Cyber security assessment · Cyber Essentials · Security questionnaires

Cyber security assessment · a senior security lead reviews how you are protected

A cyber security assessment is a structured review of how well a business is protected: its governance, risks, controls, suppliers, incident response and people. We deliver it by placing a senior practitioner, a fractional or interim CISO, who runs the assessment inside your business and stays to fix what it finds if you want them to.

To bring in a fractional CISO for an assessment, brief us on what you need reviewed and why. We send a shortlist of 3–5, each with pay or day rate, availability and IR35 position set out, after five-stage vetting. We are not a certification body and we do not certify.

How a brief runswhat we undertake

  1. 01Brief30-MINUTE SCOPING CALLDay 0
  2. 02Shortlist of 3–5VETTED · RATE BENCHMARK · IR35After the brief
  3. 03InterviewsYOU MEET THE SHORTLISTYour diary
  4. 04Scoped startFIRST-MONTH OUTCOMES AGREEDYou set the date
  5. 05Fractional, interim and permanentIR35 POSITION SET OUTOn every brief

Shortlist3–5

3–5
Shortlist · with pay or day rate, availability and IR35 set out
5
Vetting · stages before a candidate reaches you

15 minutes · video or phone

Book 15 minutes to hire a security lead

Tell us the scope and the days a week. We come back with Security Lead candidates, their day rates and availability.

  1. 0115 minutes, video or phone
  2. 02We scope the role and the days a week
  3. 03A shortlist of 3–5 after the call
  4. 04Fractional, interim and permanent briefs
Prefer email? Use the booking page →

Pick a day that suits · live availability

Live security leadership roles

Fractional recruitment works differently from a permanent search — shorter, scoped by days a week, and priced on the engagement. Send a Security Lead brief and we come back with a shortlist of three to five vetted candidates.

01/ the role

Cyber security assessment: what a senior lead reviews

A cyber security assessment tells the board where the business stands and what to do first. It is led by a senior person who can judge risk, not only run a scan. A useful frame is the NCSC’s 10 Steps to Cyber Security, which breaks the job of protecting an organisation into components a reviewer can test one by one.

Governance

Who owns cyber risk, how it reaches the board, and whether the board asks the right questions. The government’s Cyber Governance Code of Practice sets out the actions directors should take, and the NCSC’s Cyber Security Toolkit for Boards explains how to put them in place.

Risk

What information and systems matter most, what could go wrong, and who owns each risk. If you handle personal data, the UK GDPR requires appropriate technical and organisational measures based on an analysis of the risks, so the assessment also shows whether you can evidence that.

Controls

Access, patching, configuration, malware protection, backups, logging and monitoring: whether each control exists, whether it works, and whether anyone would notice if it stopped. The lead samples evidence rather than taking a policy at its word.

Suppliers

Which suppliers hold your data or can reach your systems, what you require of them, and how you check. The NCSC’s supply chain security guidance sets out principles for gaining control and oversight of a supply chain.

Incident response

Whether there is a plan, whether people know it, and whether it has been rehearsed. The NCSC’s incident management guidance covers planning, building and maintaining a response capability, linked to business continuity and crisis management.

People

Training, joiners and leavers, privileged users, and whether staff know how to report something odd. For how other UK organisations approach these questions, the government’s annual Cyber Security Breaches Survey is the official statistics series to read.

02/ scope

Cyber Essentials: a certification, not an assessment

Cyber Essentials is the UK government-backed certification scheme that the NCSC describes as the minimum standard of cyber security recommended for organisations of all sizes. It covers firewalls, secure configuration, security update management, user access control and malware protection. A growing number of organisations ask suppliers to hold it before they bid.

How it is certified

The scheme is delivered by IASME, the NCSC’s Cyber Essentials Delivery Partner. Certification is renewed each year. You can take the self-led route, a verified self-assessment signed off by a board member and marked by an assessor, or pay a licensed certification body for support. Cyber Essentials Plus is arranged directly with a certification body.

