Cyber risk assessment
A security roadmap your board can approve and your team can deliver.
Boards and insurers want to know the organisation's cyber risk and what is being done about it. In three to five weeks we assess the risks across the whole environment, map them to the framework you need, and give you a costed, sequenced roadmap.

Who it is for
Organisations that need a security plan broader than the Essential Eight: for a board, a new CISO or IT leader, an insurer, a major customer or a regulator. It is the usual starting point for a fractional CISO engagement.

What we assess
- Identity and access, including privileged access and third-party accounts
- Endpoints, servers and the Microsoft security stack
- Network and remote access
- Cloud platforms: Azure, and AWS or GCP where they are part of the estate
- Data: where sensitive information lives and who can reach it
- Suppliers and service providers with access to your systems
- People and process: policies, awareness, incident readiness and recovery
Frameworks
Results are mapped to the framework you need: the NIST Cybersecurity Framework 2.0, ISO 27001, the Essential Eight, APRA CPS 234 or the SOCI Act risk management program. Where you need more than one, a single set of findings is mapped to each.
What you receive
- A risk register, with likelihood, impact and owners
- Maturity against the chosen framework
- A 12 to 24 month roadmap, sequenced and costed in ranges
- A board summary in plain language
How it runs
- Scoping: the framework, the audience for the results and the systems in scope.
- Assessment: configuration review, interviews and evidence across each area.
- Analysis: risks rated, mapped to the framework and turned into a roadmap.
- Readout: results with your leadership, and a board session if you want one.
Questions buyers ask
How is this different from an Essential Eight assessment?
The Essential Eight covers eight specific controls. A cyber risk assessment covers the whole environment, including suppliers, data and process, and maps to wider frameworks.
Does it include penetration testing?
It can. We run penetration tests as part of the assessment or separately, and our engineers fix what they find.
Can you present the results to our board?
Yes. The board summary is written for directors, and we can present it.
Will the roadmap be tied to a particular provider?
No. The roadmap and findings are yours to deliver with any provider.
What happens next?
Your team can deliver the roadmap, North Ark can deliver it as projects, and a fractional CISO can own it month to month.
Start a conversation
Know your cyber risk before someone asks.
Tell us who needs the answer and by when.
Talk to an Engineer