The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
Governance and compliance
Stop arguing about security from impressions. Measure it.
We measure your security against the CIS Controls, the benchmark the market uses to describe actual state. The review goes safeguard by safeguard, against what is actually configured rather than what the policy says, and every score comes with the evidence attached. That evidence is what sustains the budget request with the board and holds up under challenge.
The work starts with the asset and software inventory, because you cannot measure what nobody knows exists. Almost every company discovers unregistered equipment and software at this stage, and that finding alone pays for the step. Then come the measurement and the plan in the order that reduces risk fastest, with the reasoning behind each position.
Your choice of Implementation Group defines how far the yardstick reaches, from the essential hygiene that stops most real-world attacks to the scope for companies with critical environments and dedicated adversaries. The larger groups add the maturity analysis and the board presentation, and the third adds implementation and an evolution roadmap with a deadline per control.
We ask for access to the people who administer the environment, the configurations, and the records that support each score. What comes out of this does not die in the report: the evidence carries straight into an ISO 27001 or SOC 2 project later, and the measurement is comparable in the next round, so progress shows up as a number, not a perception.
The stages and deliverables below describe the Group 2: when there is a team and third party data modality. The other modalities appear when you request the proposal.
Opening assessment
A snapshot of the starting point: what exists, what is written down and what actually works. Progress will be measured against it at the end of the period, so we record it with method, not from memory.
Asset inventory
We find out what exists before measuring anything. Almost every company discovers hardware and software here that nobody had on record, and that finding alone pays for the stage.
Control measurement
We check each safeguard against what is actually configured, not against what the policy says. Every score comes with the evidence behind it.
Maturity analysis
We compare the practice with what each discipline calls for and assign the score, with the criteria in the open.
Presentation
A meeting with leadership translating the technical result into business risk and investment decisions. We arrive with the answers to the questions the board always asks: what to attack first, how much effort it takes and what happens if nothing is done.
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.