A security risk assessment answers one question: if someone went after your business tomorrow, where would they get in, and what would it cost you? It is a point-in-time review, done by a person, that ends with a written list of what to fix and in what order.
What gets looked at
An assessment follows the same paths an attacker or a ransomware incident would take.
- The network edge. Firewalls, VPN appliances, and anything reachable from the internet, including things nobody remembers opening.
- Workstations and servers. Whether they are patched, whether any are past end-of-support, and whether endpoint protection is installed and updating.
- How people sign in. Shared logins, administrator accounts, and whether anything beyond a password protects remote access.
- Backups. Not just whether they run, but whether anyone has restored from them recently.
- Email. Whether your domain can be impersonated, and what filtering stands between a phishing message and your staff.
Part of this is a vulnerability scan, which checks your systems against known weaknesses. The scan is evidence, not the assessment. A scanner cannot tell you that three people share one admin password or that the backups have never been tested.
What you get at the end
- A written findings report. Each finding says what we found, why it matters to the business, the evidence, and the recommended fix.
- A priority order. Findings are ranked by risk, with a suggested owner and timeline, so the first week's work is obvious.
- The raw scan export. The evidence behind the report, which you can hand to an insurer or auditor.
- A walkthrough. A conversation in plain English about what it all means and what can wait.
You can see exactly what these look like in our sample reports.
What an assessment is not
- It is not a penetration test. A pen test has someone actively try to break in. An assessment finds and ranks the weaknesses without exploiting them, which is the better first step for most small businesses.
- It is not a compliance certificate. It tells you where you stand. If you need to be ready for a HIPAA, PCI DSS, or SOC 2 audit, that is compliance readiness work, and the assessment is usually where it starts.
- It is not a guarantee. It describes your environment on the day it was done. Things change, which is why it is worth repeating each year.
How to get the most from one
- Say what worries you. If an insurance renewal or a client questionnaire prompted this, bring it.
- Give access to someone who knows the systems, even informally. An hour of their time saves days of guessing.
- Ask for the priority order in writing. A list of forty findings with no ranking is not much use.
- Decide who owns the fixes before the report arrives, so it does not sit in a drawer.