# Cyber security assessments.

> A cyber security risk assessment for London businesses: where you are exposed, what matters most and a practical plan to fix it.

Canonical: https://cybersecuritylondon.com/cyber-security-assessments


The best place to start. We look at your systems, people and suppliers, find the weaknesses most likely to cause you harm, and give you a clear, prioritised plan.

Covers: Risk assessment, Third-party risk, Prioritised roadmap, Board-ready report.

## Overview

A cyber security assessment answers three questions: where are we exposed, what would hurt most, and what should we fix first? It covers technology, but also how people work and which suppliers you depend on.

You get a short report written for decision makers, and a practical roadmap that puts the most important fixes first, so budget goes where it makes the biggest difference.

### A good fit if

- You don't know where your biggest risks are
- You are preparing for growth, investment or a sale
- A client has sent you a security questionnaire
- You want a baseline before choosing other services

## What's included

- **Business context**: We start with how you operate and which systems and data matter most.
- **Technical review**: Configuration, access, backups, email security, devices and cloud services.
- **People and process**: How staff handle data, passwords and suspicious requests.
- **Supplier risk**: A look at the third parties who hold your data or access your systems.
- **Risk register**: Each risk scored by likelihood and impact, in business terms.
- **Prioritised roadmap**: A clear order of work, with quick wins first.

## How it works

1. **Understand**: Interviews and a review of how your business runs.
2. **Assess**: Technical checks across systems, cloud and devices.
3. **Score**: Each risk rated by likelihood and business impact.
4. **Plan**: A prioritised roadmap, walked through with you.

## Assessment options

- **Cyber security risk assessment**: A full review of technical, people and supplier risk, with a scored risk register.
- **Security posture review**: A quicker health check of your core controls against good practice.
- **Third-party risk assessment**: A review of the suppliers and partners who could expose you.
- **Pre-certification gap analysis**: An assessment against Cyber Essentials or ISO 27001 before you apply.

## What affects the cost

- **Size of business**: The number of people, sites and systems involved.
- **Scope**: Whether the assessment covers technology only or people and suppliers too.
- **Complexity**: On-premises, cloud and hybrid environments take different amounts of time.
- **Depth of report**: A health check is quicker than a full risk register and roadmap.

Assessments are quoted at a fixed price, agreed after a short initial conversation.

## Frequently asked questions

### What is a cyber security risk assessment?

It is a structured review of the threats your business faces, how likely they are and what impact they would have. It produces a ranked list of risks and a plan to reduce them.

### How long does a cyber security assessment take?

Most assessments take one to three weeks from kick-off to final report, depending on size and scope.

### What do we need to prepare?

Very little. A short list of key systems and suppliers, and time with the people who run them. We guide you through the rest.

### Where should a small business start with cyber security?

With an assessment. It shows where the real risk is, so you spend money on what matters rather than on products you may not need.

## Related services

- [Security Audits](https://cybersecuritylondon.com/security-audits)
- [Penetration Testing](https://cybersecuritylondon.com/penetration-testing)
- [Cyber Essentials](https://cybersecuritylondon.com/cyber-essentials)

## Contact

Email enquiry@cybersecuritylondon.com or use the enquiry form at https://cybersecuritylondon.com/#contact. Cyber Security London, The Leather Market, London Bridge, London.
