
Targeted research with depth
Cybersecurity Assessment
A Cybersecurity Assessment is a targeted study into a specific question about cybersecurity or IT security. First, we'll discuss what you want to know and what decision the investigation should support. Then we investigate the relevant technology, processes, suppliers and responsibilities. Depending on the question, we look at documents, configurations and technical data and check how security is set up in practice. If it is mainly infrastructure, cloud, vulnerabilities or technical management, we carry out the research as an IT Security Assessment. You get a clear picture of the risks, concrete findings and a practical order for improvements.
- A baseline assessment or earlier study has made a specific focus visible.
- You want to support an investment or improvement program in substance.
- A technical or organisational security theme requires more depth and targeted control.
- A supplier, cloud environment or management facility requires an independent assessment.
What are the risks? A broad-based demand quickly yields a lot of loose information. A sharp scope makes causes, impact, dependencies and improvement options visible at the level at which IT and management can decide.
Our promise of service
Research with the depth your question needs
The Cybersecurity Assessment will present the relevant facts, causes, dependencies and risks. The scope may be technical, organisational or combined.
- Clear research question
- Targeted roadworthiness tests
- Improvements in a logical order
Cybersecurity Assessment
What is a Cybersecurity Assessment?
A Cybersecurity Assessment investigates a clearly defined question about cybersecurity or IT security. The research may be technical, organisational or a combination of them.
Supplier risk
Independent assessment of a critical IT supplier
A Cybersecurity Assessment can be fully delineated around a critical supplier, cloud environment or outsourced IT service. We will then examine access rights, continuity, incident arrangements, assurance and certifications, relevant technical establishment, contractual arrangements, open risks and the possibilities for exit and transfer. This way you assess the security maturity of the supplier on facts and the consequences for your own organisation.
Read how to assess a critical IT provider →When does this service fit?
When do you choose a Cybersecurity Assessment?
Choose an assessment when a specific technical or organisational issue needs to be addressed. This fits, for example, after a baseline assessment, before an investment, with questions about an IT provider or cloud environment and when management and IT want to capture causes, impact and improvement options together.
Research area
What are we investigating?
The research question determines what we're looking at. We combine the subjects needed to understand the issue and provide the desired decision-making information.
Identity and Access Management
Accounts, roles, multifactor authentication, management rights and periodic access control.
Cloud, network and infrastructure
Microsoft 365, cloud configurations, architecture, segmentation, external access and network components.
Endpoints, servers and vulnerabilities
Protection, hardening, patching, configurations and vulnerability management.
Logging, recovery and incident response
Monitoring, monitoring, backup, repairability, escalation and technical tests.
Suppliers and Chain
Technical dependencies, agreements, access, control of the service and practical direction.
Processes and governance
Property, responsibilities, reporting, decision-making and connection to business risks.
Technical details
IT Security Assessment: technical floor
If the research question is mainly technical, we carry out the Cybersecurity Assessment as an IT Security Assessment. We are looking at technology, configurations, vulnerabilities and technical management.
Access and management rights
Accounts, roles, strong authentication, management accounts and periodic checks.
Microsoft 365 and cloud
configurations within the Tenant, Data Protection, Management and Shared responsibilities.
Network, endpoints and servers
Architecture, segmentation, external access, secure settings and system protection.
Patching and vulnerability management
How vulnerabilities are found, assessed, ordered and resolved in time.
Logging and monitoring
Log details, warnings, follow-up and retention periods available.
Backup and Recovery
Backup security, recovery targets, technical dependencies and periodic recovery tests.
Your result
What do you get after the assessment?
You get a clear picture of the risks within the agreed investigation. The report contains the findings, their causes and coherence and the improvements that call for attention. This allows you to support an investment, address a supplier or create an improvement agenda.
- Clear risk picture for the agreed study
- Concrete findings with a clear explanation
- Understanding causes and interdependencies
- Risk-based and business impact-based order
- Practical improvements and, where necessary, a roadmap
- Discussion with IT, management and relevant suppliers
How we work
This is how we perform the Cybersecurity Assessment
- 01
Research and scope
Focus on decision-making needs, themes, systems, suppliers and desired depth.
- 02
Collecting Information
Collecting relevant documents, configurations, registrations and technical information.
- 03
Investigation and control
Talk to stakeholders, assess documents and configurations and carry out the agreed technical checks.
- 04
Review findings
To look at risks, causes, dependencies and corporate impact in a coherent way.
- 05
Ordering improvements
Determine which improvements require first attention and which can follow later.
- 06
Discussion
Discuss results with IT, management, suppliers and other relevant decision makers.
Choose based on your question
Which form of research suits your decision-making needs?
The routes differ in purpose, depth and the type of support you need.
Quickscan
Gives an initial indication on its own and at a low threshold and helps to determine whether further research is useful.
View Quickscan →Information security baseline assessment
Presents the current situation, main risks and first priorities for improvement broadly and relatively compactly.
View Information security baseline assessment →Cybersecurity Assessment
Researches and assesses a defined technical, organisational or combined demand more extensively.
Fits this decision questionCyber Security Audit
Systematically keys to predefined criteria and formulates an audit conclusion based on traceable evidence.
View Cyber Security Audit →Make the research question, desired depth and intended decisions concrete. Together we decide whether the scope is technically, organizationally or combined.
Schedule an intake call →Frequently Asked Questions
Practical answers on Cybersecurity Assessment
What is a Cybersecurity Assessment?
A Cybersecurity Assessment is a targeted investigation with extra depth to a clearly defined security question. The research may be technical, organisational or a combination of them.
What is the difference between a baseline assessment and an assessment?
A baseline assessment gives a broad insight into main lines. An assessment looks at one or more selected issues more comprehensively and highlights causes, impact and possible improvements.
What is the difference between an assessment and an audit?
An assessment examines and assesses a defined demand focused and deepening. A Cyber Security Audit systematically reviews the criteria set out in advance, uses traceable evidence and formulates an audit conclusion on the scope under consideration.
Is an IT Security Assessment a separate service?
An IT Security Assessment is the technical implementation of the Cybersecurity Assessment within Kynexis. We are looking at technology, configurations, vulnerabilities and technical management.
Which technical components can be examined?
Think of identity and access management, Microsoft 365 and cloud, network and infrastructure, endpoints, servers, hardening, patching, vulnerabilities, logging, monitoring, backup and recovery.
Can an assessment also take our IT supplier?
Yes. We can assess technical access, management arrangements, responsibilities, reporting, monitoring and dependencies of the IT supplier within the agreed scope.

A clear research question gives room for technical depth and makes it clear what business risk lies behind a finding.