06 · Assess · Rank · Roadmap
Security Risk Assessment
A defensible view of your enterprise risk.
A structured, framework-aligned assessment of your organization's security posture across people, process, and technology. The deliverable is a prioritized risk register plus a phased remediation roadmap your board can approve — grounded in NIST SP 800-30 and ISO 27005 risk methodology, not a consultant's gut feel.
Outcomes
- +Enterprise-wide risk register with likelihood × impact scoring
- +Gap analysis against your chosen framework (NIST CSF, ISO 27001, HIPAA, PCI)
- +18-month remediation roadmap with effort × cost estimates
- +Board-ready summary and engineer-ready detail
01Scope
What we cover
In scope
- +Governance, policies, and organizational structure
- +Asset inventory + data-classification review
- +Access control + IAM + privileged access management
- +Vulnerability management + change management processes
- +Incident response + business continuity + disaster recovery
- +Third-party risk management
- +Physical + environmental controls (interview-based)
Out of scope
- −Deep technical testing (see Vulnerability Assessment, Pen Testing)
- −On-site physical inspection (available as add-on)
02Approach
How the engagement runs
Framework selection
NIST CSF? ISO 27001? HIPAA? PCI DSS? A hybrid? We help you pick the one that matches your regulators and industry.
Evidence gathering
Interviews, policy review, control-configuration review, sample-based testing. Two-week window, typically.
Gap analysis
Every control mapped, evidenced, and scored — organized by control family and business function.
Risk quantification
Each gap translated to a risk statement with likelihood, impact, and inherent-vs-residual scoring (NIST SP 800-30 method).
Roadmap
Phased remediation: quick wins, medium-term projects, strategic initiatives — each sized.
03Deliverables
What you receive
Every artifact is defensible under external audit and actionable for engineering.
- 01Enterprise Risk Register (spreadsheet + PDF summary)
- 02Framework Gap Analysis matrix
- 03Executive board deck (10–15 slides)
- 04Remediation Roadmap with quarterly milestones
- 05Optional annual reassessment engagement
04Frameworks
Regulator-defensible mapping
05Timeline
Typical engagement pace
Scoping
1 week
Evidence gathering
2–3 weeks
Analysis + scoring
1–2 weeks
Roadmap + delivery
1 week
06FAQ
Common questions
Different question? Raise it on a scoping call — we'd rather flag surprises early.
Is this the same as an audit?+
No. An SRA is a gap-analysis + risk-quantification exercise designed to feed remediation planning. An audit is an independent-attestation exercise. Many organizations run an SRA to prepare for audit.
How is this different from a Vulnerability Assessment?+
A VA is technical — which vulnerabilities exist. An SRA is holistic — which risks exist across people, process, and technology, and how they should be prioritized.
Can we use this to inform ISO 27001 certification?+
Yes. The output is designed to feed your ISO 27001 Statement of Applicability inputs and risk-treatment plan directly.
Ship a defensible risk story.
Board-ready output, auditor-defensible methodology, engineer-executable roadmap. Typical delivery: 6–8 weeks.
Book a scoping call