Skip to main content
YavoraInnovations
Open menu

Practice 02

Cyber Security Assessment

An honest picture of where you stand, mapped to a framework your board and your customers already recognise.

Engagement shapes

  • Focused review

    2 weeks

  • Full programme assessment

    4 to 8 weeks

  • Certification readiness

    6 to 10 weeks

  • Advisory retainer

    Monthly

Who this is for

  • Security leaders inheriting a programme they did not design
  • Companies preparing for ISO 27001 or SOC 2
  • Teams whose last assessment was a scan report rather than an assessment

The problem

A scanner tells you what is broken on the day it ran. It does not tell you whether the programme that produced the breakage will produce it again next quarter.

Boards ask for a position against a recognised framework. Engineering asks for a backlog it can actually schedule. Most assessments serve one audience and leave the other unconvinced.

The gap is usually evidence discipline. Findings without a named artifact behind them get argued away, and nothing changes.

What we do

The workstreams in an engagement

01

Programme maturity assessment

Measured against NIST CSF 2.0, ISO 27001, or CIS Controls v8, with the evidence recorded behind each score.

02

Application security review

SDLC gates, SAST, SCA and secrets coverage, threat modelling practice, and dependency and supply-chain posture.

03

Cloud and infrastructure posture

Identity, network, data, and workload configuration across the accounts that matter.

04

Identity and access review

Human and non-human identities, service credentials, privilege paths, and joiner-mover-leaver reality against policy.

05

Third-party risk process

How vendors are assessed, what evidence is kept, and what happens when a vendor fails.

06

Incident readiness

A facilitated tabletop exercise, with findings written into an updated runbook.

07

Certification readiness

Gap-to-readiness for ISO 27001 or SOC 2, sequenced against your target audit date.

Deliverables

What lands on your desk

You keep all of it, including the method behind it, so the work can be repeated without us.

  • Maturity scorecard by function, with the evidence behind each score
  • Risk register scored by likelihood and impact, owned and dated
  • Prioritised remediation backlog with effort, impact, and sequence
  • Twelve-month security roadmap with quarterly milestones
  • Executive readout and a board-ready summary
  • Tabletop findings and an updated incident runbook

Standards we work against

  • NIST CSF 2.0
  • ISO/IEC 27001 and 27002
  • CIS Controls v8
  • OWASP ASVS and SAMM
  • SOC 2 Trust Services Criteria

What we do not do

  • We do not run unauthorised testing, ever, on any system.
  • We do not resell tooling for commission.
  • We do not issue certifications. We prepare you for the auditor who does.

Engagement shapes

Three sizes, not one package

Durations are indicative and depend on estate size. Scope and price are fixed in writing before the engagement starts.

ShapeDurationWhat you get
Focused review2 weeksOne domain assessed in depth
Full programme assessment4 to 8 weeksScorecard, risk register, backlog, roadmap, and board summary
Certification readiness6 to 10 weeksGap analysis, control evidence plan, and an audit-ready sequence
Advisory retainerMonthlyStanding security counsel and roadmap stewardship

Related insights

Our thinking on this

Next step

Start with a briefing, not a proposal.

Thirty minutes on cyber security assessment. We will tell you whether we are the right firm for the problem, and who to talk to if we are not.