Service
Virtual CISO
Security leadership without a full-time hire
Service
A structured review of how your organization manages security risk today, measured against NIST CSF 2.0 and the CIS Controls, ending in a prioritized plan your team can act on.
What we deliver
Security posture and risk assessments mapped to NIST CSF 2.0 and CIS Controls.
Every engagement begins with a written scope and proposal.
We confirm your goals, the business units and systems in scope, the people we'll talk to, and the evidence we'll need.
We review documents, hold structured interviews, and sample evidence remotely, using a shared tracker so your team always knows what's outstanding.
We map what we found to NIST CSF 2.0 and the CIS Controls, rate each risk, and draft recommendations.
We review draft findings with your technical owners to correct misunderstandings before anything is final.
We deliver the report and roadmap, then walk leadership through the priorities and tradeoffs.
NIST CSF 2.0, published on February 26, 2024, organizes cybersecurity outcomes into six Functions: Govern, Identify, Protect, Detect, Respond, and Recover. An Organizational Profile describes an organization's posture in terms of those outcomes.
A Current Profile specifies the outcomes an organization is achieving now, and how or to what extent. A Target Profile specifies the outcomes it has selected and prioritized for its risk management objectives, taking into account anticipated changes such as new requirements, new technology, and threat trends. Analyzing the gaps between the two produces a prioritized action plan, and NIST names a risk register among the forms that plan can take.
The Govern Function places the assessment in business context. Its six categories are:
Source: NIST CSWP 29, The NIST Cybersecurity Framework (CSF) 2.0 (February 26, 2024)
A HIPAA risk analysis and an organization-wide cybersecurity risk assessment overlap, but they aren't the same exercise.
The HIPAA Security Rule's risk analysis is a required implementation specification with a defined subject: the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) held by a covered entity or business associate (45 CFR 164.308(a)(1)(ii)(A)). Its scope follows the ePHI through the systems, locations, and service providers involved with it.
An organization-wide assessment against a framework such as NIST CSF 2.0 looks at the whole program, including governance, supplier risk, and business systems that never touch ePHI. Each can inform the other, but one doesn't automatically satisfy the other. If HIPAA applies to you, make sure the risk analysis stands on its own and is documented and kept as the rule requires (45 CFR 164.316).
Sources: eCFR: 45 CFR 164.308, administrative safeguards; eCFR: 45 CFR Part 164, Subpart C (HIPAA Security Rule); NIST CSWP 29, The NIST Cybersecurity Framework (CSF) 2.0 (February 26, 2024)
Read the full guide: HIPAA security risk analysis: what the rule requires
From $7,500
Typical scoped range: $7,500 to $18,000
One-time project
Non-binding. Final pricing follows a written scope and proposal.
Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.
Security Inspect is not a law firm, a CPA firm, or an ISO/IEC 27001 certification body. We don't give legal opinions, issue SOC 2 reports or ISO/IEC 27001 certificates, or guarantee that a client will pass an assessment.
A risk assessment looks across your whole program (governance, people, processes, and technology) and asks whether controls exist and work. A penetration test goes deep on specific systems and tries to exploit weaknesses with your written authorization. Many organizations start with a risk assessment to decide where testing will matter most.
It shows how your controls line up against NIST CSF 2.0 and the CIS Controls, and we note where findings overlap with the frameworks you care about. It isn't a compliance audit and doesn't produce a compliance opinion. If you're working toward a specific framework, compliance readiness work is the more direct path.
They answer different questions. NIST CSF 2.0 describes the outcomes a security program should achieve, including governance, and works well for leadership reporting. The CIS Controls are specific, prioritized safeguards that technical teams can act on. Using both gives leadership a program view and engineers a concrete task list.
Mostly we need access to people and documents. We may ask for screenshots, configuration exports, or a short screen-sharing session to confirm how a control works. We don't scan or test your systems as part of this service, so we don't need administrative credentials.
The roadmap is written so your team can carry it out on its own. Some clients ask us to help oversee the work through the virtual CISO service, or to build policies and evidence routines. Any follow-on work is scoped separately.
Share what’s prompting the work and what you need to decide, and we’ll help you judge whether this service is the right fit.