PCI DSS
Gap analysis, assessment and ongoing support for organisations that handle card data.
An independent review of your people, processes and technology, with a ranked plan of what to fix first.
A Best Practice Security Assessment helps you manage the risks to your data. We measure how mature your current information security capabilities are, find the weak areas and rank what to fix first. The review goes beyond technology. We look at your people, processes and technology together, so you understand your overall risk posture. If you need it, we can add an in-depth code review and testing of your whole security architecture.
An assessment identifies, estimates and ranks the risks to your operations and assets. It helps you manage weak spots and limit the threat to your data. It matters even more when your business depends on financial transactions.
We start with how your organisation makes money, how people and assets affect that income, and which risks could cause large losses. Then we look at how to improve your IT infrastructure to reduce the biggest financial risks.
Risk = Asset × Threat × Vulnerability. If an asset is worth nothing to you, the risk of losing money through it is zero.
How important the assets at risk are to the business.
How critical the threat is.
How exposed your systems are to that threat.
The assessment can be the first step towards a specific standard. These services take it further.
Gap analysis, assessment and ongoing support for organisations that handle card data.
Build an information security management system and prepare it for certification.
Information security obligations for APRA-regulated entities, including banks, insurers and superannuation trustees.
Test the systems the assessment flags as the highest risk.
Findings come from three sources of evidence: people, systems and documents.
Agree the scope, the people to speak with and any standard you must meet.
Talk with management, data owners and other staff about how security works day to day.
Review your systems and infrastructure to see how controls are set up in practice.
Examine your policies, procedures, records and plans, and compare them with what we observe and hear.
Rate the maturity of each capability and rank each weak area by the risk it creates for the business.
Present the findings and a ranked remediation plan to your team and leadership.
The maturity of your information security capabilities today, measured consistently across each area.
Roles, responsibilities, awareness and how decisions about security are made.
Policies and procedures, and whether what happens in practice matches what is written down.
Your systems and infrastructure, and how well the controls on them are set up.
On request, an in-depth review of application code to find security flaws.
On request, testing across your whole security architecture to confirm how controls hold up.
A clear view of how mature your security is today.
A list of weak areas across people, processes and technology.
A remediation plan ranked by risk to the business.
An understanding of your overall risk posture that leadership can act on.
A penetration test attacks specific systems to find weaknesses an attacker could use. This assessment looks wider, at people, processes and technology, and measures how mature your security is overall. We can add testing when you need it.
No. It measures your security against good practice and gives you a plan. It does not certify you. If you need to meet a particular standard, tell us and we will take it into account.
Time with management, data owners and other staff, access to review your systems and infrastructure, and your security documentation.
You get a ranked plan of what to fix first. You can act on it with your own team or ask Vectra to help, and repeat the assessment later to measure progress.
Speak to us about your cyber governance and compliance requirements.