Cyber security assessment · Cyber Essentials · Security questionnaires
Cyber security assessment · a senior security lead reviews how you are protected
A cyber security assessment is a structured review of how well a business is protected: its governance, risks, controls, suppliers, incident response and people. We deliver it by placing a senior practitioner, a fractional or interim CISO, who runs the assessment inside your business and stays to fix what it finds if you want them to.
To bring in a fractional CISO for an assessment, brief us on what you need reviewed and why. We send a shortlist of 3–5, each with pay or day rate, availability and IR35 position set out, after five-stage vetting. We are not a certification body and we do not certify.
How a brief runswhat we undertake
- 01Brief30-MINUTE SCOPING CALLDay 0
- 02Shortlist of 3–5VETTED · RATE BENCHMARK · IR35After the brief
- 03InterviewsYOU MEET THE SHORTLISTYour diary
- 04Scoped startFIRST-MONTH OUTCOMES AGREEDYou set the date
- 05Fractional, interim and permanentIR35 POSITION SET OUTOn every brief
Shortlist3–5
15 minutes · video or phone
Book 15 minutes to hire a security lead
Tell us the scope and the days a week. We come back with Security Lead candidates, their day rates and availability.
- 0115 minutes, video or phone
- 02We scope the role and the days a week
- 03A shortlist of 3–5 after the call
- 04Fractional, interim and permanent briefs
Pick a day that suits · live availability
Live roles · last 3 months
Live Security and technology leadership jobs
Live security leadership roles
Fractional recruitment works differently from a permanent search — shorter, scoped by days a week, and priced on the engagement. Send a Security Lead brief and we come back with a shortlist of three to five vetted candidates.
01/ the role
Cyber security assessment: what a senior lead reviews
A cyber security assessment tells the board where the business stands and what to do first. It is led by a senior person who can judge risk, not only run a scan. A useful frame is the NCSC’s 10 Steps to Cyber Security, which breaks the job of protecting an organisation into components a reviewer can test one by one.
Governance
Who owns cyber risk, how it reaches the board, and whether the board asks the right questions. The government’s Cyber Governance Code of Practice sets out the actions directors should take, and the NCSC’s Cyber Security Toolkit for Boards explains how to put them in place.
Risk
What information and systems matter most, what could go wrong, and who owns each risk. If you handle personal data, the UK GDPR requires appropriate technical and organisational measures based on an analysis of the risks, so the assessment also shows whether you can evidence that.
Controls
Access, patching, configuration, malware protection, backups, logging and monitoring: whether each control exists, whether it works, and whether anyone would notice if it stopped. The lead samples evidence rather than taking a policy at its word.
Suppliers
Which suppliers hold your data or can reach your systems, what you require of them, and how you check. The NCSC’s supply chain security guidance sets out principles for gaining control and oversight of a supply chain.
Incident response
Whether there is a plan, whether people know it, and whether it has been rehearsed. The NCSC’s incident management guidance covers planning, building and maintaining a response capability, linked to business continuity and crisis management.
People
Training, joiners and leavers, privileged users, and whether staff know how to report something odd. For how other UK organisations approach these questions, the government’s annual Cyber Security Breaches Survey is the official statistics series to read.
02/ scope
Cyber Essentials: a certification, not an assessment
Cyber Essentials is the UK government-backed certification scheme that the NCSC describes as the minimum standard of cyber security recommended for organisations of all sizes. It covers firewalls, secure configuration, security update management, user access control and malware protection. A growing number of organisations ask suppliers to hold it before they bid.
How it is certified
The scheme is delivered by IASME, the NCSC’s Cyber Essentials Delivery Partner. Certification is renewed each year. You can take the self-led route, a verified self-assessment signed off by a board member and marked by an assessor, or pay a licensed certification body for support. Cyber Essentials Plus is arranged directly with a certification body.
How it differs from an assessment
Cyber Essentials checks a defined set of technical controls and gives you a certificate. A cyber security assessment is broader: it looks at governance, risk, suppliers, incident response and people as well, and gives you a judgement and a plan, not a certificate. Many businesses use the assessment to find their gaps, then certify to Cyber Essentials, and later to ISO 27001 (see our ISO 27001 consultant page).
03/ vetting
How we vet security leads
What we undertake on every brief, before a candidate reaches you.
- 01
Qualification screen
Verify Security Lead tenure, sector context and stage fit.
SOURCING - 02
Mandate fit
Match to your situation — stage, board dynamics, timing.
MATCHING - 03
Reference deep-dive
We take references ourselves, from recent past clients — real outcomes, not titles.
VERIFY - 04
Shortlist
Three to five candidates with day rate, availability and IR35 position set out.
SHORTLIST OF 3–5
04/ security questionnaire
Security questionnaire: answering customers so the sale keeps moving
A security questionnaire is the set of questions a customer sends before it buys: how you control access, where data is held, how you handle incidents, which certifications you hold, and how you manage your own suppliers. Larger customers send them as standard, and a slow or vague answer can stall a sale.
A senior security lead answers them from evidence. They build a library of approved answers and supporting documents, so sales does not start from a blank page each time, and they join the customer call when the security team wants to talk to someone who owns the answers.
The rule is simple: never claim a control you do not have. Where there is a gap, the honest answer is what you do today and the date you have committed to internally. The assessment on this page is often how that library starts.
05/ hire a fractional CISO
Hire a fractional CISO to run the assessment and what follows
When you hire a fractional CISO, you get a senior security lead for part of the week who runs the assessment, presents it to the board and then owns the plan. See our hub to hire a fractional CISO, what a fractional CISO costs, and the ISO 27001 route if certification is next. For full-time cover over a fixed period, an interim CISO fits better.
The same model covers a technology audit or technology due diligence, led by a senior technology practitioner. For that, see how to hire a fractional CTO or an interim CTO.
We send a shortlist of 3–5, each with pay or day rate, availability and IR35 position set out, after our five-stage vetting. IR35 status is decided by how the engagement runs, and a medium or large client makes the determination; our IR35 guide sets out the tests.
06/ questions
Cyber security assessment FAQ
The questions people ask before bringing in a security lead.

Book 15 minutes · shortlist of 3–5
Bring the brief. We architect the team.
A shortlist of 3–5 with day rate, availability and IR35 position set out, after five-stage vetting.
