Security Posture Reviews
Find out how strong your security is today and what to fix first. A point-in-time review of your controls, benchmarked against recognised frameworks, with a prioritised roadmap.
Service Details
A security posture review tells you how strong your security is today and what to fix first. We review the controls protecting your identities, devices, cloud services, data and policies, benchmark them against a recognised framework, and give you a prioritised roadmap to close the gaps.
It is often the first piece of work we do with a new client, because every later decision is easier once you know where you stand. The review sits within our assessments and engineering services, alongside the testing and engineering work that acts on what it finds.
INFO
You get a clear baseline you can share with your board, insurer or auditor, and a plan that puts your budget where it reduces the most risk.
A clear picture of your security, in plain English
Most organisations have built up security controls over years, through different suppliers and projects. Nobody has a full view of what is switched on, what is half-configured and what was never done.
A posture review gives you that view. Each finding explains the risk in business terms, the fix in technical terms, and how urgent it is, so leadership and IT can agree on what happens next.

What the review covers
We look at the controls that stop the most common attacks and keep you running when something goes wrong:
Identity and Access
Multi-factor authentication, admin accounts, sign-in policies, joiner and leaver processes and access reviews.
Endpoints
Laptops, desktops and phones: encryption, patching, malware protection and how devices are managed.
Cloud and Collaboration
Microsoft 365 or Google Workspace settings, email security, file sharing, and Azure, AWS or Google Cloud configuration.
Network
Firewalls, remote access, Wi-Fi, segmentation and the services you expose to the internet.
Backups and Recovery
What is backed up, whether backups are protected from ransomware, and whether restores have been tested.
Policies and Suppliers
Security policies, incident response plans, staff awareness and how you check the suppliers who hold your data.
Where we find weaknesses, our identity and access, endpoint management, Microsoft 365, Google Workspace and cloud security teams can fix them, or you can hand the roadmap to your own IT team or provider.
Who a posture review is for
A posture review suits you if you have never had an independent look at your security, or if the last one is out of date. Typical triggers include a new IT or security lead wanting a baseline, a board asking how exposed the business is, or an insurer’s questionnaire you are not sure how to answer.
It also helps before a certification or audit, so you know the size of the gap before you commit to a date. If you are buying or investing in a business rather than reviewing your own, technical due diligence applies the same thinking to a deal timetable.

How we work
- Scoping — We agree which parts of the organisation, systems and framework the review covers, and who we need to speak to.
- Interviews — We talk to IT, leadership and key teams to understand how security works in practice, not just on paper.
- Technical checks — With read-only access, we examine configuration in your identity platform, devices, cloud tenants and backup tooling.
- Benchmarking — We score each control against the chosen framework and rate every gap by risk and effort to fix.
- Readout — We walk your team and leadership through the results and answer questions before anything is finalised.
What you receive
The output is built to be used, not filed. Leadership gets a short summary they can act on, and the people doing the work get enough detail to start straight away.
Maturity baseline
A score per control area you can re-measure next year
Findings report
Each gap explained, with risk rating and fix
Prioritised roadmap
Quick wins first, then larger projects in order
How it differs from testing and risk management
A posture review asks whether the right controls are in place and set up well. Penetration testing asks a different question: can an attacker actually break in through a specific system? Testing is most useful once the review’s quick wins are done, so you are not paying a tester to find missing basics.
Risk management is the ongoing work that follows. Gaps from your review are scored by likelihood and business impact, given owners and tracked in a risk register, so progress continues between reviews.
Evidence for audits and certification
Your findings are mapped to the framework you choose, so the report doubles as a gap analysis. Common choices are the CIS Controls, the NIST Cybersecurity Framework (CSF) 2.0 and Cyber Essentials, the UK government-backed scheme covering five technical controls. We can also map to ISO 27001 or sector rules such as DORA for financial firms.
When you are ready to work towards certification, our compliance support team can take the roadmap from there.
Services that work alongside
A posture review is a starting point. Threat and vulnerability management keeps finding and fixing weaknesses after the review ends, and user awareness training addresses gaps in staff behaviour. If you need someone to own the roadmap at leadership level, a fractional CISO can steer it, and board advisory helps directors understand what the findings mean for them.
Frequently asked questions
Find out where you stand
Tell us about your organisation and what prompted the question. We will suggest a review scope that fits, and what you can expect to have in hand at the end of it.