Domain 04 of six

Cybersecurity

This domain establishes what you are protecting, what is protecting it, and where the gap between those two sits. It is a governance assessment, not a product recommendation.

Why it matters

The problem this addresses

Security spending tends to follow whatever was most recently in the news, or whatever the last supplier presented. That produces strong controls in some places and nothing at all in others, with no way to tell which is which.

The question worth answering is not whether you have security tools. It is whether the controls you hold match the exposure you actually carry, and whether you could demonstrate that to somebody who asked.

Scope

What we examine

  • What information you hold, where it sits, and who can reach it
  • The security policy suite, and whether it reflects how people really work
  • Control coverage against the exposure identified, not against a generic list
  • Access, joiners and leavers, and privileged accounts
  • Incident response: who is called, in what order, and whether that has been rehearsed
  • Awareness, because most incidents begin with an ordinary person doing an ordinary thing
Assessed against
A five-level maturity scale, applied against recognised frameworks selected to suit the domain. Framework alignment is a statement of method, not a certification claim.
ISO/IEC 27001
Information security management, controls and the statement of applicability.
NIST Cybersecurity Framework
Identify, Protect, Detect, Respond and Recover.

Assessment

Included in the Assessment

Fixed scope, agreed in writing before work begins. Findings your leadership can act on within ten working days of the final interview.

  • Maturity rating for this domain on the five-level scale
  • Security policy suite, written to be read by the people expected to follow it
  • Controls gap assessment against your actual exposure
  • Prioritised remediation plan, ranked by consequence
  • A position you can present to an oversight committee or a regulator
Price
SCR 20,000 to 40,000 for this domain, VAT exclusive. Where it sits in that band depends on the size and scope of your organisation, not on which domain you choose. Fixed and agreed in writing before work begins. All six domains together are quoted on request, priced as six with a discount for taking the whole position at once.
What that price does not include
Building what the assessment recommends. That is a separate engagement, scoped and quoted against what you need, and it is where most of the work usually sits. See below.
Evidence gathered
Structured interviews across executive, finance, technology and one business function, plus document and systems review.
Turnaround
Ten working days from the final interview.

What this does not include

We do not sell, resell or install security products, and we do not carry out penetration testing. This is deliberate. An assessment of your control coverage is worth more when the organisation carrying it out has nothing to sell you at the end of it. Where testing or a product is genuinely needed, we will say so and you can procure it independently.

Implementation

Available as an Implementation Engagement

An assessment that ends at a report has done half the job. Most organisations know roughly what is wrong. What they lack is the time and the specialist capacity to fix it while also running the organisation.

In this domain that means

  • Write the policy suite and take it through approval
  • Work the remediation plan with your team, in priority order
  • Design and run the first incident rehearsal
How it is priced
Quoted on request. Fixed scope and fixed fee, agreed in writing before work begins. We do not work on an open-ended basis.
Independence
Assessment and implementation are separately scoped engagements, quoted and agreed in writing before either begins. Keeping them separate is deliberate. It is what allows the assessment to stay independent, and it means you are never presented with findings that happen to recommend more of our own work. Where we have implemented something, any later re-assessment of that work says so plainly.

Where does this sit for you today?

If you are not sure whether this domain is a priority, the Quick Diagnosis takes about two minutes and gives you a position on the page. Nothing is sent anywhere.