Many systems, one scale.

A broader assessment across multiple systems, shared services or an entire estate, with risk normalised so exposure can be compared and ranked across the whole.

RegisterSorted by residualSample
R-02 14
R-01 8
R-05 9
R-03 6
R-04 4
R-06 3

Across an estate, the ranking is the deliverable. The top of this list is where the next dollar goes.

What triggers this engagement.

You need to know where the worst exposure sits across several systems, and answers scored by different people at different times are not comparable.

Where the boundary sits.

A scope that is not written down is a scope that grows. Ours is agreed before work starts and it is printed in the report.

In scope
  • Every system in the agreed boundary, scored on one scale
  • Shared services and the dependencies between systems
  • Concentration risk where several systems rest on one provider
  • An aggregate view alongside the system-level detail
Out of scope
  • Systems outside the agreed boundary, named explicitly in the report
  • Exploitation in practice
  • Vendor negotiation, though the findings support it
What we need
  • A working list of systems in the boundary, however rough
  • Access to system owners across the estate
  • Whatever documentation exists, gaps included
Timeline

Longer than a single system, and scheduled together during scoping once the boundary is agreed.

What you receive.

One document, layered so that a board and an engineering team can both work from it.

01Executive summary covering the estate as a whole
02Aggregate register ranked by residual across every system
03Per-system registers that stand on their own
04Threat model covering shared and system-specific threats
05Roadmap sequenced by risk reduction per unit of effort

Is this the right scope for you?

Tell us the decision you are facing. If a different engagement fits better, we will say so before you commit to this one.

Request an assessment