Cybersecurity risk assessment

Know what is exposed, what matters, and what to fix first.

We map your real systems, people, vendors, and controls to NIST CSF and CIS Controls. You receive a scored risk register, evidence-backed findings, and a sequenced remediation roadmap.

Book a 30-minute scope call

Scope, timing, and fees are documented before work begins.

Illustrated security posture gauge moving from exposed to protected
  • 2–4 weeksTypical delivery window
  • One scopeAgreed before kickoff
  • One advisorFrom kickoff through findings
  • Written outputReport, register, and roadmap

Why companies book this now.

01

Someone is asking

An insurer, an enterprise customer, a regulator, or your own board. The first question is always the same: when was your last risk assessment? It’s a lousy question to answer with “never.”

02

Alerts aren’t a program

Your MSP’s tools generate alerts. Alerts are noise until somebody ranks them. An assessment turns unknowns into a list with owners, costs, and dates.

03

It’s the cheapest step

Every remediation dollar goes further when you know which gap actually matters. The assessment is how you find out.

Best fit: regulated small and midsize organizations with an IT team or MSP, multiple systems or vendors, and a board, insurer, customer, or compliance deadline asking for documented risk decisions.

Not the right fit: organizations seeking a checkbox certification, an emergency incident-response team, or penetration testing without a broader risk assessment.

What you get.

Every assessment includes

  • Network topology map + asset inventory
  • Vulnerability scan (external + internal)
  • Policy & documentation review
  • Staff interviews + evidence review
  • Framework assessment (NIST CSF / CIS Controls)
  • HIPAA module (if healthcare) or insurance readiness module
  • Vendor & third-party risk review
  • Risk register with scored findings
  • Executive report + 30/60/90 remediation roadmap
  • Findings walkthrough call

Example report structure

HW / RISK REGISTERExecutive priorities
HighIdentity and privileged access30 days
MedVendor access review60 days
PlanPolicy and evidence refresh90 days

Illustrative structure only. Your findings, owners, evidence, costs, and priorities are based on your environment.

See what your scope includes

How pricing works

Priced by scope. Fixed in writing.

There’s no rate card, because no two environments are the same size. Your quote is built from four things, then fixed in writing at the free 30-minute briefing, before any work starts.

Headcount

More people means more interviews, more accounts, and more evidence to review.

Locations

Each site adds physical review, network segments, and scheduling.

Systems

An EHR, heavy cloud, or a long vendor list adds surface area to map and verify.

Modules

HIPAA, penetration testing, or IR planning extend the scope where they apply.

Your proposal documents the work, deliverables, assumptions, timing, and fees before kickoff. Any change to that scope requires written approval.

Separately scoped when needed

Penetration testing, remediation labor, onsite travel, new software, and third-party audit or certification fees are not included unless they appear in your written proposal.

Three steps. Minimal disruption.

01

Private risk briefing (30 min, free)

We learn how your business runs and give you an honest read, even if the honest read is “you’re in decent shape.” Then your exact scope and fixed price go in writing.

02

The assessment (2–4 weeks)

Scan-first: we map the network and check for exposures, then verify with your people. Your team’s total time: a few hours.

03

Report, roadmap & follow-through

A leadership walkthrough in plain English, a sequenced fix-it plan your IT can execute, and a retainer if you want it run for you.

How the work lands with leadership and IT.

Aprio
The assessment brought up the right uncomfortable questions around access, client data, and old accounts. The consultants at Hardenwell handled it professionally and helped us separate urgent work from cleanup work.
Brent M.Chief Digital Officer and Partner
Stewart Title
The hard part was not finding things to improve. It was knowing which improvements mattered most. Our Hardenwell advisor helped weigh risk, effort, and business impact so the plan felt practical.
John H.Chief Information Officer

Questions we hear about this service.

Book your scope call.

Thirty minutes with an advisor.

We’ll cover your organization, systems, deadline, and the evidence already available. You’ll leave knowing the likely scope, timing, and next step.

Prefer phone or email?

(754) 216-9664 info@hardenwell.com

Do not include PHI or sensitive records in booking notes. See our Privacy Policy.

Book a call