Cybersecurity

Security assessments and risk reviews

You cannot fix everything at once, and you should not have to guess what matters most. A Promatics security assessment reviews how your organization is actually set up, ranks the risks by likelihood and impact, and gives you a remediation plan you can act on.

Who this service is for

A good fit if

  • You have never had a security review, or the last one is out of date.
  • An insurer, client or board has asked how you protect data, and you need evidence.
  • You have grown, merged or moved to the cloud, and you are not sure what changed.
  • You want a baseline before signing up for managed security.
  • You are preparing for expectations such as the FTC Safeguards Rule, a HIPAA Security Rule risk analysis, CMMC 2.0 or NYDFS Part 500.

Another approach may suit you better if

  • You need a formal audit opinion or certification. That must come from an independent, accredited assessor; our assessment helps you prepare for it.
  • You only need a one-off vulnerability scan with no interpretation. A scanning tool may be enough.
  • You need an in-depth penetration test of a complex custom application. We can scope it and coordinate a specialist tester.

What this service is

A security assessment is a structured review of how well your organization is protected against the attacks that most often cause harm: stolen passwords, phishing, ransomware, unpatched systems and misconfigured cloud services. It ends with a ranked list of risks and a practical plan, not a pile of scanner output.

We measure what we find against recognized baselines, such as CISA's Cross-Sector Cybersecurity Performance Goals, the CIS Critical Security Controls and the NIST Cybersecurity Framework 2.0. Where you have a specific requirement, such as the FFIEC IT Examination Handbook for a bank or credit union, NYDFS Part 500 for a New York-regulated financial company, CMMC 2.0 for a defense contractor, or a client's security questionnaire, we map the findings to it.

What we look at

  • Identities and access: who has accounts, who has administrator rights, where MFA is missing, and what happens when someone leaves.
  • Devices: patch levels, encryption, endpoint protection and whether users can install software.
  • Email and collaboration: filtering, domain authentication, external sharing and mailbox rules that attackers like to abuse.
  • Network and remote access: firewall rules, VPN, Wi-Fi and anything exposed to the internet.
  • Backups and recovery: what is backed up, whether an attacker could reach the backups, and when a restore was last tested.
  • Cloud services and vendors: configuration of key platforms and how third parties access your systems.
  • People and process: training, incident response, and how payment or banking changes are verified.

What the findings look like

Demonstration, not a client project

Three rows from an invented risk register, showing the format we use:

FindingLikelihoodImpactRecommended fixEffort
Two administrator accounts have no MFAHighHighEnforce MFA and move admins to separate accountsLow
Backups stored on a share reachable by all staffMediumHighIsolate backups and test a restoreMedium
No DMARC record on the main email domainHighMediumPublish DMARC in monitoring mode, then enforceLow

Why organizations ask for an assessment

  • To protect the business and its data from unexpected problems and unwanted intruders, starting with the risks that matter most.
  • To keep leadership focused on the core business, with a clear roadmap instead of recurring security fire drills.
  • To budget with fewer surprises, because the roadmap shows the order and the estimated effort of the work ahead.
  • To answer insurers, clients and boards with evidence rather than assurances.

How we keep the assessment safe

Reviewing security means handling sensitive information. We use read-only access wherever possible, through named accounts that are removed at the end. Scans run only within written authorization and agreed time windows. Findings are shared only with the people you name, and assessment data is deleted at the end of the engagement as agreed.

After the assessment

You can fix the findings with your own team, with another provider, or with us. Promatics can deliver the remediation as a project, or fold it into managed IT services with ongoing security. Common next steps include EDR deployment, email security and awareness training.

What is included

The exact list is agreed in writing for each project. These are the usual deliverables and the usual boundaries.

