Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Service

Cybersecurity risk assessment: know what to fix first

A structured review of how your organization manages security risk today, measured against NIST CSF 2.0 and the CIS Controls, ending in a prioritized plan your team can act on.

What we deliver

Security posture and risk assessments mapped to NIST CSF 2.0 and CIS Controls.

References
NIST CSF 2.0CIS Controls v8.1

Who it's for

A good fit for

  • Leadership teams that need an honest baseline before setting a security budget or roadmap
  • Organizations fielding customer security questionnaires they can't confidently answer
  • Companies planning a compliance effort that want to understand their starting point first
  • New security or IT leaders who inherited a program and want an outside view of it
  • Boards and investors asking for a plain-language summary of security risk

Not the right fit for

  • Organizations that need a formal audit report or certificate rather than an advisory assessment
  • Teams that want hands-on exploitation of specific systems, which is penetration testing
  • Teams with a recent, credible assessment that mainly need help carrying it out; the virtual CISO service is a better fit

Problems it addresses

  • Security spending decisions are being made without a shared view of the biggest risks.
  • Different people give different answers about which controls exist and whether they work.
  • Customer questionnaires and insurance applications ask about controls no one has checked.
  • A compliance deadline is approaching, and no one knows how large the gap is.
  • Findings from past reviews were never tracked to closure, so it's unclear what's still open.

Scope

Included

  • Interviews with leadership, IT, engineering, and the people who carry out day-to-day security tasks
  • Review of existing policies, procedures, architecture diagrams, and prior assessment or test reports
  • Evidence sampling to confirm that key controls operate as described, not only that they're documented
  • A current-state profile across the six NIST CSF 2.0 functions: Govern, Identify, Protect, Detect, Respond, and Recover
  • Assessment of the CIS Controls safeguards that fit your size and risk
  • Risk ratings that weigh likelihood, business impact, and the effort needed to fix each issue
  • A readout session where leadership can walk through the results and ask questions

Not included

  • Vulnerability scanning or hands-on exploitation of your systems (available separately as penetration testing)
  • Detailed configuration review of individual cloud accounts (see cloud and application security reviews)
  • Implementing fixes, buying tools, or configuring systems
  • Physical security inspections of offices or facilities

Deliverables

  • Executive summary written for leadership and board audiences
  • NIST CSF 2.0 current-state profile and a recommended target profile
  • CIS Controls safeguard assessment with notes on what was observed
  • Risk register with a rating, a suggested owner, and the reasoning behind each rating
  • Prioritized remediation roadmap grouped into near-term, mid-term, and longer-term work
  • Leadership readout presentation

How the engagement runs

Every engagement begins with a written scope and proposal.

  1. Scope and plan

    We confirm your goals, the business units and systems in scope, the people we'll talk to, and the evidence we'll need.

  2. Gather evidence

    We review documents, hold structured interviews, and sample evidence remotely, using a shared tracker so your team always knows what's outstanding.

  3. Analyze and rate

    We map what we found to NIST CSF 2.0 and the CIS Controls, rate each risk, and draft recommendations.

  4. Validate findings

    We review draft findings with your technical owners to correct misunderstandings before anything is final.

  5. Report and read out

    We deliver the report and roadmap, then walk leadership through the priorities and tradeoffs.

Standards and methods

  • NIST Cybersecurity Framework (CSF) 2.0: current and target profiles across its six functions
  • CIS Critical Security Controls v8.1: specific, prioritized safeguards your technical teams can act on

Current and Target Profiles in NIST CSF 2.0

NIST CSF 2.0, published on February 26, 2024, organizes cybersecurity outcomes into six Functions: Govern, Identify, Protect, Detect, Respond, and Recover. An Organizational Profile describes an organization's posture in terms of those outcomes.

A Current Profile specifies the outcomes an organization is achieving now, and how or to what extent. A Target Profile specifies the outcomes it has selected and prioritized for its risk management objectives, taking into account anticipated changes such as new requirements, new technology, and threat trends. Analyzing the gaps between the two produces a prioritized action plan, and NIST names a risk register among the forms that plan can take.

