Two questions, answered together. First: are your controls in place? Every one of the 56 safeguards in CIS Controls v8.1 Implementation Group 1 is scored Met, Partial, Gap, or N/A against real evidence pulled from your Microsoft 365 tenant, endpoints, and infrastructure. Second: what could actually go wrong here, how badly, and what should you fix first? That answer comes from a full NIST SP 800-30 risk assessment — the federal standard for cybersecurity risk — which is what turns a list of gaps into a defensible order of work.
What you get
- ✓ Kickoff workshop and discovery questionnaire
- ✓ Evidence collection across M365, endpoints, and on-prem systems
- ✓ 56-safeguard gap assessment with a 0–100% maturity score
- ✓ NIST SP 800-30 risk assessment — every risk rated for likelihood and impact, with the reasoning written down
- ✓ Current and residual risk profile: where you stand now, and where the roadmap takes you
- ✓ Prioritized P1/P2/P3 remediation roadmap, sequenced by risk rather than by ease
- ✓ Signed Compliance Attestation + one-page Executive Dashboard
- ✓ Evidence Binder (40–80 pages) with every control cited
What it means for you
- A documented baseline you can hand to an insurer, customer, or board
- A straight answer to "what should we fix first?" — and the reasoning behind it
- Risk assessment evidence for NIST CSF and a Texas SB 2610 safe-harbor position
- Evidence that survives scrutiny — not a template PDF
Who it’s for
New clients, annual re-assessments, prospects evaluating their posture, or any business facing a cyber-insurance renewal, customer due-diligence questionnaire, or regulatory change.
Before you decide
Read a complete one first.
We publish a full 23-page sample risk assessment for a fictional Texas manufacturer — the whole deliverable, not an outline. It’s the fastest way to tell whether our work is worth $9,500 of yours.