Sentrix

Services · Assessments

Posture assessment: know where your security stands

Interviews and technical validation mapped to ISO 27001, NIST CSF or CIS v8.1: an objective baseline and a phased roadmap before you spend on remediation.

Why start here

You can't fix what you haven't measured. Before implementing controls, buying tools or writing policies, you need an objective baseline of where you actually stand, not where you assume you stand.

Unknown exposure

You can't prioritize a risk you haven't identified, or defend a budget you can't justify.

Audits without a baseline

Walking into a certification audit blind is how timelines and budgets blow up.

Reactive spending

Buying tools before understanding your gaps means paying twice: once for the wrong tool, once for the right one.

No shared language with the board

A maturity score your leadership can track quarter over quarter beats a wall of technical findings.

What sets this apart

We test the configuration, not just the policy. Most assessments stop at "do you have an EDR? Yes or no." We go further: we technically validate how each of your security solutions is actually configured, and hand you a specific, prioritized action for every gap we find, not just a rating.

  • Identity and access: MFA enforcement, conditional access, privileged accounts.
  • Endpoint and EDR: policy coverage, tamper protection, blind spots.
  • Network and firewall: rule hygiene, segmentation, exposed services.
  • Backup and recovery: job success, restore testing, retention.

Sample validation findings

Illustrative examples of the kind of findings a technical validation surfaces; they do not describe a specific client.

  • High: an outbound firewall rule permits unrestricted RDP (3389) to the internet. Action: restrict RDP egress to the management subnet and require VPN for remote access.
  • High: MFA is not enforced on three privileged Microsoft 365 accounts. Action: apply a Conditional Access policy requiring MFA for all admin roles.
  • Medium: EDR real-time protection is disabled on a dozen endpoints. Action: re-enable it via policy and turn on tamper protection.
  • Low: backup jobs succeed but restores have never been tested. Action: schedule a periodic restore test and document the recovery time.

What you receive

A report built to be used, not filed away.

Posture Status Report

Maturity scoring by domain, with identified gaps clearly attributed to their root cause.

Risk Register

Every gap prioritized by both cyber impact and business impact, so you know what actually matters first.

Phased Roadmap

Quick wins, then foundational controls, then advanced maturity: sequenced actions, not a wall of unordered findings.

Budgetary Pricing

Cost estimates by roadmap phase, plus optional packages, so you can plan before you commit.

Choose your framework

Mapped to the standard that fits your goals. A certification path (ISO 27001), a risk-management lens (NIST CSF) or a prescriptive, controls-first approach (CIS v8.1): we help you choose during scoping.

How it works

From kickoff to leadership sign-off.

  1. Discovery and interviews. Structured interviews with your team, plus optional evidence collection: we learn how things actually work, not just how they're documented.
  2. Technical validation. We verify controls where applicable; we do not just take your word for it.
  3. Scoring and gap analysis. Every finding is weighed through a business impact lens and a cyber risk lens, then scored against your chosen framework.
  4. Roadmap and workshop. A phased roadmap with budgetary pricing, presented to your leadership team so the findings land, not just get filed away.

What comes next

The roadmap is yours. If you want help running it, each phase maps to a service: identity and access, endpoint and server protection, network security, data protection, then managed security operations to keep the controls effective. If the goal is a certification, the assessment doubles as the gap analysis for ISO 27001 certification support.

Know your real posture, before it costs you.

A structured assessment, a real roadmap and an estimate before you commit. Let's talk about what applies to you.

Contact us

Frequently asked questions

Which framework should we choose?
It depends on your industry, customer expectations and where you are headed: ISO 27001 for a certification path, NIST CSF for a risk-management lens, or CIS v8.1 for a more prescriptive, controls-first approach. We help you decide during scoping, and the report is scored against the framework you choose.
How long does an assessment take?
It depends on the size and complexity of your environment. Most assessments are scoped to a few weeks: structured interviews with your team, technical validation of the controls, scoring and gap analysis, then a workshop with your leadership. We give you a firm timeline once we understand your environment, not before.
What is in the report?
Four deliverables: a posture status report with maturity scoring by domain and every gap attributed to its root cause; a risk register prioritized by cyber impact and business impact; a phased roadmap (quick wins, foundational controls, advanced maturity); and budgetary pricing by phase, with optional packages, so you can plan before you commit.
Do we have to fix everything ourselves afterwards?
No. The roadmap is yours: you can run it internally, with your IT provider or with us. Our implementation and managed services teams can take on any part of it, from a single control (MFA, EDR, segmentation, backups) to the full program, including keeping it effective over time.
Is the assessment confidential?
Yes. Findings, collected evidence and the results of the technical validation are covered by confidentiality terms agreed with your organization before work begins. The report is presented to your leadership in a workshop and belongs to you; we neither publish nor reuse its content.

Let's talk about your compliance program.

Last updated: 2026-09-17