Skip to content
Red Vault
Layered acrylic sheets, an inspection lens, a metal ruler, and a red finding marker

Assess

Cybersecurity Assessment.

A clear starting point for your security.

What is a cybersecurity assessment?

A cybersecurity assessment is a structured review of how your organisation protects its systems, data and day-to-day operations. We look at your policies, responsibilities and existing security controls to establish what is in place and what needs attention.

When an assessment is useful

Your business may have grown faster than its security processes, inherited systems from different providers, or received questions from a customer that are difficult to answer. An assessment helps when you need to understand your current security posture before choosing a solution, setting a budget or committing to a larger project.

What the review involves

We connect what your documents say with how your organisation works: who is responsible for security, how access is approved and removed, and how important systems and data are protected. Conversations with your team, existing policies and agreed samples of evidence help establish that picture. We distinguish what we can confirm from what is reported or still needs checking.

What you take away

A documented view of your security today, with practical recommendations in priority order.

Your current security position
What is in place, where gaps exist and what still needs checking.
Priorities with business context
Recommended actions, why they matter and which areas need a closer technical review.
A plan your team can use
Next steps we discuss with you, ready to take forward with your own team or chosen provider.
Conceptual architectural image of a contemporary office facade, with consistent stone frames and reflective windows.

Your first step towards a clearer security plan.

You do not need to know which security service to buy. We start with your situation, review the available evidence and explain the work worth considering.

The action plan is yours to use with your own team or a provider you choose. Any further work with Red Vault is optional and agreed separately.

Explore assessment examples

What we review in your organisation

We review the policies, systems and working practices that shape your security. The areas below guide the conversation; we agree which to examine and the level of detail before work begins.

  • Policies & responsibilities

    • Security policies & responsibilities
    • Risk decisions & review routines
    • Supplier security expectations
  • Systems & access

    • Key systems, cloud services & data
    • User, administrator & supplier access
    • Account lifecycle & access reviews
  • Protective controls

    • Device protection & patching
    • Security settings & network separation
    • Logging, alerts & escalation
  • Incident readiness

    • Response plans & responsibilities
    • Backups & evidence of recovery checks
    • Critical dependencies & communication

Evidence behind the recommendations.

We combine team interviews, document review and agreed samples of control evidence. Each finding distinguishes what we observed, what was reported and what still needs checking.

We organise the review using the relevant parts of NIST CSF 2.0.

A clear scope from the start.

This is a current-state review, not a penetration test or certification audit. Detailed technical investigations and implementation are separate work. The report records the scope and limits of the evidence.

Assessment examples

Explore how a review could address a specific need. Your assessment can combine relevant areas within an agreed scope.

Select a focus to explore the review and its outputs.

Establish your current security position.

When it is useful: You want a starting point for improving security, but are not yet sure where the main gaps are.

What we review

  • Your key systems, data and business dependencies.
  • Existing policies, responsibilities and protective controls.
  • Available evidence of access reviews, monitoring and incident preparation.

What you receive

  • A current-state summary of what is in place and what remains unclear.
  • A prioritised list of gaps and practical improvements.
  • Recommendations for any areas that need a more detailed review.

These are example scopes, not fixed packages or client case studies. The depth of review and deliverables are agreed in your proposal.

How your cybersecurity assessment works

We agree the scope, review your current security and discuss the recommendations with you. The process is designed around the information available and the decisions you need to make.

  1. Agree the scope

    We agree the business questions, review areas and depth. Your proposal sets out the evidence needed, access, price and schedule.

  2. Review your security

    We speak with the people responsible and examine the agreed documents and control evidence. We check inconsistencies and make missing information visible.

  3. Discuss the findings

    We explain the findings, test recommendations against your constraints and walk through an action plan your team or chosen provider can carry forward.

Before you book.

What does a cybersecurity assessment cover?

It reviews how your organisation manages security today: policies and responsibilities, key systems and access, protective controls, monitoring, and incident readiness. We agree which areas to examine and how deeply before starting. The result is a current-state view and a prioritised action plan.

How much does it cost, and how long does it take?

The scope, number of systems and teams, and availability of evidence determine the work. We agree the price, review schedule and deliverables in a proposal. Tell us about any customer, planning or due-diligence deadline so we can shape a useful scope and confirm availability.

What if our documentation is incomplete?

Bring what you have. Policies, a system list, diagrams and recent reports are useful starting points. We agree interviews and walkthroughs to fill in the picture, and clearly mark what remains unverified. Creating a full inventory or rewriting policies can be scoped separately if needed.

Will you need access to our systems?

We start with conversations, documents and agreed evidence. Any system access, configuration review or additional checks are defined in the scope and authorised before use. The assessment does not include changes to your live environment.

Is this a penetration test or a certification audit?

No. The assessment reviews your wider security posture and helps decide what to improve. A penetration test examines a defined application or network for exploitable weaknesses. A certification audit has its own requirements and assessor criteria. Share any formal requirement before booking so we can establish whether this review is suitable.

Can Red Vault help with the recommended work?

Yes, where it fits our services. We can discuss a separate engagement after the assessment. Your action plan describes the work and can be used by your own team or another provider. Implementation is optional, with its own scope and price; buying the assessment does not commit you to further services.

How is our information handled?

We agree confidentiality, access, secure transfer and evidence retention before the review. Tell us about your data-handling requirements during scoping. We request the evidence needed for the agreed questions and discuss how sensitive material can be shared appropriately.

Related security services

An assessment helps identify where further work may be useful. These services can address specific needs highlighted by the review.

Further work is optional, with its own scope and price. The assessment does not commit you to another service.

Let’s find your starting point.

Tell us about your organisation and what you want to understand. We’ll help define a useful review and come back with a proposal.

contact@redvault.co.uk

How we handle your details: Privacy policy.