Service
Cybersecurity risk assessment
Map your real exposure, rank risks by business impact and deliver a roadmap your board can defend.
The problem we solve
Organizations invest in technical controls without knowing which ones actually reduce their exposure. The result: a security budget that is hard to justify, repeat audit findings, and decisions made under pressure after an incident.
Who it is for
- Organizations of 50 to 1,000 employees with no full-time security leader
- Companies responding to a client, insurer or regulator questionnaire
- Leadership teams needing a baseline before committing a multi-year budget
What is included
- Interviews with business and IT stakeholders
- Document review (policies, contracts, architecture)
- Inventory of critical assets and supplier dependencies
- Gap analysis against NIST CSF 2.0 and CIS Controls v8.1
- Findings workshop with leadership
Our approach
We work in four stages: scoping the perimeter and impact criteria, three to four weeks of collection, a gap analysis mapped to a public framework, then a workshop where every risk is arbitrated with you. No finding is delivered without a recommendation costed in effort and time.
Typical deliverables
Assessment report
30 to 50 pages, French or English
Risk register
Ranked by business impact and likelihood
12–24 month roadmap
Actions costed in effort, budget and sequence
Executive summary
4 pages, board-ready
Expected outcomes
- A shared view of risk across IT, leadership and the business
- A defensible security budget tied to named risks
- A documented answer to client and insurer questionnaires
- A baseline to measure progress the following year