I have sat through more cyber security assessment sales pitches than I care to count, and they all follow the same pattern. A vendor in a nice suit shows up with a slide deck full of scary statistics, promises to “identify your vulnerabilities,” and quotes you a number that could fund a small department. Three weeks later you get a 200-page PDF that tells you things you already knew, formatted in a way that impresses executives who do not understand the technical details.
A proper cyber security assessment is genuinely valuable. The problem is that the term has been stretched so far by marketing departments that it can mean almost anything – from a 15-minute automated vulnerability scan to a six-month red team engagement. If you are responsible for commissioning one, you need to understand what you are actually buying.
What a Cyber Security Assessment Is Supposed to Accomplish
At its core, a cyber security assessment is a structured evaluation of an organisation’s security posture. It should answer three questions: What do we have? How well is it protected? Where are the gaps? Everything else is detail.
The problem is that different types of assessments answer these questions at different depths, and vendors have a financial incentive to sell you the most expensive option regardless of whether it is the right fit. Before engaging anyone, you need to understand the taxonomy.
Types of Cyber Security Assessment
Vulnerability Assessment. This is the most basic form of cyber security assessment – an automated scan of your network, systems, and applications to identify known vulnerabilities. Tools like Nessus, Qualys, or OpenVAS are pointed at your infrastructure, they run their checks, and you get a report listing CVEs sorted by severity. A competent internal team can do this themselves. If a vendor is charging you consultancy rates for essentially running Nessus and reformatting the output, you are being taken for a ride.
That said, a good vulnerability assessment includes validation. Automated scanners produce false positives. Someone with actual technical knowledge needs to verify findings, assess their real-world exploitability in your specific environment, and prioritise remediation based on context rather than just CVSS scores. The raw scanner output is data. The analysis is where the value lies.
Penetration Test. A pentest goes beyond identifying vulnerabilities to actually exploiting them. A skilled tester attempts to compromise your systems using the same techniques an attacker would – but with rules of engagement, a defined scope, and without causing actual damage. The deliverable is not just a list of vulnerabilities but a narrative of how they chain together to achieve specific objectives: gaining domain admin, accessing the database, exfiltrating test data.
Pentests come in several flavours. External tests target your internet-facing perimeter. Internal tests simulate an attacker who already has a foothold on the network (or a malicious insider). Web application tests focus specifically on your web apps and APIs. The scope should be agreed in writing before anyone touches a keyboard. If your vendor cannot articulate the difference between these, find a different vendor.
Risk Assessment. This is less technical and more strategic. A risk assessment evaluates threats to your organisation, the likelihood of those threats materialising, and the potential impact if they do. It considers not just technical vulnerabilities but also processes, policies, physical security, personnel, and third-party dependencies. Frameworks like ISO 27005, NIST SP 800-30, or OCTAVE provide structured methodologies for conducting risk assessments.
A risk assessment should produce a risk register – a prioritised list of risks with estimated likelihood and impact, existing controls, and recommended mitigations. This feeds directly into security planning and budget justification. If your CISO needs ammunition to request funding, a well-conducted risk assessment is the tool to use.
Compliance Audit. This is a cyber security assessment measured against a specific standard or regulation: PCI DSS, ISO 27001, HIPAA, SOC 2, GDPR, or whatever applies to your industry. The assessor evaluates whether your controls meet the requirements of the standard. The deliverable is typically a gap analysis showing where you comply, where you fall short, and what you need to do to close the gaps.
Compliance does not equal security – a point I will keep making until I am blue in the face. You can be fully PCI compliant and still get breached. You can have excellent security practices and fail a compliance audit on a technicality. But compliance is a business requirement for many organisations, so these assessments serve a necessary purpose.
Scoping a Cyber Security Assessment Properly
The single biggest factor that determines whether a cyber security assessment delivers value is how well it is scoped. A vague scope produces vague results.
Before engaging a vendor or starting an internal assessment, define:
- Objectives. What specifically do you want to learn? “Find our vulnerabilities” is not specific enough. “Determine whether an external attacker can reach the payment processing system” is.
- Scope boundaries. Which systems, networks, applications, and locations are in scope? Which are explicitly out of scope? Put it in writing.
- Assessment type. Based on your objectives, which type of assessment is appropriate? You might need a combination – a vulnerability assessment of the full estate plus a targeted pentest of critical systems.
- Rules of engagement. For pentests: Can the tester use social engineering? Are denial-of-service attacks permitted? What are the communication protocols if a critical vulnerability is found during testing?
- Timeline and resources. When will the assessment happen? Who is the internal point of contact? What access will the assessor need?
What the Deliverables Should Look Like
A cyber security assessment report should be actionable. If you finish reading a 200-page report and still do not know what to do next, the report has failed.
Good deliverables include:
- An executive summary that a non-technical board member can understand, with clear risk ratings and business impact statements
- A technical findings section with enough detail for your engineering team to reproduce and remediate each issue
- Evidence – screenshots, packet captures, command outputs – proving each finding is real and not a false positive
- Prioritised remediation recommendations with estimated effort and impact for each
- A risk-based prioritisation that considers your specific business context, not just generic CVSS scores
If the report reads like it could apply to any organisation with the company name swapped out, it is a template job and you should demand better.
Red Flags When Engaging a Vendor
After years of reviewing cyber security assessment proposals and deliverables, here are the warning signs I look for:
- The proposal quotes a fixed price without asking detailed scoping questions first
- The vendor cannot name the specific tools and methodologies they will use
- They promise to find “all” vulnerabilities (nobody can guarantee that)
- The assessment timeline seems unreasonably short for the scope (a comprehensive pentest of a large environment in two days is a scan, not a pentest)
- Previous report samples are mostly auto-generated scanner output with a cover page
- They cannot provide references from organisations of similar size and complexity
A competent assessor will push back on unrealistic scopes, ask difficult questions about your environment before quoting, and be transparent about the limitations of their approach. If everything they say sounds too good and too easy, it probably is.
The best cyber security assessment is one that tells you something you did not already know and gives you a clear path to fix it. Everything else is expensive wallpaper.