You want to assess your organisation’s security but are unsure where to begin. We agree the audit scope and assess it against the available material.
One assessment with modules selected for your question and operating context. It can cover one process or several connected areas. Scope, criteria and exclusions are agreed before work starts.
An initial discussion and entry questions establish the purpose, processes, contacts, authorisation and boundaries.
02
Review
We examine agreed documents, sources and examples, interview responsible people and record unavailable material.
03
Assess
We compare findings against agreed criteria, discuss discrepancies with the organisation and explain uncertainty.
04
Plan and reassess
We provide priorities and an improvement plan. Action owners and a date for reassessing selected findings can be agreed.
03 / Assessment
A descriptive readiness profile
For each assessed area, we describe its state and supporting material. We do not calculate an aggregate organisational security score.
Not established
Material demonstrates that the required practice or responsibility is absent.
Defined
Rules and responsibilities are documented, but application has not yet been demonstrated.
Applied
The agreed sample demonstrates that the practice operates and has an accountable owner.
Reviewed
The organisation periodically reviews the practice and documents resulting improvements.
Insufficient material is recorded as ‘not assessed’; an area outside scope is ‘not applicable’. Neither is the lowest rating. The profile refers to the agreed sample and the assessment period.
Finding priority is separate from readiness: urgent decision, planned improvement or observation. The rationale considers potential impact, exposure, reliability of material and response time.
04 / Deliverable
What you receive
An executive summary and scope statement.
Findings with their basis, limitations and risk areas.
Priorities and recommendations to support decisions.
An improvement roadmap with dependencies and a reassessment proposal.
A competency gap map where supported by the findings.
The report can be used independently, by your own team or by a provider you choose. The audit does not require a follow-on service or training purchase. Assessing an organisation does not certify its employees.
Audit boundaries
The audit does not include a full penetration test, exploit development, a red-team operation or an offensive campaign. This product does not attempt to bypass security controls. Findings may indicate a need for a separate examination by an appropriate provider.
This is an assessment within the agreed scope of ProSentinel’s competencies. It does not certify the organisation or confirm compliance with ISO, NIS2 or other regulations. It does not replace a legal or financial audit or a full IT infrastructure examination.
Acting on findings
Depending on the outcome, you may investigate an event, reduce exposure, plan team development or repeat a selected part of the assessment.