Cybersecurity · Assessment

Security Assessments

An assessment answers a question most organizations cannot answer confidently: where are we actually exposed, and what should we fix first? It is a measurement exercise, not a sales exercise, and it should produce a plan you could hand to any competent provider.

We review the environment as it is configured today — identity, devices, email, network, data, backup and the written governance around them — and report findings in business language with an order of work attached.

Why organizations ask

The three usual triggers

The first is an insurance renewal. The application form asks specific questions about multi-factor authentication, endpoint detection, backup immutability and patch cadence, and somebody has to be able to answer them accurately rather than optimistically.

The second is a client or contract requirement. Legal, accounting, healthcare and manufacturing organizations increasingly have to describe their controls to a larger counterparty before work proceeds.

The third is a change of confidence: a new leader arrives, a near-miss occurs, an internal IT person leaves, or a long-standing provider relationship is being reconsidered. In each case the need is the same — an independent, documented picture.

What we do

How the assessment runs

  1. 01

    Scope and inventory

    We establish what exists: users, devices, servers, network equipment, cloud tenants, line-of-business applications, remote access paths and where regulated or sensitive data lives.

  2. 02

    Configuration review, not guesswork

    We read the actual settings — Conditional Access policies, mail flow and anti-phishing rules, endpoint policy state, firewall rules and firmware levels, backup jobs and retention — rather than relying on a questionnaire.

  3. 03

    Evidence for the claims

    Where a control is said to exist, we look for proof: the last successful restore, the MFA coverage report, the patch compliance figure, the log retention period.

  4. 04

    Findings ranked by real risk

    Each finding records what could happen, how likely it is in this environment, and the effort to resolve. Quick wins are separated from projects requiring budget.

  5. 05

    A roadmap leadership can approve

    Immediate actions, a 90-day plan and longer-term items with costs and dependencies, written so a non-technical board can follow the reasoning.

  6. 06

    Insurance and client answers

    A mapping of findings to the questions insurers and counterparties actually ask, so the next form takes an hour rather than a fortnight.

Our position

The report belongs to you

An assessment is only useful if it is honest, so we write it to be actionable regardless of who implements it. Findings include what is already done well, because knowing which controls to keep is part of the value.

If we go on to deliver the remediation, the roadmap becomes the project plan. If you keep your existing arrangements, the report still stands on its own.

  • Written findings and evidence
  • Executive summary
  • Prioritised action plan
  • Estimated effort and cost
  • Insurance answer mapping
  • Review session with leadership

Where this fits

Assurance work like this sits alongside the day-to-day controls described on our St. Catharines cybersecurity page.

Questions

Frequently asked questions

How long does an assessment take?
For most organizations of 15 to 150 staff, one to three weeks from access being granted to the review session, depending on how many systems and sites are in scope.
Do you need administrative access?
Read-level access to the Microsoft 365 tenant, the endpoint management platform, the firewall configuration and the backup console is usually enough. We can work from exported configuration where policy requires it.
Will this disrupt anything?
No. An assessment is a review activity — we read configuration and reporting rather than changing settings. Anything we recommend is implemented separately, with your approval and a change window.

Next step

Talk to Griffin IT Group about your St. Catharines IT environment

Tell us how your technology is set up today and what is getting in the way. We will walk through your environment, outline the gaps we see and recommend a practical path forward.