B://ASSESS26Risk Assessment
Where you are
actually exposed.
A point-in-time assessment of your technology and security posture against a recognised standard, producing a ranked list of what to fix. It is for organisations that need a defensible answer to how exposed they are, often for an insurer, a board, or a customer.
THE PROBLEM
Being told you are probably fine is not an answer you can give to an insurer, a board, or a customer.
The cost of leaving this alone is rarely one visible failure. It is the slow accumulation: the workaround that became the process, the thing only one person knows, the renewal nobody questioned.
Our starting point is always the same: establish what is actually true today, then decide what to change. Work scoped against an assumption tends to solve a problem you do not have.
- 01Nobody owns itIt sits with whoever touched it last, which is not the same as being managed.
- 02No current pictureWhat you have, what it costs, and who has access are all slightly out of date.
- 03Only handled when it breaksAttention arrives after the disruption rather than before it.
WHAT YOU GET
What the engagement covers
Scoped before it starts, so you know what is included and what is not.
- 01
Assessment
Configuration, access, and process reviewed against a recognised framework rather than against opinion.
- 02
Ranked findings
Rated by real-world exploitability and business impact, not by the severity score a tool printed.
- 03
Remediation plan
What to fix first, what it takes, and what it costs.
- 04
Written report
Two versions: one for the technical team, one a board can read without a translator.
HOW WE WORK
Scope, assess, report, support
Four stages with a written output at each one. You always know which stage you are in and what comes next.
- 01Week 1
Scope
We agree what is being examined and what a useful answer looks like, so the work is not open-ended.
- 02Weeks 2 – 3
Assess
Evidence gathered from your systems and your people, because the documented process and the real one rarely match.
- 03Week 4
Report
Findings written for a decision maker: what is true, what it means, and what we would do about it, ranked.
- 04As needed
Support
We can hand the report over and step back, or stay and deliver the remediation. Both are normal.
WHAT CHANGES
What you should expect
- Someone other than you owns it, with that written down.
- The current state is documented and stays documented.
- Cost is planned ahead rather than discovered at renewal.
- Decisions are made against evidence rather than assumption.
FAQ
Questions we get asked
01What is risk assessment?
A point-in-time assessment of your technology and security posture against a recognised standard, producing a ranked list of what to fix. It is for organisations that need a defensible answer to how exposed they are, often for an insurer, a board, or a customer.
02What is the difference between a risk assessment and a penetration test?
An assessment reviews your controls, configuration, and processes against a framework and tells you where the gaps are across the whole environment. A penetration test attempts to exploit specific systems to prove what an attacker could achieve. Assessment first is usually the right order, because a penetration test against an environment with known unaddressed gaps tends to produce an expensive report confirming what you already suspected.
03How long does a cyber risk assessment take?
For most small and mid-sized organisations, two to four weeks from scoping to report, depending on the size of the environment and how quickly we can get access to the information. The demand on your team is usually a handful of interviews and access to systems, rather than sustained involvement.
04Our insurer or a customer is asking for this. Will your report satisfy them?
Usually yes, and we will confirm what they specifically require before we start rather than after. Requirements vary: some want an assessment against a named framework, some want evidence of particular controls, some want a penetration test and will not accept an assessment instead. Establishing that up front avoids paying for the wrong piece of work.
05What do you typically find?
The same handful of things, in most environments. Multi-factor authentication not applied everywhere, particularly on service and administrator accounts. Former staff who still have access somewhere. Backups that have never been restored from. Administrator rights granted broadly because it was easier. And no documented process for what happens during an incident. None of these are exotic, and all of them are what actual breaches are built on.
06Do we have to use you for the remediation?
No. The report is written to be actionable by anyone, including your internal team or another provider, and plenty of clients take it away and do exactly that. We are happy to deliver the remediation if you want us to, and we would rather the work got done than that it waited for us.
07How much does risk assessment cost in New Zealand?
We quote after scoping rather than before. Anyone pricing this work without looking at your environment is guessing, and the guess is rarely in your favour. Scoping itself is quick, and we tell you what it costs before we start it.
08How long does it take to get started with risk assessment?
A first conversation takes about half an hour and costs nothing. Scoping is usually a week or two of our time depending on the size of the environment, and we agree the delivery dates with you before anything is booked in.
09Can you deliver risk assessment alongside our existing IT team or provider?
Yes, and it is common. We are happy to work as an extra pair of hands under your internal team, or alongside an incumbent provider on a defined piece of work. We will set out in writing where the responsibilities split, so nothing falls between us.
10Do we have to use Atlas for the work the report recommends?
No. This can be delivered as a standalone piece of work for an organisation we have never worked with before, or folded into a managed agreement if you already have one with us. Plenty of clients use us for one thing and keep everything else where it is.
11Do you work with organisations outside Auckland?
Our team is based in Auckland and we attend sites across the wider region. Most of this work is delivered remotely, so we support organisations throughout New Zealand, and we will say up front where being on site genuinely matters.
12Who does the assessment, and who presents the findings?
Named people, not a queue. You get a lead who knows your environment and stays with it, which is the difference between explaining your business once and explaining it every time you make contact.
13What do we actually receive at the end?
You keep the documentation regardless, and anything registered in your name stays in your name. Whether we stay involved is your call. Some clients take it in house from there, others move it onto an ongoing agreement with us. We would rather you left cleanly than stayed because leaving was difficult.
Start with a conversation.
Tell us what you are dealing with and we will tell you whether this is the right service for it, and what it would take.
← All services