Renewal questions
Your carrier wants evidence of controls, not a yes/no answer that nobody has verified.
A cybersecurity risk assessment is a point-in-time review that turns your policies, configurations, and interviews into a defensible picture of where you actually stand: a NIST CSF 2.0 Current Profile, an agreed Target Profile, severity-ranked findings, and a prioritized remediation roadmap. DSE runs it as a national, fixed-fee engagement, typically 5 to 10 business days after kickoff. It answers the question your insurer, your board, or your biggest customer is about to ask: what's the risk, and what gets fixed first?
A point-in-time cybersecurity risk assessment for leaders who need a defensible view of exposure, not another generic checklist. We turn interviews, configurations, policies, and operating evidence into results. You get a NIST CSF 2.0 Current Profile, an agreed Target Profile, severity-ranked findings, and a prioritized roadmap.
For COO, CFO, CTO, risk, security, and IT leaders across the United States.
Your carrier wants evidence of controls, not a yes/no answer that nobody has verified.
A customer questionnaire or procurement review is exposing uncertainty across owners and systems.
Leadership needs a concise risk picture, investment choices, and accountable next steps.
New people, systems, vendors, or locations have outpaced the control environment.
A phishing event, account compromise, outage, or near miss. It raised questions the team cannot yet answer.
You have tools and policies. But you have no evidence-based view of whether the controls operate together.
We document the outcomes your organization currently achieves. That spans Govern, Identify, Protect, Detect, Respond, and Recover. It is based on evidence, not aspiration.
We agree on the outcomes appropriate to your obligations and threat exposure. We factor in your operating model and business priorities. The gap between profiles focuses the roadmap.
A bounded evidence request covers policies, inventories, access, configurations, recovery, vendors, and prior findings. Focused interviews test ownership and operating reality.
We rate observed gaps using likelihood and business impact. Then we record evidence strength, affected outcomes, and urgency. Severity is not a vulnerability score. We explain it in the report.
Each finding states what we observed and why it matters. It gives the supporting evidence, a recommended action, and an accountable owner.
Immediate actions and a sequenced 90-day roadmap balance risk reduction, dependencies, effort, and cost. Leadership receives an executive readout.
Typical timebox: 5 to 10 business days after kickoff and timely evidence access. Complex or regulated environments are scoped separately. National engagement price is scoped after the diagnostic and confirmed in writing before work begins.
Synthetic sample, illustrative only. It contains no client information and is not a finding about any organization.
The sample table scrolls horizontally on smaller screens. Keyboard users can focus the labeled table region and use horizontal navigation.
| CSF 2.0 outcome | Observed evidence | Rating | Recommended move |
|---|---|---|---|
| PR.AA · Identity and access | MFA is enforced for administrators; two legacy access paths remain outside the policy. | High | Disable legacy authentication; validate emergency-access controls; assign identity owner. |
| RC.RP · Recovery planning | Backups run daily; the team could not provide a recent restore-test record. | High | Run a representative restore test, record recovery time, and schedule quarterly evidence. |
| GV.SC · Cyber supply chain | Critical vendors are listed, but security review and renewal owners are inconsistent. | Moderate | Tier vendors, set minimum evidence, and attach accountable owners to renewal dates. |
Final ratings depend on the environment, evidence, and agreed methodology. We do not convert CSF outcomes into a purported certification score.
NIST CSF 2.0 is the organizing framework. Where useful, we map recommended safeguards to CISA Cross-Sector Cybersecurity Performance Goals and CIS Controls. These serve as supporting implementation references. The mappings help teams act. They do not make the assessment a CISA or CIS audit. They do not imply endorsement.
Price is scoped after the diagnostic and confirmed in writing before work begins, so the fee matches the number of systems, locations, and regulated data you actually have, not a generic rate card.
Typical timebox is 5 to 10 business days after kickoff and timely evidence access. Complex or regulated environments are scoped separately.
NIST CSF 2.0 is the organizing framework, structured as a Current Profile and an agreed Target Profile. Where useful, we map recommended safeguards to the CISA Cross-Sector Cybersecurity Performance Goals and CIS Critical Security Controls as supporting references, not a separate certification.
No. It is a point-in-time assessment: not an audit, not a certification, not an attestation, not a penetration test, and not legal advice. It does not include continuous monitoring or a 24x7 SOC, and it does not include remediation implementation unless that work is separately scoped in writing.
A NIST CSF 2.0 Current Profile, an agreed Target Profile, severity-ranked findings with recommended actions and owners, and a prioritized remediation roadmap leadership can act on. Every finding states what we observed, why it matters, and what to do about it.
This is a point-in-time assessment. It covers the systems, people, documentation, and evidence in the agreed scope. It is not an audit, not a certification, not an attestation, not a penetration test, and not legal advice. It does not include continuous monitoring or a 24x7 SOC. It does not include live incident response or digital forensics and incident response (DFIR). It does not include remediation implementation unless that work is separately scoped in writing. It does not guarantee prevention of an incident, insurance eligibility, contract award, or compliance outcome. Counsel, auditors, insurers, and certification bodies retain their respective roles.
Related free assets: Cybersecurity Assessment Sample Excerpt · NIST CSF 2.0 Current-vs-Target Profile Workbook
Deep dive: What a cybersecurity risk assessment includes and costs