Assess · Cyber Security Assessments
Understand where you stand. Know what to improve.
A structured cyber security assessment gives you a clearer view of your current arrangements, where material gaps exist and what should happen next. H Change provides proportionate assessments against recognised frameworks, requirements or an agreed scope.
Our approach
How we approach assessments.
Agree what we're assessing
Start with the reason for the assessment, the appropriate framework or scope, and the evidence that will be needed.
Look at evidence, not assumptions
Review relevant documentation, arrangements and discussions with appropriate people to understand what is actually in place.
Prioritise what happens next
Findings should help you improve. Material gaps and recommendations are prioritised so you can distinguish immediate priorities from longer-term improvements.
What we offer
Options and pricing.
Choose the piece that fits, or talk to us about combining them. Fixed prices apply where the scope is predictable; where it depends on your organisation, we say what affects it.
NIST CSF Assessment
A structured assessment of your current cyber security arrangements against the NIST Cybersecurity Framework, helping you understand areas of strength, gaps and improvement priorities.
- Initial scoping discussion
- Agreement of assessment scope
- Review against relevant NIST CSF outcomes
- Review of available supporting evidence
- Discussions with relevant people where appropriate
- Identification of strengths and material gaps
- Prioritised recommendations
- Written findings report
- Findings discussion
The depth, scope and final price depend on your organisation. This is an advisory assessment, not NIST certification.
From £1,500
Depends on the size and complexity of the organisation.
NIS Readiness Review
A structured review for organisations that need to better understand their cyber security arrangements in the context of relevant NIS requirements.
- Requirements and scope discussion
- Review of relevant security arrangements
- Review of available evidence
- Identification of material gaps
- Prioritised improvement recommendations
- Written findings
- Findings discussion
The review looks at your security arrangements. It does not determine whether your organisation is legally in scope of NIS and is not legal or regulatory advice; specialist legal or regulatory advice should be sought when determining formal obligations.
Quoted separately
Scoped around the requirement.
Cyber Security Gap Assessment
A structured assessment against an agreed set of security expectations, customer requirements or defined control areas. Suited to organisations that need something more structured than the Cyber Security Health Check but do not necessarily need a full framework assessment.
- Scope and requirements discussion
- Agreement of assessment criteria
- Evidence review
- Relevant stakeholder discussions
- Identification of gaps
- Prioritised recommendations
- Concise written findings
- Findings discussion
From £1,250
Final scope and price depend on the requirement.
Which do I need?
Health Check or Cyber Security Assessment?
Neither is better than the other. They answer different questions, so the right choice depends on what has prompted the requirement.
Cyber Security Health Check
- Best when
- You want a practical, high-level view of your current cyber security arrangements and where to start.
- Approach
- Broad review across people, process and technology.
- Output
- Concise findings and prioritised Now / Next / Later recommendations.
- Price
- £595
Cyber Security Assessment
- Best when
- You need a more structured review against a framework, requirement or agreed assessment criteria.
- Approach
- Defined scope, assessment criteria and evidence review.
- Output
- Structured findings, identified gaps and prioritised improvement recommendations.
- Price
- From £1,250 depending on assessment.
Frameworks
Recognised frameworks. Applied proportionately.
NIST Cybersecurity Framework
NIST CSF provides a structured way to understand and improve how an organisation manages cyber security risk. It gives you a common language for describing your current position and a sensible basis for deciding what to improve.
NIS
NIS requirements apply to certain organisations and sectors, and place expectations around the management of cyber security and resilience. An H Change review can help you examine your relevant security arrangements, but does not determine legal applicability or provide regulatory certification.
Assess to improve
A useful assessment doesn't end with a score.
The purpose of an assessment is not simply to identify gaps. It should help you decide what to do about them. H Change translates findings into practical priorities, helping you understand what matters now, what can follow and where further work may be needed.
What you get
What you should leave with.
- A clearer understanding of your current cyber security position
- Evidence-based findings rather than assumptions
- Identified strengths and material gaps
- Prioritised recommendations
- A practical basis for planning improvements
- Findings that can support internal conversations with decision-makers
Scope of an assessment
H Change Cyber Security Assessments are advisory assessments designed to support understanding and improvement. Unless explicitly agreed and appropriately authorised, they are not:
- certification audits ·
- regulatory inspections ·
- penetration tests ·
- vulnerability assessments ·
- legal opinions ·
- guarantees of compliance ·
- guarantees that a cyber incident will not occur
Related
Often combined with
Once you have findings, ongoing cyber security advice can help you work through the priorities in the right order.
Free 20-minute consultation
Talk to us about what you need to assess.
Tell us what has prompted the requirement, whether a particular framework or customer requirement is involved, and what you need to understand. We'll help you work out the appropriate starting point.