You May Already be Required to Do This.
A Security Risk Assessment isn’t just a good idea — for many businesses it’s a documented compliance obligation. If you accept credit card payments, handle health information, carry cyber insurance, work with enterprise clients, or sit anywhere in the federal contracting supply chain, the requirement may already exist in your contracts, your policy, or your regulatory framework.
The question isn’t whether you need one. It’s whether yours has been done — and done properly.
PCI-DSS
Any business accepting credit card payments is required to conduct an annual risk assessment as part of PCI-DSS compliance. Many mid-market businesses either don’t know this requirement exists or are not fulfilling it adequately.
HIPAA
Healthcare-adjacent businesses — medical practices, dental offices, billing companies, healthcare staffing, and medical device vendors — are required to conduct a bona fide Security Risk Analysis annually under the HIPAA Security Rule. It is one of the most commonly cited violations in HHS enforcement actions.
A Note on HIPPA Audits
The first thing an HHS auditor typically requests — including in a desk audit — is six years of Security Risk Assessment documentation. When a covered entity or business associate can’t produce it, what might have been a routine audit escalates into a comprehensive investigation virtually guaranteed to uncover additional violations. The SRA isn’t just a compliance requirement. It’s your first line of defense when an auditor comes knocking — and the foundation for addressing the risks you can’t mitigate until you know they exist.
CYBER Insurance
Cyber insurance underwriters have fundamentally changed their approach. What was once a routine renewal process now involves detailed questionnaires — and they get harder every year. The reason is straightforward: you are not an insurable risk if you don’t know what your risks are. A documented annual risk assessment demonstrates that you do — and puts you in a materially stronger position at renewal.
Enterprise Contacts
Vendor security questionnaires used to be treated as a formality — a box to check on both sides of a deal. That’s changing. Enterprise clients with highly sensitive data are increasingly verifying the answers they receive, not just filing them. A vendor who can’t substantiate their responses — or worse, misrepresented their security posture — may be exposed to serious contractual and reputational liability. A documented annual risk assessment means your answers are truthful, defensible, and backed by evidence.
Major IT Changes
New infrastructure, cloud migration, acquisitions, new office locations, or significant system changes may trigger an interim assessment requirement under your compliance framework — or simply represent a new risk profile that your existing program hasn’t evaluated.
THE ASSESSMENT
A CIS Controls-Based Evaluation of Your Security Posture
Our Security Risk Assessment evaluates your environment against NIST 800-53 — a comprehensive security framework — using the CIS Controls methodology across 18 control areas that represent the most effective practices for protecting against the most common threats. The result maps directly to PCI-DSS, HIPAA, cyber insurer expectations, enterprise vendor requirements, and NIST 800-171 for businesses in the federal supply chain.
WHAT WE EVALUATE
(18 CIS Control Areas)
✔︎ Inventory and control of
enterprise assets
✔︎ Inventory and control of software assets
✔︎ Data protection practices
✔︎ Secure configuration of enterprise assets
✔︎ Account management and access controls
✔︎ Continuous vulnerability management
✔︎ Audit log management
✔︎ Email and web browser protections
✔︎ Malware defenses
✔︎ Data recovery practices
✔︎ Network infrastructure management
✔︎ Network monitoring and defense
✔︎ Security awareness and skills training
✔︎ Service provider management
✔︎ Application software security
✔︎ Incident response management
✔︎ Penetration testing practices
✔︎ Security governance program maturity
THIS IS NOT:
✖︎ A penetration test
✖︎ A vulnerability scan
✖︎ An automated tool output
✖︎ A generic checklist
Our assessment is a practitioner-led evaluation — not a software-generated report. Every finding is reviewed in the context of your specific business environment, your data, your clients, and your risk profile.
Everything You Need. Nothing You Don’t.
Program Risk Assessment Report
A formal written report covering your current state across all 18 CIS Controls, with risk ratings (Critical / High / Medium / Low) for each identified gap. Written in plain business language — suitable for board, insurer, or enterprise client review.
Prioritized Risk Register
A living document listing every identified risk, its rating, its business impact, and its recommended remediation. Organized by priority so you know exactly where to focus first.
Remediation Roadmap
A practical, sequenced plan for addressing identified gaps — mapped to your business constraints, not an idealized enterprise standard. Tells you what to do, in what order, and why.
Executive Summary
A concise summary of findings suitable for non-technical audiences — ownership, board members, insurers, and enterprise clients.
60-Minute Debrief Session
A structured review of all findings with your leadership team. We walk through the report, answer your questions, and help you understand what the findings mean for your business.
Delivered within 30 days of engagement start.
Transparent. Fixed. No Surprises.
$7,500
FLAT FEE – NO ONGOING COMMITMENT
Conversion Credit:
Clients who engage a full Cybersecurity Governance Program within 90 days of their Security Risk Assessment receive a complete waiver of their program onboarding fee — entirely, regardless of tier. The assessment isn’t a sunk cost — it’s a head start.
THE PROCESS
Simple. Structured. Delivered in 30 Days.

Engage
Sign a simple services agreement. No long-term commitment required. We schedule your kickoff call and begin gathering background information.

Assess
We conduct a thorough CIS Controls-based evaluation of your environment — your systems, your data, your people, and your processes. This typically involves 2-3 working sessions with your team over 2-3 weeks.

Report
You receive your complete deliverable package — Assessment Report, Risk Register, Remediation Roadmap — within 30 days of engagement start.

Debrief
We walk through the findings together in a structured 60-minute session. You leave knowing exactly where you stand, what your greatest risks are, and what to do about them.
The Security Risk Assessment Is the RIght Starting Point If ...
You should start here if:
✔︎ You’ve never had a bona fide security risk assessment conducted
✔︎ Your cyber insurance renewal is approaching and you expect harder questions
✔︎ A client has sent you a security questionnaire you’re not prepared to answer
✔︎ You need the SRA to help demonstrate PCI-DSS or HIPAA compliance
✔︎ Your IT environment has changed significantly — new systems, cloud migration, acquisition
✔︎ You want to understand your risk posture before committing to a full program
✔︎ A prior assessment was conducted but is more than 12 months old
You may be ready for the full program instead, if:
➤ You’ve had an assessment and know your gaps — now you need ongoing management
➤ Your stakeholder pressure is ongoing, not a one-time event
➤ You want a partner managing your security program, not just a report
➤ You’re ready to build the policy documentation your clients and insurers require
➤ You’re ready to jump in — the full program includes a risk assessment as part of the 90-day Foundation Phase, and one each year over the next three years
Not sure which is right for your situation? [Schedule a 30-minute call] and we’ll help you figure it out.
COMMON QUESTIONS
Ready to know where you stand?
Schedule a 30-minute conversation. We’ll discuss your specific situation, your compliance obligations, and whether a Security Risk Assessment is the right starting point for your business.
Looking for ongoing security program management?
The Security Risk Assessment is a natural starting point. Clients who engage our Cybersecurity Governance Program within 90 days have their program onboarding fee waived entirely — making the assessment a zero-risk first step toward a complete program.

