Proposal
CIS Controls
An assessment of your security against the CIS Controls, the reference the market uses to measure the real state. We build the inventory, check each safeguard against what is actually configured, score it with the evidence attached, and hand over the plan in the order that cuts risk fastest. It is the measurement that carries a budget request to the board, and the evidence produced here goes on to an ISO 27001 or SOC 2 project intact.
No price appears on this page. Scope does: what we do, how we run it, who runs it and what is not included. The people who read your request are the ones who will look after you, and they come back with the proposal and with time to talk it through.
CIS Controls
Stop arguing about security from impressions. Measure it.
How we run it
What this work consists of
We measure your security against the CIS Controls, the benchmark the market uses to describe actual state. The review goes safeguard by safeguard, against what is actually configured rather than what the policy says, and every score comes with the evidence attached. That evidence is what sustains the budget request with the board and holds up under challenge.
The work starts with the asset and software inventory, because you cannot measure what nobody knows exists. Almost every company discovers unregistered equipment and software at this stage, and that finding alone pays for the step. Then come the measurement and the plan in the order that reduces risk fastest, with the reasoning behind each position.
Your choice of Implementation Group defines how far the yardstick reaches, from the essential hygiene that stops most real-world attacks to the scope for companies with critical environments and dedicated adversaries. The larger groups add the maturity analysis and the board presentation, and the third adds implementation and an evolution roadmap with a deadline per control.
We ask for access to the people who administer the environment, the configurations, and the records that support each score. What comes out of this does not die in the report: the evidence carries straight into an ISO 27001 or SOC 2 project later, and the measurement is comparable in the next round, so progress shows up as a number, not a perception.
How we conduct it, stage by stage
Opening assessment
A snapshot of the starting point: what exists, what is written down and what actually works. Progress will be measured against it at the end of the period, so we record it with method, not from memory.
Asset inventory
We find out what exists before measuring anything. Almost every company discovers hardware and software here that nobody had on record, and that finding alone pays for the stage.
Control measurement
We check each safeguard against what is actually configured, not against what the policy says. Every score comes with the evidence behind it.
Maturity analysis
We compare the practice with what each discipline calls for and assign the score, with the criteria in the open.
Presentation
A meeting with leadership translating the technical result into business risk and investment decisions. We arrive with the answers to the questions the board always asks: what to attack first, how much effort it takes and what happens if nothing is done.
What is not included
- Implementing the controls identified, which comes in as its own project or as CISO as a Service
- Purchasing and licensing the tools the measurement points to: the buying decision is yours, our role is to say what the tool needs to cover
- Ongoing operation of whatever gets implemented, which stays with your team or comes in as a separate service
- Penetration testing outside Group 3: in Groups 1 and 2 we measure maturity, we do not exploit vulnerabilities
- Fixing configurations during the measurement: changing the environment mid-measurement invalidates the comparison with the next round
- Certification or attestation: the CIS Controls are a measurement framework; when a standard requires an audit, the auditing is done by an independent body
- Assessing your vendors' security, which is its own third-party risk engagement
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.