Targeted research with depth

Cybersecurity Assessment

A Cybersecurity Assessment is a targeted study into a specific question about cybersecurity or IT security. First, we'll discuss what you want to know and what decision the investigation should support. Then we investigate the relevant technology, processes, suppliers and responsibilities. Depending on the question, we look at documents, configurations and technical data and check how security is set up in practice. If it is mainly infrastructure, cloud, vulnerabilities or technical management, we carry out the research as an IT Security Assessment. You get a clear picture of the risks, concrete findings and a practical order for improvements.

Do you recognize this?
  • A baseline assessment or earlier study has made a specific focus visible.
  • You want to support an investment or improvement program in substance.
  • A technical or organisational security theme requires more depth and targeted control.
  • A supplier, cloud environment or management facility requires an independent assessment.

What are the risks? A broad-based demand quickly yields a lot of loose information. A sharp scope makes causes, impact, dependencies and improvement options visible at the level at which IT and management can decide.

Our promise of service

Research with the depth your question needs

The Cybersecurity Assessment will present the relevant facts, causes, dependencies and risks. The scope may be technical, organisational or combined.

  • Clear research question
  • Targeted roadworthiness tests
  • Improvements in a logical order

Cybersecurity Assessment

What is a Cybersecurity Assessment?

A Cybersecurity Assessment investigates a clearly defined question about cybersecurity or IT security. The research may be technical, organisational or a combination of them.

FOR WHOMFor the board and management
WHENWhen do you choose a Cybersecurity Assessment?
RESULTWhat do you get after the assessment?

Supplier risk

Independent assessment of a critical IT supplier

A Cybersecurity Assessment can be fully delineated around a critical supplier, cloud environment or outsourced IT service. We will then examine access rights, continuity, incident arrangements, assurance and certifications, relevant technical establishment, contractual arrangements, open risks and the possibilities for exit and transfer. This way you assess the security maturity of the supplier on facts and the consequences for your own organisation.

Read how to assess a critical IT provider

When does this service fit?

When do you choose a Cybersecurity Assessment?

Choose an assessment when a specific technical or organisational issue needs to be addressed. This fits, for example, after a baseline assessment, before an investment, with questions about an IT provider or cloud environment and when management and IT want to capture causes, impact and improvement options together.

For the board and managementFor CISO and IT managerFor supplier and investment decisions

Research area

What are we investigating?

The research question determines what we're looking at. We combine the subjects needed to understand the issue and provide the desired decision-making information.

Identity and Access Management

Accounts, roles, multifactor authentication, management rights and periodic access control.

Cloud, network and infrastructure

Microsoft 365, cloud configurations, architecture, segmentation, external access and network components.

Endpoints, servers and vulnerabilities

Protection, hardening, patching, configurations and vulnerability management.

Logging, recovery and incident response

Monitoring, monitoring, backup, repairability, escalation and technical tests.

Suppliers and Chain

Technical dependencies, agreements, access, control of the service and practical direction.

Processes and governance

Property, responsibilities, reporting, decision-making and connection to business risks.

Technical details

IT Security Assessment: technical floor

If the research question is mainly technical, we carry out the Cybersecurity Assessment as an IT Security Assessment. We are looking at technology, configurations, vulnerabilities and technical management.

IDENTITY

Access and management rights

Accounts, roles, strong authentication, management accounts and periodic checks.

CLOUD

Microsoft 365 and cloud

configurations within the Tenant, Data Protection, Management and Shared responsibilities.

INFRASTRUCTUUR

Network, endpoints and servers

Architecture, segmentation, external access, secure settings and system protection.

KWETSBAARHEDEN

Patching and vulnerability management

How vulnerabilities are found, assessed, ordered and resolved in time.

DETECTION

Logging and monitoring

Log details, warnings, follow-up and retention periods available.

RECOVERY

Backup and Recovery

Backup security, recovery targets, technical dependencies and periodic recovery tests.

Your result

What do you get after the assessment?

You get a clear picture of the risks within the agreed investigation. The report contains the findings, their causes and coherence and the improvements that call for attention. This allows you to support an investment, address a supplier or create an improvement agenda.

  • Clear risk picture for the agreed study
  • Concrete findings with a clear explanation
  • Understanding causes and interdependencies
  • Risk-based and business impact-based order
  • Practical improvements and, where necessary, a roadmap
  • Discussion with IT, management and relevant suppliers
KYNEXISCybersecurity Assessment
4Core risks3Choices required2Phases
FocusRisks, causes and order of actionRisk-driven and enforceable

How we work

This is how we perform the Cybersecurity Assessment

  1. 01

    Research and scope

    Focus on decision-making needs, themes, systems, suppliers and desired depth.

  2. 02

    Collecting Information

    Collecting relevant documents, configurations, registrations and technical information.

  3. 03

    Investigation and control

    Talk to stakeholders, assess documents and configurations and carry out the agreed technical checks.

  4. 04

    Review findings

    To look at risks, causes, dependencies and corporate impact in a coherent way.

  5. 05

    Ordering improvements

    Determine which improvements require first attention and which can follow later.

  6. 06

    Discussion

    Discuss results with IT, management, suppliers and other relevant decision makers.

Choose based on your question

Which form of research suits your decision-making needs?

The routes differ in purpose, depth and the type of support you need.

ORIENTATION

Quickscan

Gives an initial indication on its own and at a low threshold and helps to determine whether further research is useful.

View Quickscan
ONAFHANKELIJK ASSESS

Cyber Security Audit

Systematically keys to predefined criteria and formulates an audit conclusion based on traceable evidence.

View Cyber Security Audit
Make your next step concreteHave Cybersecurity Assessment performed?

Make the research question, desired depth and intended decisions concrete. Together we decide whether the scope is technically, organizationally or combined.

Schedule an intake call

Frequently Asked Questions

Practical answers on Cybersecurity Assessment

What is a Cybersecurity Assessment?

A Cybersecurity Assessment is a targeted investigation with extra depth to a clearly defined security question. The research may be technical, organisational or a combination of them.

What is the difference between a baseline assessment and an assessment?

A baseline assessment gives a broad insight into main lines. An assessment looks at one or more selected issues more comprehensively and highlights causes, impact and possible improvements.

What is the difference between an assessment and an audit?

An assessment examines and assesses a defined demand focused and deepening. A Cyber Security Audit systematically reviews the criteria set out in advance, uses traceable evidence and formulates an audit conclusion on the scope under consideration.

Is an IT Security Assessment a separate service?

An IT Security Assessment is the technical implementation of the Cybersecurity Assessment within Kynexis. We are looking at technology, configurations, vulnerabilities and technical management.

Which technical components can be examined?

Think of identity and access management, Microsoft 365 and cloud, network and infrastructure, endpoints, servers, hardening, patching, vulnerabilities, logging, monitoring, backup and recovery.

Can an assessment also take our IT supplier?

Yes. We can assess technical access, management arrangements, responsibilities, reporting, monitoring and dependencies of the IT supplier within the agreed scope.

Wouter Parent

A clear research question gives room for technical depth and makes it clear what business risk lies behind a finding.

Current
WebinarFree webinars on NIS2, cyber risk management and oversight

Choose a live session for the board, executive team, supervisory board or board of trustees and register directly.

View webinars and dates