How it differs from an assessment

Cyber Essentials checks a defined set of technical controls and gives you a certificate. A cyber security assessment is broader: it looks at governance, risk, suppliers, incident response and people as well, and gives you a judgement and a plan, not a certificate. Many businesses use the assessment to find their gaps, then certify to Cyber Essentials, and later to ISO 27001 (see our ISO 27001 consultant page).

03/ vetting

How we vet security leads

What we undertake on every brief, before a candidate reaches you.

  1. 01

    Qualification screen

    Verify Security Lead tenure, sector context and stage fit.

    SOURCING
  2. 02

    Mandate fit

    Match to your situation — stage, board dynamics, timing.

    MATCHING
  3. 03

    Reference deep-dive

    We take references ourselves, from recent past clients — real outcomes, not titles.

    VERIFY
  4. 04

    Shortlist

    Three to five candidates with day rate, availability and IR35 position set out.

    SHORTLIST OF 3–5

04/ security questionnaire

Security questionnaire: answering customers so the sale keeps moving

A security questionnaire is the set of questions a customer sends before it buys: how you control access, where data is held, how you handle incidents, which certifications you hold, and how you manage your own suppliers. Larger customers send them as standard, and a slow or vague answer can stall a sale.

A senior security lead answers them from evidence. They build a library of approved answers and supporting documents, so sales does not start from a blank page each time, and they join the customer call when the security team wants to talk to someone who owns the answers.

The rule is simple: never claim a control you do not have. Where there is a gap, the honest answer is what you do today and the date you have committed to internally. The assessment on this page is often how that library starts.

05/ hire a fractional CISO

Hire a fractional CISO to run the assessment and what follows

When you hire a fractional CISO, you get a senior security lead for part of the week who runs the assessment, presents it to the board and then owns the plan. See our hub to hire a fractional CISO, what a fractional CISO costs, and the ISO 27001 route if certification is next. For full-time cover over a fixed period, an interim CISO fits better.

The same model covers a technology audit or technology due diligence, led by a senior technology practitioner. For that, see how to hire a fractional CTO or an interim CTO.

We send a shortlist of 3–5, each with pay or day rate, availability and IR35 position set out, after our five-stage vetting. IR35 status is decided by how the engagement runs, and a medium or large client makes the determination; our IR35 guide sets out the tests.

06/ questions

Cyber security assessment FAQ

The questions people ask before bringing in a security lead.

A structured review of how well a business is protected, covering governance, risk, controls, suppliers, incident response and people. It ends with a judgement for the board and a prioritised plan. We deliver it by placing a senior practitioner, a fractional or interim CISO, who runs it.

No. Cyber Essentials is a government-backed certification scheme that checks a defined set of technical controls. An assessment is broader and gives you a plan, not a certificate. Many businesses do the assessment first, then certify.

Yes. The security lead we place answers them from evidence, builds a library of approved answers for sales, and joins customer calls where needed. They never claim a control you do not have.

No. We are not a certification body and we do not certify, for Cyber Essentials, ISO 27001 or anything else. We place the senior practitioner who prepares you; an independent certification body assesses you.

Write down what you need reviewed and why (a board request, a customer, a tender, an incident), who the lead will report to, and whether they should stay on to fix what they find. We send a shortlist of 3–5, each with pay or day rate, availability and IR35 position set out. See our fractional CISO hub.

It depends on the scope, the days a week and how long the work runs. We set out each candidate’s pay or day rate on every shortlist. Our fractional CISO cost page sets out sourced day-rate bands, and the rate calculator multiplies a day rate by the days you need.

Yes, by the same model: we place a senior technology practitioner, usually a fractional or interim CTO, who runs the work. See how to hire a fractional CTO.

Book 15 minutes · shortlist of 3–5

Bring the brief. We architect the team.

A shortlist of 3–5 with day rate, availability and IR35 position set out, after five-stage vetting.

Fractional Quest logo — how to hire a fractional CISO, cyber security assessment