Cyber security risk assessment

A cyber security risk assessment your board can budget against.


We assess your security controls against NIST CSF 2.0, model the threats that matter to your business, and hand back a costed roadmap that shows what to fix first and what it will take.

Typically four weeks · Led by a CISSP-certified consultant · Letter of assessment included

The problem

The board wants a number. The control list can't give one.

Most organisations have security controls, a framework they refer to and audits they pass. What is usually missing is the link between those controls, the risks the business faces and the evidence a bank, partner or regulator expects to see.

Asked for risk, holding a list of tools

The question comes from the board: how exposed are we, and what will it cost to fix? The answer to hand is an inventory of products and a set of audit results.

A framework named, not evidenced

Policies refer to NIST or ISO 27001, but nobody can show an auditor which control meets which requirement.

Controls without an owner

Tools were bought and configured, then the person who set them up moved on. No one can say who checks they still work.

Every gap looks urgent

A long list of findings with no ranking against business impact leaves the budget going to whatever is loudest.

Growth brings estates you didn't design

Acquisitions and new brands add tenants, platforms and suppliers with their own standards, and the picture fragments.

Third parties asking for proof

Banks, partners and regulators want evidence of how cyber risk is managed, and a self-assessment carries little weight with them.

What our assessments find

The same gaps come up in most organisations we assess.

60%+cannot evidence framework alignment to an auditor
1 in 3controls operate without documented ownership or evidence
<20%have a roadmap linking control gaps to business risk

Figures drawn from Talanos risk and maturity assessments.

How it works

Four stages, from business context to a costed plan.

Each stage feeds the next, so findings are checked against how your business works before any recommendation is made.

  1. 01

    Business context

    We learn how the business makes money, what it depends on and which regulators, banks and partners it answers to, so the assessment is proportionate to your situation.

    30-minute scoping call
  2. 02

    Control assessment

    Structured interviews with security, IT, engineering and risk stakeholders, and a review of documents and evidence. Controls are tested on a sample basis and scored against the six Functions of NIST CSF 2.0.

    Current maturity per Function
  3. 03

    Threat and risk analysis

    We model the threats most likely to target your organisation, assess the risk each one poses, and set a target maturity that matches your appetite for risk.

    Target maturity per Function
  4. 04

    Costed roadmap

    Gaps become workstreams, ranked by risk and costed for project effort and ongoing spend, then walked through with your leadership and security team.

    Review and follow-up

Typically four weeks from scoping call to roadmap. Larger or multi-entity organisations take longer, and we confirm the timeline before work starts.

What we assess

All six Functions of NIST CSF 2.0.

We map your controls to the framework's 22 Categories and 106 Subcategories, using our mapping to NIST SP 800-53 Rev 5 to score each control against defined maturity levels. Where ISO 27001 or CIS Controls v8 suit your regulators or customers better, the same method applies to them.

Govern

Risk strategy, roles, policy, oversight and supply chain risk: how cyber risk is owned, prioritised and reported at leadership level.

Identify

Asset management, risk assessment and improvement: what you have, what matters most and where the risk sits.

Protect

Identity and access, awareness and training, data security, platform security and infrastructure resilience.

Detect

Continuous monitoring and adverse event analysis across endpoint, identity, network and cloud.

Respond

Incident management, analysis, reporting and mitigation, including readiness to notify regulators and third parties.

Recover

Recovery plan execution, restoration testing and communication after an incident.

Why Talanos

A roadmap with a price on every line.

Every workstream has a cost

Each workstream carries an estimate of project and running costs, so the roadmap can go straight into a budget discussion.

Led by a CISSP-certified consultant

Every assessment is led by a CISSP-certified consultant, working from what our SOC analysts see attackers do each day.

A letter you can share

Each assessment ends with a letter of assessment on Talanos letterhead, for you to share with auditors, banks, regulators and partners.

The framework your stakeholders expect

NIST CSF 2.0 by default, ISO 27001 or CIS Controls v8 where they fit better. The choice follows your regulators and customers.

What you receive

Three documents, a letter and a walkthrough.

Executive risk summary

The top risks, current and target maturity per Function, and the message for your board, in a few pages.

Control reference

Every in-scope control mapped to the framework, with its maturity score, the evidence reviewed and the gap.

Letter of assessment

Confirms the assessment, its scope, framework and date, for you to share with third parties.

Findings are presented to your leadership and security team in a review session, with a follow-up session included.

In practice

A payments group with a board asking for numbers.

Financial services · Cross-border payments

A multi-brand group growing by acquisition, with several Microsoft 365 tenants across its brands and a CTO asked to put cyber risk in front of the board. We assessed the group against NIST CSF 2.0, modelled the threats most relevant to its business and delivered a costed improvement roadmap.

The group then appointed Talanos to run its security operations.

Accredited and certified
ISO 27001
ISO 9001
Cyber Essentials Plus
CREST Security Operations
FSQS Registered
FAQ

Questions we're asked before an assessment.

What is the difference between a risk assessment and a maturity assessment?

A maturity assessment scores how well your controls are designed and operated against a framework. A risk assessment asks which threats could harm the business and how badly. We do both: controls are scored for maturity against NIST CSF 2.0, then the gaps are ranked by the risk they create for your organisation.

How is this different from a penetration test?

A penetration test attacks specific systems to find exploitable weaknesses. A risk assessment reviews your whole security programme across people, process and technology, and tells you where to invest. Many organisations use both, and the assessment shows where testing is worth doing.

How long does it take?

Typically four weeks from the scoping call to the roadmap. Larger or multi-entity organisations take longer, and we confirm the timeline with you before work starts.

How much of our team's time will it need?

We ask for your process documentation up front and interview a small group of stakeholders from security, IT, engineering and risk. We ask for replies to follow-up queries within three working days, which keeps the assessment on schedule. Controls are tested on a sample basis, so we don't need access to every device.

Which framework do you assess against?

NIST CSF 2.0 by default. It covers governance as well as technical controls and is widely recognised in financial services. If your regulators or customers expect ISO 27001 or CIS Controls v8, we assess against those instead. We agree the framework on the scoping call.

How is it priced?

On the effort your scope needs, agreed with you before work starts. The scoping call is free and without obligation.

Do we have to use Talanos to fix what you find?

No. The roadmap is written so your own team, or any provider you choose, can deliver it. If you want support, we can help with remediation, managed detection and response, and third party risk management.

What is the letter of assessment for?

It confirms that Talanos assessed your organisation, when, against which framework and at what scope. You can share it with auditors, banks, regulators and partners without handing over the full report.

What happens after the roadmap?

We walk your leadership and security team through the findings, and a follow-up session is included. Progress reviews against the roadmap can be added later, to check what has been delivered and adjust the plan.

Ready to talk

Find out where your cyber risk sits, and what it will cost to reduce.

Start with a 30-minute scoping call. We'll agree the framework, the scope and the business risks to focus on. No preparation needed.

Book a scoping call