Services / Security Posture Assessment
For those who don’t know where to start
Security Posture Assessment
You know cybersecurity matters, but not where to begin. Is a pentest worthwhile? What does NIS2 require of you? In a few weeks we map where you stand and give you a concrete, prioritised plan.
What you get
- A maturity score per area, so you see where you stand
- Your top 10 risks, explained in plain language
- A roadmap for 30, 90 and 365 days
- Honest advice on which follow-up tests make sense — and which don’t
- A management presentation, also useful for your board or insurer
What we look at
We assess against the CIS Controls and the NIS2 duty-of-care measures (in the Netherlands: the Cyberbeveiligingswet), translated to the reality of a mid-sized organisation.
External attack surface
What does an attacker see from outside? Domains, open ports, forgotten systems and leaked data.
Identity & access
MFA, admin accounts, password policy and how Microsoft 365 / Entra ID is set up.
Endpoints & servers
Patching, endpoint protection and how well systems are hardened.
Backup & recovery
Would you survive a ransomware attack? Offline backups, restore tests and recovery times.
Cloud & SaaS
Configuration of your cloud environments and key SaaS applications.
People & processes
Incident response, supplier management, awareness and who is responsible for what.
How it works
- 01
Kick-off & interviews
We talk to management, IT and, if relevant, your IT partner to understand your organisation and risks.
- 02
Technical checks
A non-intrusive external scan and a review of your configurations using read-only access.
- 03
Analysis
We combine the findings into a picture per area and identify the biggest risks.
- 04
Report & roadmap
We present the results to management, with a plan you can start on right away.
Quick check
Quick check: where do you stand?
Answer seven questions and get a first indication right away. Your answers stay in your browser and are not sent anywhere.
Questions
How long does a Security Posture Assessment take?
Typically two to four weeks end to end, including a few days of your time for interviews and arranging access.
Is this the same as an audit?
No. We don’t certify anything and there’s no pass or fail. The goal is insight and a practical plan. You can use the outcome to prepare for ISO 27001 or NIS2.
Will anything in our systems be changed?
No. We work with read-only access and non-intrusive scans.
What if we already have an IT partner?
That’s fine — we’re happy to involve them. An independent view helps you and your IT partner improve in a focused way.
Curious how an attacker sees your organisation?
Book a no-obligation 30-minute call. We’ll discuss your situation and give honest advice on what makes sense — even if that isn’t work for us.