The challenge behind the engagement.
This service answers which risks deserve money and attention first. We match the method to your obligations and add dollar-based loss ranges when the board wants figures. We interview owners, review your architecture, prior test findings, and incident history, then sample the controls that matter most: multi-factor authentication coverage across your identities, endpoint protection, backup and restore testing, and privileged account cleanup in your directory and cloud environment. Threat scenarios come from real attacker paths, such as a stolen password leading to a mailbox takeover, ransomware through exposed remote access, or a compromised vendor. You receive a risk register, a written assessment report, and a treatment plan with owners and due dates. The register covers the agreed scope, not every risk you carry.
For compliance leads, CISOs, and CFOs who must document a formal risk assessment for a regulator, an auditor, or a cyber insurance application, and for leadership teams deciding next year’s security budget. Typical triggers: a first regulated contract, an acquisition, a board request for a risk picture, or an incident that exposed an unrated exposure.
What we do.
What you can use.
Frame the risk model
We agree the purpose, the business units, systems, and data types in scope, then fix the risk model in writing: the threat sources, the events we worry about, the likelihood and impact scales, and whether the approach is descriptive, scored, or fully quantitative. Your obligations pick the frame, so the method lines up with what your auditor or regulator expects to see.
Interview, sample, and rate
Typically two to four hours of interviews per business function, a document review, and direct sampling of control state across your identity, endpoint, backup, and cloud environments with read-only access. Each scenario is written as an attacker path, rated for likelihood and impact on the agreed scale, and given an inherent and a residual score with existing controls listed.
Assign owners and hand over the register
Each risk receives an owner, a treatment decision to mitigate, transfer, accept, or avoid, the specific controls that address it, an effort estimate, a target date, and an expected residual risk. You receive the register in a clear, portable format, the written assessment report, and a heat map, and we walk your risk owners through all of it.
Who it’s for.
When you need it.
- Compliance leads who must document a risk assessment for an auditor or regulator
- CFOs and leadership teams deciding where next year's security budget should go
- Firms entering a regulated market that requires a formal, repeatable risk analysis
- CISOs needing a defensible, rated picture of enterprise risk for the board
- A first contract, framework, or regulation now mandates a documented risk analysis
- An acquisition brings systems and exposures nobody has yet rated
- An incident revealed a serious risk that no assessment had captured
- Budget planning starts and leadership needs risks ranked by reduction value
What the scope can include.
- 01
Purpose, scope, assumptions, and risk model documented before interviews begin
- 02
Owner interviews and review of architecture, data flows, prior pentest and audit findings, and incident history
- 03
Direct sampling of multi-factor authentication coverage, endpoint protection, backup restore tests, privileged accounts, and logging
- 04
Threat scenarios written as attacker paths and rated for likelihood and impact on the agreed scale
- 05
Treatment plan with owner, option, mapped controls, effort, target date, and residual risk per item
- 06
Dollar-based loss ranges with stated assumptions when quantitative output is requested
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.
Under 50 employees, one location, mostly cloud or managed IT
About 40–60 hours50–250 employees, a few departments or sites, mix of cloud and office systems
About 80–120 hours250–1,000 employees, several business units or locations, regulated data
About 140–200 hours- Number of business units, locations, and systems in scope
- Which regulations or frameworks the assessment has to satisfy
- Whether the board wants dollar-based loss estimates instead of a rated heat map
- How current your documentation, asset list, and prior test results are
3–6 weeks for small and mid-size scopes; 6–10 weeks for large
Get a fixed quote for your scopeRanges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Risk register with scenario, threat source, vulnerability, existing controls, likelihood, impact, inherent and residual rating, owner, and due date
- A written assessment report in a clear, repeatable structure, with a heat map or a ranked risk list
- Treatment plan sequenced by how much risk each fix removes for the effort it takes, with the controls named
- Executive summary written for a board pack, a cyber insurance application, or a public-company disclosure process
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
Does this satisfy the risk analysis our regulator, auditor, or framework requires?
The method is aligned to the common requirements: we match it to your framework or regulation, and one register can serve several obligations at once when the scope is set that way. Whether the result is sufficient is decided by your compliance owner, auditor, or assessor, not by us. One boundary matters if you are pursuing a formal certification: if the principal performs your risk assessment, that same principal cannot later serve as your independent assessor, and we say so at scoping.
How is this different from a penetration test or a gap assessment?
A penetration test finds paths an attacker can exploit today and proves them. A gap assessment checks whether required controls exist against one standard. A risk assessment weighs threat scenarios against their likelihood and their impact on your business, decides which to mitigate, transfer, accept, or avoid, and assigns owners and spending. Test findings and gap results feed the register as evidence of weaknesses and control state. If the board wants figures, we add dollar-based loss ranges with the assumptions shown rather than a single number.
- NIST CSWP 29: The NIST Cybersecurity Framework (CSF) 2.0
- NIST Cybersecurity Framework 2.0: Quick-Start Guide for Creating and Using Organizational Profiles
- NIST SP 800-30 Rev. 1: Guide for Conducting Risk Assessments
- NIST IR 8286 Rev. 1: Integrating Cybersecurity and Enterprise Risk Management (ERM)
- CIS Critical Security Controls Version 8.1
- ISO/IEC 27005:2022 - Guidance on managing information security risks
- Cross-Sector Cybersecurity Performance Goals
