Latest alerts
  1. Home
  2. Services
  3. Get compliant
  4. Risk Assessment
// get compliant · compliance & grc

Cyber Risk Assessment & Security Posture Review

A clear, board-ready picture of your cyber risk: what you have, what threatens it, how well you are protected and which investments reduce the most risk per rupee.

NIST CSF 2.0ISO/IEC 27005ISO 31000CIS Controls v8.1
// the problem

Without a risk view, security spending follows the loudest vendor or the latest headline. Leadership needs priorities, not a list of 300 findings.

// scope

What we cover

Asset & data inventory

Systems, data stores, vendors and cloud services that matter to the business.

Threat modelling

Likely attackers and scenarios for your industry — ransomware, fraud, insider, supply chain.

Control assessment

Maturity scoring against NIST CSF 2.0 functions: Govern, Identify, Protect, Detect, Respond, Recover.

Third-party risk

Vendor and outsourcing review with practical contract clauses.

Risk register

Likelihood × impact scoring with owners and treatment decisions.

Roadmap

A 12-month, budget-aware plan with quick wins first.

// how it works

Five clear steps, no surprises

01

Discover

Map data, systems, vendors and gaps.

02

Plan

Risk-based roadmap with owners.

03

Implement

Policies, controls and evidence.

04

Verify

Internal audit and readiness check.

05

Certify

Stand with you through the audit.

// deliverables

What you get

  • Executive risk briefing
  • Risk register and heat-map
  • NIST CSF 2.0 maturity scorecard
  • Prioritised 12-month roadmap
// standards & frameworks
NIST CSF 2.0ISO/IEC 27005ISO 31000CIS Controls v8.1
// engagement models

Pick how you'd like to work with us

Gap assessment

Two to four weeks: where you stand and a prioritised roadmap.

Most popular

End-to-end programme

From gap assessment to audit-ready, with your team trained.

Virtual CISO / DPO support

Ongoing monthly support to keep evidence current.

Every engagement starts with a free scoping call and a fixed, written quote.

// faq

Common questions

Is this the same as an audit?
No. An audit checks compliance against a standard. A risk assessment tells you where you are most likely to be hurt and what to do about it — which also makes later audits easier.
Get a quoteCall
// ready when you are

Find out how an attacker sees you — before they do.

Book a free 30-minute scoping call with our security team. No sales script, just an honest view of your risk and what to do first.

Call Email Under attack? Free DPDP Check