The three types of research may touch the same subjects, but differ in purpose, depth and evidence. An organisation that seeks priorities for the coming year needs a different approach than a board that wants certainty about the functioning of measures or a customer demand that requires independent support.

Baseline assessment: a broad and reliable starting point

A baseline assessment shows the current situation wide and relatively compact. Interviews, documents and global basic technical tests provide insight into strengths, risks and key priorities for improvement. The outcome is a management summary and a workable improvement agenda.

This form fits when a broad overview is needed, the organisation has several questions at once or a multi-annual agenda is being built up. The Quickscan precedes this as a self-direction.

  • goal: broad starting image and priorities
  • scope: organizational broad on main lines
  • depth: compact study with selected evidence
  • output: Management summary and improvement agenda
  • appropriate moment: when starting or re-calibrateing an improvement programme
Check the cybersecurity baseline assessment
Baseline assessment means wide start, assessment focused deepening and audit independent testing with traceable evidence and an audit conclusion.

Assessment: targeted deepening for a decision

An assessment examines and assesses a defined theme or risk area with more depth. Think of Microsoft 365, infrastructure, suppliers, incident clearance, management processes or a combination of technical and board-level measures.

Depending on the question, we look at documents, configurations and technical data and carry out targeted checks. If the question is mainly technical, the Cybersecurity Assessment will be given the input of an IT Security Assessment.

  • purpose: support a specific decision or investment
  • scope: clearly defined technical, organisational or combined issue
  • depth: targeted examination with appropriate controls
  • output: findings, in-depth analysis and improvement options
  • appropriate moment: when a theme requires targeted flooring
Check out the Cybersecurity Assessment

Audit: independent review and audit conclusion

A Cyber Security Audit uses pre-defined criteria and traceable evidence to assess whether measures are demonstrably present, satisfying or functioning. Scope, samples, limitations and findings are explicitly defined and the research results in an audit conclusion.

An audit is appropriate when independence and traceability weigh heavily, for example after an improvement programme, in repeated incidents, for suppliers assurance or when management wants to know whether reported control actually works.

  • purpose: independent checking whether something is detectable is satisfactory or working
  • Scope: pre-defined criteria and components
  • depth: systematic, with verification, sampling and traceable findings
  • output: audit report with conclusion, limitations and priorities
  • appropriate moment: after implementation, in assurance or an board-level accountability question
Check out the Cyber Security Audit

Which form of research suits your question?

Pre-formulate which decision supports the outcome. A baseline assessment fits a wide starting image, a targeted deepening assessment and an independent verification audit against pre-defined criteria.

  • broad overview and roadmap needed: baseline assessment
  • depth specific theme or scenario: Assessment
  • operation, compliance or evidence independent testing: audit
  • first indication without formal examination: Quickscan
  • Test according to ISO 27001 or NIS2: Targeted GAP analysis
View all research services

Sources and deepening

Based on official frameworks and practical implementation

The source pages provide the formal background. Kynexis Information Security translates this information into an executable approach for your organisation, sector and risk profile.

View NCSC - Start cybersecurityView ISO - ISO 19011 auditing guidance