Business Services — Assessment

Network & Security Assessment

A structured, evidence-based review of your current network and security architecture. Identifies real risk, misconfigurations, and compliance gaps — before they become incidents.

Back to Business Services Network and security assessment — structured architecture review

What This Service Addresses

Most organisations reach a point where their network infrastructure has evolved faster than their understanding of it. Devices have been added, configurations changed, and rules accumulated — often by multiple people over several years. The result is infrastructure that functions most of the time, but whose actual security posture is unknown.

A Network & Security Assessment provides an accurate, evidence-based picture of the current state. It identifies what the infrastructure actually does — not what documentation says it does — and maps that against risk, best practice, and applicable regulatory requirements such as DORA and NIS2.

Scope of the Assessment

  • Architecture review — mapping the actual network topology, traffic flows, and trust boundaries as they exist, not as originally designed
  • Segmentation and access control evaluation — verifying that network segments are correctly defined and that access controls enforce the intended boundaries
  • Firewall and routing configuration review — examining rule sets, routing tables, and ACLs for misconfigurations, redundant rules, and unintended access paths
  • Risk identification — documenting exposure points, lateral movement paths, and single points of failure that represent meaningful operational or security risk
  • DORA and NIS2 gap analysis — mapping findings to relevant regulatory requirements and identifying where current infrastructure does not meet compliance obligations
  • Prioritised remediation roadmap — findings structured by risk severity with clear, actionable next steps

What the Assessment Does Not Do

An assessment is diagnostic, not a penetration test. It does not involve active exploitation attempts. The focus is on architecture, configuration, and policy — understanding what the infrastructure allows and what it should not. Where penetration testing is appropriate, this will be indicated in the findings.

What You Receive

  • Current state documentation — an accurate map of the existing network architecture, including topology, segmentation, and key configuration decisions
  • Risk-prioritised findings report — every finding classified by severity (critical, high, medium, low) with evidence and clear explanation of the risk
  • DORA / NIS2 compliance gap analysis — specific mapping of findings to regulatory articles, where applicable
  • Remediation roadmap — prioritised recommendations with enough technical detail for internal teams or implementation partners to act on
  • Executive summary — a concise overview suitable for presentation to leadership, board, or auditors

Typical Situations

An assessment is most commonly initiated in one of these circumstances:

  • Pre-compliance preparation — organisations preparing for DORA, NIS2, or sector-specific audit who need to understand their current posture before engaging with regulators or auditors
  • Unknown risk posture — IT leadership that cannot confidently answer the question "are we secure?" because the infrastructure has grown beyond anyone's complete understanding
  • Post-incident review — following a security incident, breach, or near-miss, to understand how the incident occurred and what systemic changes are needed
  • M&A due diligence — assessing the network security posture of an acquisition target before integration
  • Infrastructure migration planning — as preparation before a significant cloud migration, data centre consolidation, or network redesign
"You cannot improve what you do not accurately understand. An assessment creates the baseline — everything else follows from it."

How the Assessment Is Delivered

Assessments are delivered remotely, using secure remote access to network management systems and configuration exports. On-site access is not typically required. The standard engagement timeline is 5–10 business days from access to final report, depending on the scale and complexity of the environment.

The assessment begins with a structured intake to understand the environment, key concerns, and compliance context. It concludes with a findings walkthrough session where results are explained in detail and questions addressed before the final report is issued.

Frequently Asked Questions

What does the assessment cover?

The assessment examines your network architecture, firewall policies, access control configurations, key device configurations (routing, switching, remote access), and existing documentation — evaluated against recognised best practice and, where applicable, DORA/NIS2 requirements. Scope is defined and agreed before work begins.

How long does an assessment take?

Delivery is typically within 3–5 business days of receiving the required access and documentation. Scoping discussions usually take an additional 1–2 days before the review begins.

What deliverables will I receive?

A structured report with findings classified by severity (Critical / High / Medium / Low), actionable remediation guidance for each finding, and an executive summary suitable for non-technical stakeholders.

Is access to live production systems required?

For the configuration review, read-only access to device configurations and firewall policies is needed. This can be provided via exported configuration files rather than direct live-system access, which is acceptable in most cases.

Does the assessment address DORA or NIS2 compliance?

Findings are mapped to DORA and NIS2 requirements where applicable, highlighting gaps that may affect compliance. The assessment is not a formal compliance audit, but it provides the technical input that informs one.

Ready to understand your actual security posture?

An assessment typically begins within 5–10 business days of engagement. Get in touch to discuss scope and access requirements.

Book Assessment