Skip to main content

The assessment portfolio

22 assessments in four categories, covering the full lifecycle from scoping and evidence collection through interviews, control testing, and validation to executive reporting.

Core Cybersecurity

5 assessments

Checks whether the organization has the basic cybersecurity and IT control foundation needed to protect systems, users, data, and networks.

  • NIST CSF 2.0 Assessment

    Creates a structured view of cyber risk management capability using a globally recognized framework.

  • Cybersecurity Maturity Assessment

    Assesses how mature the organization is across governance, asset management, identity, protection, detection, response, and recovery.

  • Zero Trust Assessment

    Determines whether the organization verifies every user, device, application, and access request before granting access.

  • Vulnerability Assessment

    Identifies technical weaknesses in systems, applications, networks, endpoints, cloud platforms, and exposed services.

  • Penetration Testing

    Simulates controlled attack scenarios to validate whether vulnerabilities can be exploited and what business impact they may create.

More about Core Cybersecurity

Resilience & Continuity

9 assessments

Checks whether the business can continue operating and recover critical services during disruption, outage, cyberattack, disaster, or crisis.

  • ITCA (IT Controls Assessment)

    Determines whether the IT control environment is properly designed, implemented, and operating effectively.

  • BCDR Assessment

    Determines whether critical business operations and technology services can be recovered within acceptable time and data-loss limits.

  • Business Impact Analysis (BIA)

    Defines what must be recovered first, how quickly, and what resources are required.

  • Cyber Resilience Assessment

    Assesses whether the organization can withstand, respond to, and recover from cyberattacks.

  • Incident Response Assessment

    Determines whether the organization can detect, contain, investigate, communicate, and recover from incidents effectively.

  • Crisis Management Assessment

    Determines whether the organization can lead, decide, and communicate effectively when a disruption escalates beyond routine incident handling.

  • Continuity & Recovery Strategy Assessment

    Determines whether recovery strategies match the recovery priorities and tolerances the business has defined.

  • Plan Development Assessment

    Determines whether continuity, recovery, and response plans are complete, current, actionable, and aligned with the agreed strategy and BIA outputs.

  • Testing, Exercises & Validation Assessment

    Determines whether continuity and recovery capability has been proven through realistic testing rather than assumed from documentation.

More about Resilience & Continuity

Governance, Risk & Compliance

4 assessments

Checks whether technology and cyber risks are properly owned, measured, reported, governed, and aligned with regulations, contracts, and business risk appetite.

More about Governance, Risk & Compliance

Emerging Technology

4 assessments

Checks whether new technologies such as AI, GenAI, IoT, and OT are adopted safely, securely, ethically, and under proper governance.

  • AI Risk Assessment

    Identifies broad business, operational, legal, ethical, privacy, and governance risks from AI adoption.

  • AI Security Assessment

    Assesses how AI systems can be attacked, misused, manipulated, or used to expose sensitive data.

  • GenAI Readiness Assessment

    Determines whether the organization is ready to safely use generative AI tools and internal LLM systems.

  • IoT / OT Security Assessment

    Assesses cyber and operational risk in connected physical, industrial, and operational technology environments.

More about Emerging Technology

Not sure where to begin? The methodology page explains how each assessment runs, and a scoping conversation will map the portfolio to your context.