Overview/Products/Strategic Security Assessment

Service, project-based

Strategic Security
Assessment.

A structured maturity assessment of your cybersecurity posture. Two workshops, review of documentation and asset inventory, and a report giving leadership a prioritized roadmap instead of a vulnerability list.

Mapped against NIST CSF 2.0, ISO 27001:2022, the NIS2 Directive, the CRA (Cyber Resilience Act) and, where OT exposure exists, IEC 62443. Delivered as a 4 to 6 week project.

The deliverable
30-40 page report in Swedish or English
Executive summary, 1 to 2 pages
Prioritized roadmap: short term, long term, continuous
Gap analysis against chosen compliance frameworks
Workshop notes and whiteboard photos
Verbal briefing with leadership and security team
60-day follow-up included
From 10,000 EUR·4 to 6 weeks

What we review

Six areas, one picture.

The areas below come from frameworks like NIST CSF, ISO 27001 and NIS2. Scope is tuned to your industry and exposure, but we give a read on each where it is relevant.

01

Asset and data management

What systems, services and information assets exist today, who owns them, where they live, what their classification is. This is the foundation, because nothing that follows can be done in a way that holds over time if this is fuzzy.

02

Identity, access and authentication

IAM maturity, MFA coverage, SSO strategy, segregation of duties, least privilege. How identities are handled for both staff and external systems, and what happens when someone leaves.

03

Vulnerability and patch management

Scan cadence (quarterly, on release), patch cycles, exception process, vendor security patching. How risk is kept down between recurring external pentests.

04

Network segmentation and detection

Segmentation between zones, VLAN strategy, firewall rules, SOC/MDR status, SIEM coverage, EDR on endpoints. If an attacker breaks in, how quickly it is detected and how far they can move.

05

Incident response and business continuity

IR plan, BCP/DR documentation, RTO/RPO for critical systems, exercises and scenarios, contact chains, reporting requirements (NIS2 has short deadlines). Roles and responsibilities, not tools.

06

Compliance, vendors and governance

Gap analysis against NIS2, CRA readiness, ISO 27001 status, GDPR Art. 28 compliance in the supplier chain, security annex in procurement, CISO role and GRC function.

How it works

Four steps, usually 4 to 6 weeks.

01

Kickoff

We walk through scope, your priorities, which frameworks are mandatory for you, and who from your side will join the workshop.

02

On-site workshops

Two full days with key people. Assets, risks, dependencies, documentation, threat modelling. Whiteboard, not powerpoint.

03

Analysis and draft

We analyse network diagrams, policies, asset list and workshop output against frameworks. Draft the report, map gaps, prioritise.

04

Delivery and briefing

Written final delivery plus a verbal briefing with leadership. Within 60 days we follow up to see what has moved.

When it fits.

You are preparing for NIS2 or CRA and need to know the gap before the auditor asks.
The business has grown and IT complexity has outrun the documentation.
You have had an incident and want to know what else lies below the surface.
A new CISO or IT lead wants a structured starting point for their first 90-day plan.
The board asks "where do we actually stand" and you need an honest answer with a plan.
A major customer or investor demands an independent security assessment.

Where it fits in

Strategic, not tactical.

This service does not answer the question "what vulnerabilities do I have today". That is what our continuous platform does, every day.

It answers the question "where should we invest, and in what order". Both are needed. Customers typically pair a Strategic Security Assessment every 18 to 24 months with ongoing continuous monitoring in between.

Read more about the continuous side: Verification Engine and MCP for AI agents.

Book a kickoff call, 30 minutes, free.

We talk through whether a Strategic Security Assessment fits you right now, or whether something else is a better fit. We will tell you if we think you do not need it.