dsp security risk banner

Security Risk Assessment

WHY IT MATTERS

You May Already be Required to Do This.

A Security Risk Assessment isn’t just a good idea — for many businesses it’s a documented compliance obligation. If you accept credit card payments, handle health information, carry cyber insurance, work with enterprise clients, or sit anywhere in the federal contracting supply chain, the requirement may already exist in your contracts, your policy, or your regulatory framework.

The question isn’t whether you need one. It’s whether yours has been done — and done properly.

PCI-DSS

Any business accepting credit card payments is required to conduct an annual risk assessment as part of PCI-DSS compliance. Many mid-market businesses either don’t know this requirement exists or are not fulfilling it adequately.

Healthcare-adjacent businesses — medical practices, dental offices, billing companies, healthcare staffing, and medical device vendors — are required to conduct a bona fide Security Risk Analysis annually under the HIPAA Security Rule. It is one of the most commonly cited violations in HHS enforcement actions.

The first thing an HHS auditor typically requests — including in a desk audit — is six years of Security Risk Assessment documentation. When a covered entity or business associate can’t produce it, what might have been a routine audit escalates into a comprehensive investigation virtually guaranteed to uncover additional violations. The SRA isn’t just a compliance requirement. It’s your first line of defense when an auditor comes knocking — and the foundation for addressing the risks you can’t mitigate until you know they exist.

CYBER Insurance

Cyber insurance underwriters have fundamentally changed their approach. What was once a routine renewal process now involves detailed questionnaires — and they get harder every year. The reason is straightforward: you are not an insurable risk if you don’t know what your risks are. A documented annual risk assessment demonstrates that you do — and puts you in a materially stronger position at renewal.

Vendor security questionnaires used to be treated as a formality — a box to check on both sides of a deal. That’s changing. Enterprise clients with highly sensitive data are increasingly verifying the answers they receive, not just filing them. A vendor who can’t substantiate their responses — or worse, misrepresented their security posture — may be exposed to serious contractual and reputational liability. A documented annual risk assessment means your answers are truthful, defensible, and backed by evidence.

Major IT Changes

New infrastructure, cloud migration, acquisitions, new office locations, or significant system changes may trigger an interim assessment requirement under your compliance framework — or simply represent a new risk profile that your existing program hasn’t evaluated.

THE ASSESSMENT

A CIS Controls-Based Evaluation of Your Security Posture

Our Security Risk Assessment evaluates your environment against NIST 800-53 — a comprehensive security framework — using the CIS Controls methodology across 18 control areas that represent the most effective practices for protecting against the most common threats. The result maps directly to PCI-DSS, HIPAA, cyber insurer expectations, enterprise vendor requirements, and NIST 800-171 for businesses in the federal supply chain.

WHAT WE EVALUATE
(18 CIS Control Areas)

✔︎ Inventory and control of
enterprise assets
✔︎ Inventory and control of
software assets
✔︎ Data protection practices
✔︎ Secure configuration of enterprise assets
✔︎ Account management and access controls
✔︎ Continuous vulnerability management

✔︎ Audit log management
✔︎ Email and web browser protections
✔︎ Malware defenses
✔︎ Data recovery practices
✔︎ Network infrastructure management
✔︎ Network monitoring and defense

✔︎ Security awareness and skills training
✔︎ Service provider management
✔︎ Application software security
✔︎ Incident response management
✔︎ Penetration testing practices
✔︎ Security governance program maturity

THIS IS NOT:

✖︎ A penetration test
✖︎
A vulnerability scan
✖︎
An automated tool output
✖︎
A generic checklist

Our assessment is a practitioner-led evaluation — not a software-generated report. Every finding is reviewed in the context of your specific business environment, your data, your clients, and your risk profile.

DELIVERABLES

Everything You Need. Nothing You Don’t.

Program Risk Assessment Report

A formal written report covering your current state across all 18 CIS Controls, with risk ratings (Critical / High / Medium / Low) for each identified gap. Written in plain business language — suitable for board, insurer, or enterprise client review.

A living document listing every identified risk, its rating, its business impact, and its recommended remediation. Organized by priority so you know exactly where to focus first.

Remediation Roadmap

Executive Summary

A concise summary of findings suitable for non-technical audiences — ownership, board members, insurers, and enterprise clients.

60-Minute Debrief Session

A structured review of all findings with your leadership team. We walk through the report, answer your questions, and help you understand what the findings mean for your business.

Delivered within 30 days of engagement start.

PRICING

Transparent. Fixed. No Surprises.

$7,500

FLAT FEE – NO ONGOING COMMITMENT

Conversion Credit:

Clients who engage a full Cybersecurity Governance Program within 90 days of their Security Risk Assessment receive a complete waiver of their program onboarding fee — entirely, regardless of tier. The assessment isn’t a sunk cost — it’s a head start.

THE PROCESS

Simple. Structured. Delivered in 30 Days.

process 1

Engage

Sign a simple services agreement. No long-term commitment required. We schedule your kickoff call and begin gathering background information.

process 2

Assess

We conduct a thorough CIS Controls-based evaluation of your environment — your systems, your data, your people, and your processes. This typically involves 2-3 working sessions with your team over 2-3 weeks.

process 3

Report

You receive your complete deliverable package — Assessment Report, Risk Register, Remediation Roadmap — within 30 days of engagement start.

process 4

Debrief

We walk through the findings together in a structured 60-minute session. You leave knowing exactly where you stand, what your greatest risks are, and what to do about them.

IS THIS RIGHT FOR YOU?

The Security Risk Assessment Is the RIght Starting Point If ...

You should start here if:

You’ve had an assessment and know your gaps — now you need ongoing management
Your stakeholder pressure is ongoing, not a one-time event
You want a partner managing your security program, not just a report
You’re ready to build the policy documentation your clients and insurers require
You’re ready to jump in — the full program includes a risk assessment as part of the 90-day Foundation Phase, and one each year over the next three years

Not sure which is right for your situation? [Schedule a 30-minute call] and we’ll help you figure it out.

COMMON QUESTIONS

Ready to know where you stand?

Schedule a 30-minute conversation. We’ll discuss your specific situation, your compliance obligations, and whether a Security Risk Assessment is the right starting point for your business.