Skip to content
IT21

The IT Risk & Readiness Assessment

Find out where you stand in weeks, not quarters

You suspect there are gaps. You do not know which ones would matter to an auditor, a customer, or an attacker, or what it would cost to close them. This is a defined engagement that answers that.

Most technology decisions in mid-market companies get made without a current picture. A vendor recommends a product. A board member reads about a breach. A customer sends a questionnaire nobody can answer. Money gets spent in the direction of whatever asked most recently, which is not the same as the direction of the most risk.

This assessment produces the picture. It is built on COBIT (Control Objectives for Information and Related Technologies), the governance framework auditors, examiners and boards use to judge whether an organization's technology is being managed properly. Using a recognized framework matters for a practical reason: the results are already in the language the people who will question you speak.

What it covers

How technology decisions get made and who is accountable. Who has access to what, including administrative access and accounts belonging to people who have left. How changes reach production systems. Whether backups restore, and whether anyone has checked. How incidents are detected and what happens in the first hour. Third-party and vendor risk. Whether the controls you are subject to — through regulation, a contract, or an insurer — are documented and operating.

How it runs

We ask for a short list of documents in advance and send questionnaires that become part of our source record. We interview a small number of people — usually whoever runs technology, whoever runs finance, and one or two people who do the daily work — and we corroborate what we are told rather than taking it at face value, because the gap between the documented process and the real one is where most findings live. We inspect system configuration directly instead of accepting a description of it. Then we test controls the way an auditor does: a test of design, to see whether a control could work as intended, and a test of operating effectiveness, to see whether it actually did over a period, on real transactions. Knowing how to scope and build those tests properly is what separates an assessment that holds up from one that only reads well.

What you get

A written report with findings ranked by risk, each one written the way an auditor would write it, with what we saw, why it matters to your organization specifically, and what closing it involves. A remediation sequence with rough effort attached, so you can decide what belongs in this budget year and what can wait. A short executive summary a board or an owner can read in a sitting. And a conversation to walk through it.

Two things this is not. It is not a vulnerability scan with several hundred rows and no priorities. And it is not a sales instrument — a fair number of assessments end with a short list of things a client's own team can fix, and that is a good outcome.

[PLACEHOLDER: scope tiers and typical duration — to be set after the partner meeting. Price held at $0.00 for now.]

Tell us a little about your organization using the form on this page and we will come back with scope and cost.

  • Assess
  • Transform
  • Optimize

Request the assessment

HubSpot form — assessment-request — not configured

Set portalId and forms.assessment-request in src/lib/hubspot.ts.

Email
Company
Submit

Oscar Chacon, CISA

Certified Information Systems Auditor since 1997