Services / Security Posture Assessment

For those who don’t know where to start

Security Posture Assessment

You know cybersecurity matters, but not where to begin. Is a pentest worthwhile? What does NIS2 require of you? In a few weeks we map where you stand and give you a concrete, prioritised plan.

What you get

  • A maturity score per area, so you see where you stand
  • Your top 10 risks, explained in plain language
  • A roadmap for 30, 90 and 365 days
  • Honest advice on which follow-up tests make sense — and which don’t
  • A management presentation, also useful for your board or insurer

What we look at

We assess against the CIS Controls and the NIS2 duty-of-care measures (in the Netherlands: the Cyberbeveiligingswet), translated to the reality of a mid-sized organisation.

External attack surface

What does an attacker see from outside? Domains, open ports, forgotten systems and leaked data.

Identity & access

MFA, admin accounts, password policy and how Microsoft 365 / Entra ID is set up.

Endpoints & servers

Patching, endpoint protection and how well systems are hardened.

Backup & recovery

Would you survive a ransomware attack? Offline backups, restore tests and recovery times.

Cloud & SaaS

Configuration of your cloud environments and key SaaS applications.

People & processes

Incident response, supplier management, awareness and who is responsible for what.

How it works

  1. 01

    Kick-off & interviews

    We talk to management, IT and, if relevant, your IT partner to understand your organisation and risks.

  2. 02

    Technical checks

    A non-intrusive external scan and a review of your configurations using read-only access.

  3. 03

    Analysis

    We combine the findings into a picture per area and identify the biggest risks.

  4. 04

    Report & roadmap

    We present the results to management, with a plan you can start on right away.

Quick check

Quick check: where do you stand?

Answer seven questions and get a first indication right away. Your answers stay in your browser and are not sent anywhere.

01Do you have a complete overview of all systems reachable from the internet?
02Is MFA enforced for all accounts, including admins?
03Have your applications or infrastructure been tested by an external party in the past 12 months?
04Do you have offline or immutable backups, and do you regularly test restores?
05Do you know whether NIS2 / the Cyberbeveiligingswet applies to your organisation?
06Does your organisation build its own software or web applications?
07Do you use AWS, Azure or Google Cloud (besides Microsoft 365)?

Questions

How long does a Security Posture Assessment take?

Typically two to four weeks end to end, including a few days of your time for interviews and arranging access.

Is this the same as an audit?

No. We don’t certify anything and there’s no pass or fail. The goal is insight and a practical plan. You can use the outcome to prepare for ISO 27001 or NIS2.

Will anything in our systems be changed?

No. We work with read-only access and non-intrusive scans.

What if we already have an IT partner?

That’s fine — we’re happy to involve them. An independent view helps you and your IT partner improve in a focused way.

Curious how an attacker sees your organisation?

Book a no-obligation 30-minute call. We’ll discuss your situation and give honest advice on what makes sense — even if that isn’t work for us.