ProSentinel Integrated Security Assessment

Start by understanding the situation.

You want to assess your organisation’s security but are unsure where to begin. We agree the audit scope and assess it against the available material.

One assessment with modules selected for your question and operating context. It can cover one process or several connected areas. Scope, criteria and exclusions are agreed before work starts.

01 / Choose the relevant scope

Choose the relevant scope

Modules are selected for the organisation’s needs, available material and our competencies. You do not need to commission every area.

Information exposure

What open sources reveal about the company, people and relationships relevant to its operations.

Basis of assessment

Agreed identifiers, open sources and organisational context.

Possible outcome

An assessment of disclosures, their significance and information requiring verification.

Related service competencies

Digital exposure

Which signals about accounts, data and the organisation’s presence are visible externally.

Basis of assessment

Lawfully accessible external sources and client material, within agreed boundaries.

Possible outcome

An exposure map, an assessment of signal reliability and disclosure-reduction priorities.

Related service competencies

Human factors

How the organisation verifies contacts, information requests and situations exposed to manipulation.

Basis of assessment

Interviews with agreed participants and review of information-handling rules and examples. No unagreed testing of staff.

Possible outcome

An assessment of process resilience to social engineering and relevant team development needs.

Related service competencies

Operational security

How critical information and activities are protected, and where exploitable exposure may arise.

Basis of assessment

An agreed process, threat context, documents and interviews with responsible people.

Possible outcome

An operational risk assessment and options to reduce exposure and dependencies.

Related service competencies

Incident investigation readiness

Whether the organisation can reconstruct an event, preserve relevant material and initiate an appropriate response.

Basis of assessment

Review of responsibilities, availability and retention of digital material, and preservation arrangements.

Possible outcome

A DFIR readiness assessment, material gaps and recommendations for investigation preparation.

Related service competencies

Information assessment and team readiness

How decisions are supported, information is verified and the team recognises its competency limits.

Basis of assessment

Agreed examples of assessments and decisions, role allocation and team interviews.

Possible outcome

An assessment of information and competency gaps, with further action recommended where needed.

Related service competencies

02 / Process

From scope to priorities

  1. Agree

    An initial discussion and entry questions establish the purpose, processes, contacts, authorisation and boundaries.

  2. Review

    We examine agreed documents, sources and examples, interview responsible people and record unavailable material.

  3. Assess

    We compare findings against agreed criteria, discuss discrepancies with the organisation and explain uncertainty.

  4. Plan and reassess

    We provide priorities and an improvement plan. Action owners and a date for reassessing selected findings can be agreed.

03 / Assessment

A descriptive readiness profile

For each assessed area, we describe its state and supporting material. We do not calculate an aggregate organisational security score.

Not established
Material demonstrates that the required practice or responsibility is absent.
Defined
Rules and responsibilities are documented, but application has not yet been demonstrated.
Applied
The agreed sample demonstrates that the practice operates and has an accountable owner.
Reviewed
The organisation periodically reviews the practice and documents resulting improvements.

Insufficient material is recorded as ‘not assessed’; an area outside scope is ‘not applicable’. Neither is the lowest rating. The profile refers to the agreed sample and the assessment period.

Finding priority is separate from readiness: urgent decision, planned improvement or observation. The rationale considers potential impact, exposure, reliability of material and response time.

04 / Deliverable

What you receive

  • An executive summary and scope statement.
  • Findings with their basis, limitations and risk areas.
  • Priorities and recommendations to support decisions.
  • An improvement roadmap with dependencies and a reassessment proposal.
  • A competency gap map where supported by the findings.

The report can be used independently, by your own team or by a provider you choose. The audit does not require a follow-on service or training purchase. Assessing an organisation does not certify its employees.

Audit boundaries

The audit does not include a full penetration test, exploit development, a red-team operation or an offensive campaign. This product does not attempt to bypass security controls. Findings may indicate a need for a separate examination by an appropriate provider.

This is an assessment within the agreed scope of ProSentinel’s competencies. It does not certify the organisation or confirm compliance with ISO, NIS2 or other regulations. It does not replace a legal or financial audit or a full IT infrastructure examination.

Acting on findings

Depending on the outcome, you may investigate an event, reduce exposure, plan team development or repeat a selected part of the assessment.

Discuss the audit scope