Someone is asking
An insurer, an enterprise customer, a regulator, or your own board. The first question is always the same: when was your last risk assessment? It’s a lousy question to answer with “never.”
Cybersecurity risk assessment
We map your real systems, people, vendors, and controls to NIST CSF and CIS Controls. You receive a scored risk register, evidence-backed findings, and a sequenced remediation roadmap.
Scope, timing, and fees are documented before work begins.
An insurer, an enterprise customer, a regulator, or your own board. The first question is always the same: when was your last risk assessment? It’s a lousy question to answer with “never.”
Your MSP’s tools generate alerts. Alerts are noise until somebody ranks them. An assessment turns unknowns into a list with owners, costs, and dates.
Every remediation dollar goes further when you know which gap actually matters. The assessment is how you find out.
Best fit: regulated small and midsize organizations with an IT team or MSP, multiple systems or vendors, and a board, insurer, customer, or compliance deadline asking for documented risk decisions.
Not the right fit: organizations seeking a checkbox certification, an emergency incident-response team, or penetration testing without a broader risk assessment.
Every assessment includes
Example report structure
Illustrative structure only. Your findings, owners, evidence, costs, and priorities are based on your environment.
See what your scope includesHow pricing works
There’s no rate card, because no two environments are the same size. Your quote is built from four things, then fixed in writing at the free 30-minute briefing, before any work starts.
More people means more interviews, more accounts, and more evidence to review.
Each site adds physical review, network segments, and scheduling.
An EHR, heavy cloud, or a long vendor list adds surface area to map and verify.
HIPAA, penetration testing, or IR planning extend the scope where they apply.
Your proposal documents the work, deliverables, assumptions, timing, and fees before kickoff. Any change to that scope requires written approval.
Separately scoped when needed
Penetration testing, remediation labor, onsite travel, new software, and third-party audit or certification fees are not included unless they appear in your written proposal.
We learn how your business runs and give you an honest read, even if the honest read is “you’re in decent shape.” Then your exact scope and fixed price go in writing.
Scan-first: we map the network and check for exposures, then verify with your people. Your team’s total time: a few hours.
A leadership walkthrough in plain English, a sequenced fix-it plan your IT can execute, and a retainer if you want it run for you.
The assessment brought up the right uncomfortable questions around access, client data, and old accounts. The consultants at Hardenwell handled it professionally and helped us separate urgent work from cleanup work.
The hard part was not finding things to improve. It was knowing which improvements mattered most. Our Hardenwell advisor helped weigh risk, effort, and business impact so the plan felt practical.
The price is built from four things: headcount, number of locations, system complexity (an EHR, heavy cloud, many vendors), and which modules apply (HIPAA, penetration testing). We fix the scope and the price at the free briefing, in writing. No hourly billing, and changes only by signed change order.
NIST CSF and CIS Controls form the spine. If you’re healthcare, the HIPAA Security Rule module maps on top; if an enterprise customer or insurer is asking, the insurance readiness module does. One assessment, read two ways: executives get the risk story, IT gets the work list.
No. Your team’s total time is a few hours across two to four weeks. Scans run in windows we agree on ahead of time, and interviews are scheduled around your work.
A walkthrough with leadership, then the 30/60/90 roadmap. Most clients move to a fractional CISO retainer so the roadmap actually gets run: we direct, your IT executes, and a reassessment a year later proves the progress. The retainer is recommended, never required.
We’ll cover your organization, systems, deadline, and the evidence already available. You’ll leave knowing the likely scope, timing, and next step.
Prefer phone or email?
(754) 216-9664 info@hardenwell.com
Do not include PHI or sensitive records in booking notes. See our Privacy Policy.