A security risk assessment answers one question: if someone went after your business tomorrow, where would they get in, and what would it cost you? It is a point-in-time review, done by a person, that ends with a written list of what to fix and in what order.

What gets looked at

An assessment follows the same paths an attacker or a ransomware incident would take.

  • The network edge. Firewalls, VPN appliances, and anything reachable from the internet, including things nobody remembers opening.
  • Workstations and servers. Whether they are patched, whether any are past end-of-support, and whether endpoint protection is installed and updating.
  • How people sign in. Shared logins, administrator accounts, and whether anything beyond a password protects remote access.
  • Backups. Not just whether they run, but whether anyone has restored from them recently.
  • Email. Whether your domain can be impersonated, and what filtering stands between a phishing message and your staff.

Part of this is a vulnerability scan, which checks your systems against known weaknesses. The scan is evidence, not the assessment. A scanner cannot tell you that three people share one admin password or that the backups have never been tested.

What you get at the end

  • A written findings report. Each finding says what we found, why it matters to the business, the evidence, and the recommended fix.
  • A priority order. Findings are ranked by risk, with a suggested owner and timeline, so the first week's work is obvious.
  • The raw scan export. The evidence behind the report, which you can hand to an insurer or auditor.
  • A walkthrough. A conversation in plain English about what it all means and what can wait.

You can see exactly what these look like in our sample reports.

What an assessment is not

  • It is not a penetration test. A pen test has someone actively try to break in. An assessment finds and ranks the weaknesses without exploiting them, which is the better first step for most small businesses.
  • It is not a compliance certificate. It tells you where you stand. If you need to be ready for a HIPAA, PCI DSS, or SOC 2 audit, that is compliance readiness work, and the assessment is usually where it starts.
  • It is not a guarantee. It describes your environment on the day it was done. Things change, which is why it is worth repeating each year.

How to get the most from one

  • Say what worries you. If an insurance renewal or a client questionnaire prompted this, bring it.
  • Give access to someone who knows the systems, even informally. An hour of their time saves days of guessing.
  • Ask for the priority order in writing. A list of forty findings with no ranking is not much use.
  • Decide who owns the fixes before the report arrives, so it does not sit in a drawer.

Locked down. Not locked in.

Tell us what you're dealing with. We'll work out what you need and give you a fixed-price quote. Scoping conversations are free, and we reply within 24 hours.