Party Risk Assessment (TPRM)
Assesses risk introduced by suppliers, outsourced providers, technology partners, and critical service providers.
-
Regulatory Compliance Assessment
Determines whether the organization can demonstrate compliance and close control gaps before audits or regulatory reviews.
-
Data Privacy Assessment / DPIA
Identifies privacy risks in systems, processes, projects, or data-driven initiatives.
Emerging Technology
4 assessments
Checks whether new technologies such as AI, GenAI, IoT, and OT are adopted safely, securely, ethically, and under proper governance.
-
AI Risk Assessment
Identifies broad business, operational, legal, ethical, privacy, and governance risks from AI adoption.
-
AI Security Assessment
Assesses how AI systems can be attacked, misused, manipulated, or used to expose sensitive data.
-
GenAI Readiness Assessment
Determines whether the organization is ready to safely use generative AI tools and internal LLM systems.
-
IoT / OT Security Assessment
Assesses cyber and operational risk in connected physical, industrial, and operational technology environments.
Not sure where to begin? The methodology page explains how each assessment runs, and a scoping conversation will map the portfolio to your context.