Services

    Cyber Risk Surveys

    Our cyber risk surveys provide a strategic assessment of your organization's security posture, identifying gaps in governance, technology, and process that drive enterprise risk.

    Assessment Approach

    Structured risk discovery designed for enterprise environments.

    1

    Enterprise-wide risk discovery and mapping

    2

    Stakeholder interviews and control surveys

    3

    Risk visibility across business units and functions

    4

    Technology and process maturity evaluation

    5

    Third-party and supply chain risk assessment

    Analysis & Prioritization

    Risk-based prioritization frameworks that guide investment and remediation decisions.

    Risk heatmaps and exposure visualization

    Prioritization frameworks aligned to business impact

    Gap analysis against industry frameworks

    Maturity scoring and benchmarking

    Executive-ready risk reporting

    Scope of Discovery

    What a Thorough Risk Survey Covers

    Every organization's environment is different - so every risk survey is scoped to match. Depending on your infrastructure, industry, and risk profile, a comprehensive assessment may span any combination of the following areas.

    1. Perimeter & Network Security

    Server & network infrastructure

    Core infrastructure vulnerabilities across all network segments.

    Firewall configuration

    Rule integrity, legacy gaps, and segmentation logic.

    Remote access (VPN / RDP)

    Security of remote connections from branches and remote workers.

    Wireless network

    Exposure to physical perimeter bypass via Wi-Fi.

    Email & web filtering

    Whether malicious content reaches your users.

    2. Endpoints, Cloud & Identity

    Asset discovery & mapping

    What exists on your network - including shadow IT and unmanaged devices.

    Endpoint security

    Device protection, patch levels, and compliance posture.

    Cloud & SaaS environments

    Configuration, identity, and data security in cloud platforms.

    Identity & access management

    Who has access to what, and whether least-privilege is enforced.

    3. Assessment & Attack Simulation

    External attack surface

    What is reachable and exploitable from the internet.

    Internal penetration testing

    Whether an attacker can move laterally once inside your environment.

    Human vector (phishing simulation)

    Whether your people are the weakest link in practice.

    Security architecture

    Whether the overall design is sound and defensible.

    4. Resilience, Governance & Remediation

    Ransomware readiness

    Detection, containment, and recovery capability under attack conditions.

    Backup & recovery

    Whether backups are tested, isolated, and actually restorable.

    Policy & governance

    Whether written policies match operational reality.

    Remediation tracking

    How findings are assigned, tracked, and verified as resolved.

    Scope is agreed in writing before every engagement. We will never assess an area without telling you in advance - and we will never omit a critical area without explaining why.

    Survey Process

    Start to finish in 45 working days

    Kickoff & Scoping

    • Define survey scope and organizational boundaries
    • Identify key stakeholders and interview subjects
    • Gather existing documentation, policies, and architecture
    • Confirm objectives and reporting requirements

    Data Collection & Assessment

    • Conduct stakeholder interviews across departments
    • Perform technical assessment of infrastructure and controls
    • Evaluate governance, policies, and process maturity
    • Assess third-party risk and supply chain exposure

    Analysis & Risk Profiling

    • Correlate findings across all assessment dimensions
    • Score maturity against industry frameworks
    • Build risk heat maps and exposure profiles
    • Identify quick wins and strategic priorities

    Reporting & Recommendations

    • Executive summary with business risk context
    • Detailed technical findings and gap analysis
    • Prioritized investment and remediation roadmap
    • Board-ready presentation materials

    What You Receive

    Tangible, actionable outputs designed for both technical teams and executive leadership.

    Executive Risk Report

    Board-ready summary of your security posture and top risks.

    Prioritised Remediation Roadmap

    Actions ranked by risk reduction impact, not technical severity.

    Regulatory Gap Matrix

    Your current compliance posture against each relevant framework.

    Investment Guidance

    Indicative cost ranges for each priority remediation action.

    Pricing

    Fixed price based on organisation size and survey scope.

    // Engagement$8,000 - $22,000per engagement (remote + on-site)Duration: 2-4 weeks
    Book a Cyber Risk Survey

    Ready to know where you stand?

    Tell us about your organisation and we'll send a proposal within 48 hours.

    Start a conversation