Questions, answered plainly.

Straight answers on scope, method, timing and what you walk away with. If your question is not here, ask it directly.

What is a threat risk assessment?

A threat risk assessment identifies what matters in your environment, models the threats that could affect it, and scores the resulting risk before and after the controls you have in place. The outcome is a ranked, defensible view of where your exposure really sits and what to do about it first.

How long does an assessment take?

Timing depends on scope. A single system or platform assessment usually runs a few weeks from kickoff to final report, while a programme or estate-wide assessment runs longer and is scheduled together during scoping. We agree the timeline before any work begins and we hold to it.

What do you need from us to begin?

Access to the people who understand the systems in scope, any architecture or data flow documentation you already hold, and a clear statement of the decision the assessment has to support. Where documentation is thin we fill the gaps through structured interviews, so a lack of paperwork is rarely a blocker.

How is this different from a penetration test?

A penetration test demonstrates that specific weaknesses can be exploited in practice. A threat risk assessment sits earlier and reaches wider. It identifies what is at risk, how likely harm is and what it would cost, then ranks it. The two answer different questions, and we will tell you when a test would sharpen the picture rather than sell you an assessment that cannot.

Which frameworks do you align to?

Our scoring follows NIST SP 800-30, and the work aligns to ISO/IEC 27005:2022 for organizations in the ISO world. Threat modelling uses STRIDE and is grounded in MITRE ATT&CK. Building on published standards rather than a proprietary scale means the assessment speaks the same language as your auditors and regulators.

What do we receive at the end?

One report, layered so a board and an engineering team can both work from it. It contains an executive summary, a ranked risk register with owners, the threat model, control recommendations matched to what you already run, and a remediation roadmap sequenced by risk reduction.

Can you help with remediation afterwards?

The assessment itself stops at the roadmap, so that our findings stay independent of who implements them. Where you want help carrying them out, the wider Cyber Electra group can pick up privacy, compliance or architecture work without starting the relationship over.

How much does an assessment cost?

Cost follows scope, so we do not publish fixed prices. Tell us what you need assessed and the decision it supports, and we will scope the work and quote it before anything begins. We would rather propose a smaller engagement that answers your question than a larger one that does not.

Is our information kept confidential?

Yes. Client engagements are confidential and governed by the agreement in place for the work. Anything we publish is either our own reference research or a client example anonymised with permission. Our handling of personal information is set out in the privacy policy.

Do you work outside Canada?

We are based in Aurora, Ontario, and we work with organizations worldwide. The method does not change with location, though we calibrate impact and regulatory context to where you operate.

Still have a question?

Ask it directly and a member of the practice will answer. We read every enquiry ourselves.

Get in touch