01
Scope
Agree the standard and the boundary — which business units, environments, and CIS Implementation Group are in scope — so the assessment fits your risk, not a generic checklist.
Governance & Gap Assessment
We measure your security program against the CIS Controls, score where you stand today, and hand you a board-ready roadmap to close the gaps that carry the most risk — in business terms, not a scanner dump.
Why It Matters
A gap assessment answers the questions leadership actually asks: how mature is our security program, how do we compare to a recognized standard, and where should the next dollar go? It turns a sprawling security picture into a scored, defensible view you can take to a board, an auditor, or an insurer.
We measure against the CIS Controls — a widely adopted, prioritized baseline — scoped to the Implementation Group that fits your size and risk. You get a current-state maturity score, the specific gaps to your target, and a sequenced plan to close them.
Measured against a standard, not an opinion. Scoring your program against the CIS Controls means the result is comparable year over year, explainable to non-technical stakeholders, and useful as evidence when a customer or cyber insurer asks how you manage risk.
The Framework
Five steps, from scope to a roadmap your team can execute and your board can follow.
01
Agree the standard and the boundary — which business units, environments, and CIS Implementation Group are in scope — so the assessment fits your risk, not a generic checklist.
02
Gather evidence: interviews, document and policy review, and control walkthroughs. We map what actually exists today to each CIS Safeguard — not what the diagram claims.
03
Rate each domain's current maturity against the standard, producing a defensible baseline you can compare against next year and explain to non-technical stakeholders.
04
Set the target maturity and measure the distance to it, domain by domain. The gaps are ranked by the risk they carry, so the biggest exposures surface first.
05
A sequenced remediation plan — what to fix, in what order, and roughly what it takes — plus a governance cadence to keep the program improving after we leave.
→
A maturity picture your board understands and your team can act on — the same current-vs-target view shown in the radar above, backed by a prioritized roadmap.
Assessment Services
01
Your security practices scored against the CIS Controls and Safeguards, aligned to the Implementation Group appropriate for your size and risk, with a practical path to the next level of maturity.
02
A broader view of the whole program: what is in place, what is missing, what is working, and where investment produces the most risk reduction — framed for the people who set budget and priorities.
03
A design-level review of how controls are layered to enforce the trust boundaries they are meant to — identity, network, cloud, and data protection — assessed as strategy, not a configuration audit.
Need the technical picture too? Hands-on validation — vulnerability assessments, network and firewall review, and demonstrated attack paths — lives on the tactical side. See Penetration Testing & technical assessments.
Deliverables
Board-ready output that a leadership team can act on without needing a translator, backed by the detail your practitioners need.
Whether it is a full CIS Controls gap assessment, a program-level review, or evidence for an insurer or customer, we will scope it to your size and risk.