Typical deliverables

  • A scoping document listing the systems, locations and questions in scope.
  • Identity and access review: MFA coverage, administrator accounts, password policies, and how joiners and leavers are handled.
  • Device review: patching, disk encryption, endpoint protection and local administrator rights.
  • Email and collaboration review: filtering, SPF, DKIM and DMARC, sharing settings, and Microsoft 365 or Google Workspace security configuration.
  • Network and remote access review: firewall rules, VPN, Wi-Fi and services exposed to the internet.
  • Backup and recovery review: coverage, isolation from attackers, and restore testing.
  • An external vulnerability scan of internet-facing systems, with findings explained.
  • A risk register ranking every finding by likelihood and impact.
  • A remediation roadmap with quick wins, owners and effort estimates.
  • An executive summary suitable for leadership, a board or an insurer.

Not included unless agreed separately

  • Fixing the findings, which is quoted separately or delivered under a managed security agreement.
  • Certification, audit opinions or legal conclusions about compliance.
  • Physical security testing and in-person social engineering.
  • Systems not listed in the agreed scope.

What we will need from you

Most delays in this kind of work come from access and decisions, not from the technical build. Knowing these early keeps the project predictable.

  • Read-only administrator access to the systems in scope.
  • An inventory of users, devices and key applications, if one exists.
  • Time with the people who run IT, finance and operations.
  • Copies of relevant policies, insurer questionnaires and contracts with security clauses.
  • Written authorization before any scanning of your systems.
Delivery

How the work is delivered

Each stage ends with something you can review before the next one starts.

  1. Scope

    Agree the systems, sites and questions in scope, and the rules and time windows for any scanning.

    Output: Signed scope and scanning authorization.

  2. Collect

    Review configurations, run approved scans, and hold short interviews with the people who run your systems.

    Output: Evidence and raw findings.

  3. Analyze

    Compare what we found with a recognized baseline and rank each finding by likelihood and impact on your organization.

    Output: Risk register.

  4. Report

    Walk leadership and IT through the findings, the quick wins and the longer-term roadmap.

    Output: Executive summary, technical report and roadmap.

  5. Follow up

    After an agreed period, check the fixes that were made and update the register.

    Output: Retest note and updated risk register.

Testing and handover

  • Every finding has evidence, a plain description of the risk and a recommended fix.
  • Findings are ranked, so you know what to do first, not just how many issues exist.
  • Scans run only within the written authorization and the agreed time windows.
  • Assessment data, such as configurations and scan results, is stored securely and deleted at the end as agreed.
  • Leadership receives a walkthrough, not just a document.

What affects the cost

We do not publish package prices. Each estimate is based on an agreed scope, in US dollars, with taxes shown separately. These are the things that move the number most:

  • The number of users, devices, servers and sites.
  • The number of cloud services and business applications in scope.
  • Whether external and internal vulnerability scanning are included.
  • Mapping to a specific framework, such as the NIST Cybersecurity Framework 2.0, the HIPAA Security Rule or CMMC 2.0.
  • Retesting after remediation.

Questions buyers usually ask

How is this different from a vulnerability scan?

A scan finds known technical weaknesses on the systems it can reach. An assessment also looks at how accounts, email, backups and processes are set up, and explains which risks matter for your organization. Scanning is one input, not the whole picture.

Will the assessment disrupt our staff?

Very little. Most of the work is configuration review and short interviews. Any scanning is authorized in writing and scheduled in agreed windows.

Can we share the report with our insurer or clients?

Yes. You receive an executive summary suitable for sharing and a detailed technical report for your IT team. You decide who sees what.

Does a good result mean we are compliant?

No. The assessment shows how well your controls reduce risk and where the gaps are. Whether you comply with state privacy laws, HIPAA, the GLBA Safeguards Rule or other sector rules is a legal question for your counsel, and certification comes from an independent body. See privacy and compliance readiness.

How often should we repeat it?

Typically once a year, and after major changes such as a merger, a move to the cloud or a significant incident. Managed-service clients receive ongoing reviews under their agreement.

Want to know where you stand?

Tell us about your organization and what prompted the question. We will reply to arrange a scoping conversation.