Skip to content

Assess · Cyber Security Assessments

Understand where you stand. Know what to improve.

A structured cyber security assessment gives you a clearer view of your current arrangements, where material gaps exist and what should happen next. H Change provides proportionate assessments against recognised frameworks, requirements or an agreed scope.

Our approach

How we approach assessments.

01

Agree what we're assessing

Start with the reason for the assessment, the appropriate framework or scope, and the evidence that will be needed.

02

Look at evidence, not assumptions

Review relevant documentation, arrangements and discussions with appropriate people to understand what is actually in place.

03

Prioritise what happens next

Findings should help you improve. Material gaps and recommendations are prioritised so you can distinguish immediate priorities from longer-term improvements.

What we offer

Options and pricing.

Choose the piece that fits, or talk to us about combining them. Fixed prices apply where the scope is predictable; where it depends on your organisation, we say what affects it.

  • NIST CSF Assessment

    A structured assessment of your current cyber security arrangements against the NIST Cybersecurity Framework, helping you understand areas of strength, gaps and improvement priorities.

    • Initial scoping discussion
    • Agreement of assessment scope
    • Review against relevant NIST CSF outcomes
    • Review of available supporting evidence
    • Discussions with relevant people where appropriate
    • Identification of strengths and material gaps
    • Prioritised recommendations
    • Written findings report
    • Findings discussion

    The depth, scope and final price depend on your organisation. This is an advisory assessment, not NIST certification.

    From £1,500

    Depends on the size and complexity of the organisation.

  • NIS Readiness Review

    A structured review for organisations that need to better understand their cyber security arrangements in the context of relevant NIS requirements.

    • Requirements and scope discussion
    • Review of relevant security arrangements
    • Review of available evidence
    • Identification of material gaps
    • Prioritised improvement recommendations
    • Written findings
    • Findings discussion

    The review looks at your security arrangements. It does not determine whether your organisation is legally in scope of NIS and is not legal or regulatory advice; specialist legal or regulatory advice should be sought when determining formal obligations.

    Quoted separately

    Scoped around the requirement.

  • Cyber Security Gap Assessment

    A structured assessment against an agreed set of security expectations, customer requirements or defined control areas. Suited to organisations that need something more structured than the Cyber Security Health Check but do not necessarily need a full framework assessment.

    • Scope and requirements discussion
    • Agreement of assessment criteria
    • Evidence review
    • Relevant stakeholder discussions
    • Identification of gaps
    • Prioritised recommendations
    • Concise written findings
    • Findings discussion

    From £1,250

    Final scope and price depend on the requirement.

Which do I need?

Health Check or Cyber Security Assessment?

Neither is better than the other. They answer different questions, so the right choice depends on what has prompted the requirement.

Cyber Security Health Check

Best when
You want a practical, high-level view of your current cyber security arrangements and where to start.
Approach
Broad review across people, process and technology.
Output
Concise findings and prioritised Now / Next / Later recommendations.
Price
£595

Cyber Security Assessment

Best when
You need a more structured review against a framework, requirement or agreed assessment criteria.
Approach
Defined scope, assessment criteria and evidence review.
Output
Structured findings, identified gaps and prioritised improvement recommendations.
Price
From £1,250 depending on assessment.

Frameworks

Recognised frameworks. Applied proportionately.

NIST Cybersecurity Framework

NIST CSF provides a structured way to understand and improve how an organisation manages cyber security risk. It gives you a common language for describing your current position and a sensible basis for deciding what to improve.

NIS

NIS requirements apply to certain organisations and sectors, and place expectations around the management of cyber security and resilience. An H Change review can help you examine your relevant security arrangements, but does not determine legal applicability or provide regulatory certification.

Assess to improve

A useful assessment doesn't end with a score.

The purpose of an assessment is not simply to identify gaps. It should help you decide what to do about them. H Change translates findings into practical priorities, helping you understand what matters now, what can follow and where further work may be needed.

What you get

What you should leave with.

  • A clearer understanding of your current cyber security position
  • Evidence-based findings rather than assumptions
  • Identified strengths and material gaps
  • Prioritised recommendations
  • A practical basis for planning improvements
  • Findings that can support internal conversations with decision-makers

Scope of an assessment

H Change Cyber Security Assessments are advisory assessments designed to support understanding and improvement. Unless explicitly agreed and appropriately authorised, they are not:

  • certification audits ·
  • regulatory inspections ·
  • penetration tests ·
  • vulnerability assessments ·
  • legal opinions ·
  • guarantees of compliance ·
  • guarantees that a cyber incident will not occur

Free 20-minute consultation

Talk to us about what you need to assess.

Tell us what has prompted the requirement, whether a particular framework or customer requirement is involved, and what you need to understand. We'll help you work out the appropriate starting point.