Why it matters
Many organizations don't have a security team. They have an IT person, a managed service provider, or a handful of tools that someone set up years ago — and no clear idea whether any of it is working.
A security posture analysis gives you an outside, experienced view across your whole environment. It's built on years of running security operations and responding to real incidents, so the recommendations focus on what attackers actually do, not theoretical risks.
Is this right for you?
This service is a good fit if:
- You don't know where to start with security
- You've never had an outside review of your security
- You're applying for or renewing cyber insurance
- You're preparing for a sale, merger, investment, or due diligence
- You've changed IT providers and want an independent check
What's included
Identity and access
How accounts, passwords, multi-factor authentication, and administrator access are managed.
Endpoints and email
Protection on laptops, servers, and email — the most common entry points for attacks.
Backup and recovery
Whether you could actually recover from ransomware or a major outage, and how quickly.
Logging, monitoring, and response
Whether you would notice an attack, and what would happen next.
Cloud and network configuration
A review of key settings in your cloud services and network.
People and process
Security awareness, onboarding and offboarding, vendor access, and incident readiness.
What you receive
- Plain-language posture report with a scorecard by area
- Top findings ranked by risk
- Quick wins you can act on immediately
- A 30/60/90-day improvement plan
- Read-out session with your team
How it works
- 1
Review
Questionnaire, document review, and conversations with your IT team or provider.
- 2
Evaluate
Assess controls across each area and compare them against recognized benchmarks like CIS Controls.
- 3
Report
Deliver a scorecard, ranked findings, and quick wins.
- 4
Enhance
Agree on a practical improvement plan sized to your budget.
Common questions
Do you need access to our systems?
Usually only read-only access or screen-sharing sessions with your IT team. We never make changes to your environment without your written approval.
Will this help with cyber insurance?
Yes. The analysis covers the controls insurers most often ask about, such as multi-factor authentication, backups, endpoint protection, and incident response.
How is this different from a risk assessment?
A posture analysis is a faster, broad health check focused on controls. A risk assessment goes deeper on specific threats, likelihood, and business impact. Many clients start with a posture analysis.