The Govern Function places the assessment in business context. Its six categories are:

  • Organizational Context (GV.OC)
  • Risk Management Strategy (GV.RM)
  • Roles, Responsibilities, and Authorities (GV.RR)
  • Policy (GV.PO)
  • Oversight (GV.OV)
  • Cybersecurity Supply Chain Risk Management (GV.SC)

Source: NIST CSWP 29, The NIST Cybersecurity Framework (CSF) 2.0 (February 26, 2024)

HIPAA risk analysis vs an organization-wide risk assessment

A HIPAA risk analysis and an organization-wide cybersecurity risk assessment overlap, but they aren't the same exercise.

The HIPAA Security Rule's risk analysis is a required implementation specification with a defined subject: the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) held by a covered entity or business associate (45 CFR 164.308(a)(1)(ii)(A)). Its scope follows the ePHI through the systems, locations, and service providers involved with it.

An organization-wide assessment against a framework such as NIST CSF 2.0 looks at the whole program, including governance, supplier risk, and business systems that never touch ePHI. Each can inform the other, but one doesn't automatically satisfy the other. If HIPAA applies to you, make sure the risk analysis stands on its own and is documented and kept as the rule requires (45 CFR 164.316).

Sources: eCFR: 45 CFR 164.308, administrative safeguards; eCFR: 45 CFR Part 164, Subpart C (HIPAA Security Rule); NIST CSWP 29, The NIST Cybersecurity Framework (CSF) 2.0 (February 26, 2024)

Prerequisites and your responsibilities

  • An executive sponsor who can make decisions and unblock access to people and documents
  • A named coordinator who schedules interviews and tracks evidence requests
  • Time from the people who run IT, engineering, and security operations for interviews
  • Your existing documentation, even if it's incomplete or out of date
  • Candid answers: the assessment is only as useful as the information behind it

Pricing

  • NIST CSF / CIS Controls Risk Assessment

    From $7,500

    Typical scoped range: $7,500 to $18,000

    One-time project

Non-binding. Final pricing follows a written scope and proposal.

What affects the final price

Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.

Compare published prices for every service

An assessment, not an audit

Security Inspect is not a law firm, a CPA firm, or an ISO/IEC 27001 certification body. We don't give legal opinions, issue SOC 2 reports or ISO/IEC 27001 certificates, or guarantee that a client will pass an assessment.

Guides

Frequently asked questions

How is a risk assessment different from a penetration test?

A risk assessment looks across your whole program (governance, people, processes, and technology) and asks whether controls exist and work. A penetration test goes deep on specific systems and tries to exploit weaknesses with your written authorization. Many organizations start with a risk assessment to decide where testing will matter most.

Will this tell us whether we're compliant with SOC 2 or HIPAA?

It shows how your controls line up against NIST CSF 2.0 and the CIS Controls, and we note where findings overlap with the frameworks you care about. It isn't a compliance audit and doesn't produce a compliance opinion. If you're working toward a specific framework, compliance readiness work is the more direct path.

Why use both NIST CSF 2.0 and the CIS Controls?

They answer different questions. NIST CSF 2.0 describes the outcomes a security program should achieve, including governance, and works well for leadership reporting. The CIS Controls are specific, prioritized safeguards that technical teams can act on. Using both gives leadership a program view and engineers a concrete task list.

Do you need access to our systems?

Mostly we need access to people and documents. We may ask for screenshots, configuration exports, or a short screen-sharing session to confirm how a control works. We don't scan or test your systems as part of this service, so we don't need administrative credentials.

What happens after we receive the report?

The roadmap is written so your team can carry it out on its own. Some clients ask us to help oversee the work through the virtual CISO service, or to build policies and evidence routines. Any follow-on work is scoped separately.

Primary sources

Talk to a practitioner about a risk assessment

Share what’s prompting the work and what you need to decide, and we’ll help you judge whether this service is the right fit.

What happens next

  1. Tell us about your environment and what's driving the request.
  2. Talk through goals, constraints, and options with a practitioner.
  3. Review the proposal and decide whether to go ahead.