Cyber Risk Assessment
A structured, standards-aligned method for identifying assets, threats, and vulnerabilities, then rating each risk by likelihood and impact. Risk levels calculate automatically using the NIST SP 800-30 model.
Security governance and assurance work — new artifacts in development.
Assess cyber risk, quantify impact, and audit controls against the standards.
A structured, standards-aligned method for identifying assets, threats, and vulnerabilities, then rating each risk by likelihood and impact. Risk levels calculate automatically using the NIST SP 800-30 model.
A complete controls audit covering all 18 CIS Critical Security Controls v8.1 — 153 safeguards — cross-mapped to NIST CSF 2.0 and ISO/IEC 27001:2022. Score implementation and filter by Implementation Group to scope to your maturity.
Quantify the business consequences of a cyber incident across five impact dimensions, set recovery objectives (RTO/RPO/MTD), and tier each process by criticality. Ratings follow the worst-case rule and feed directly into continuity and recovery planning.
Design and harden the estate — zero trust, networks, and operational technology.
Assess and mature a zero-trust architecture across the five CISA pillars — identity, devices, networks, applications and workloads, and data — plus cross-cutting capabilities. Aligned to NIST SP 800-207 and the CISA Zero Trust Maturity Model 2.0.
Practical, standards-aligned hardening across eight domains — architecture, firewalls, remote access, wireless, device hardening, monitoring, and access control. Each domain pairs best-practice guidance with a step-by-step how-to and a trackable checklist.
Secure operational technology, industrial control systems, and IoT — segmentation and the Purdue model, IEC 62443 zones and conduits, secure remote access, OT-aware patching and monitoring, safety systems, and IoT device hardening.
Secure what you build and what you run in the cloud.
Embed security across the software lifecycle — requirements, threat modeling, secure implementation, testing, release, CI/CD, and AI/LLM applications. Aligned to OWASP ASVS 5.0, the OWASP Top 10:2025, and SAMM.
Assess and harden cloud posture across nine control areas — shared responsibility, identity, data, network, logging, workloads, secrets, and cloud incident response. Aligned to CSA CCM v4.1, CIS Foundations Benchmarks, and provider best practice.
Understand the adversary and protect data in transit and at rest.
Govern cryptography end to end — approved algorithms, the key-management lifecycle, PKI and certificate management, transport security, post-quantum readiness, and crypto governance. Aligned to NIST SP 800-57, FIPS 186-5, and the 2024 post-quantum standards.
Build a threat-informed defense — the intelligence lifecycle and tiers, MITRE ATT&CK, Kill Chain and Diamond models, STIX/TAXII sharing, structured threat modeling with STRIDE and PASTA, and operationalizing intelligence into detection and hunting.
Keep operating through disruption, and recover when it happens.
Build organizational resilience — a continuity program, business impact analysis, recovery strategy and backups, continuity and DR plans, testing and exercises, and plan maintenance. Aligned to ISO 22301 and NIST SP 800-34.