Security Health Check
Why a Cyber Security Health Check?
​
"No health assessment, no return on investment", we like to say.
​
Just like buying medicine without consulting a doctor, purchasing security solutions without a security health check can be a waste of time and money. Statistically, depending on the context humans are more likely to catch certain diseases over others. The same statistics apply to cyber security.
​
That's why a health check is a good first step to securing an organisation, especially if there is a lack of clarity as to how secure it is today.
Security Health Check Tiers
Practical Infosec offer two security health check tiers: Light and Full
Both our security health check tiers follow a similar approach. We begin with context gathering to understand your organisation and its key assets. From there we move into the gap analysis. Depending on which tier is selected, this analysis will be conducted and scored between a simple or more detailed question set.
The light health check typically requires 2 hours worth of meetings with someone in your organisation, such as senior management or someone who makes decisions regarding technology. The full health check will need at least 2 hours of meetings, but may require more depending on the depth needed for appropriate analysis.
Once all analysis actions have been completed, we then move onto producing the report. Both tiers follow a similar report structure of:
-
Risk identification
-
Any progress made during our sessions
-
Top 5 Key Risks
-
Top 5 recommendations (do now, do in next 3 months, do in following 6 months)
This allows you to appropriately prioritise the remediation actions needed to enhance your organisation’s security program.
​
Below is a break down of each health check tier:​
​
​
​
​​
​​​​​​
If your organisation would like additional support from us, we offer continuation services in the following:
-
The Security Journey - This tailored service provides the management of a cybersecurity program for your organisation. Both of our health check tiers come with one month free of The Security Journey.
-
Monitor and maintain subscription - This lower cost option allows us to still conduct some security monitoring, alongside some general support time per month.
-
Check-in call - We also offer to schedule a free call with you 6 months down the line, just to see how things are going
​​​​​​​​​​​​​​​​​​​​​​​​​​​​
What do you receive as an output?
​
-
A security health check report
-
A security improvement plan
-
A live video call summary of what was identified, what our recommendations are and a chance to answer any questions
​
The health check will identify your security key risks and recommendations. You'll receive a written overview as well as a verbal summary.
​
Implementing the recommendations will reduce the of likelihood and damage of the identified risks.
​
You can use the health check to plan your strategy and cyber security investments. This ensures that money and time spent focuses on the key risks, rather than things which won't address the real problems.
​
With a recent client, our Security Health Check process helped them identify $10,000 of annual savings due to duplicate software licenses and subscriptions that were no longer used.
​​
How do we perform the Health Check?
​
All information is collected through conversations and a security scan of your organisations website.
​
We will start by getting to know your organisation's context, vision and technology use. We then use suitable data (such as cyber incident and breach data relevant to your sector) and analysis methodologies to calculate the key risks and recommendations needed to get your cyber risk levels to an acceptable position.
​
We also run a website security scan in the full tier and other security tests to find issues cyber criminals can use to damage your organisation.
For small organisation, the whole process takes no more than 5 hours of your time in total.
​​
Price:
Full Health Check: From £2,500
Light Health Check: £1,500
​
If you would like a Security Health check or want to ask any questions, you can book a free call here or get in touch.
​