Advisory

Best Practice Security Assessment

An independent review of your people, processes and technology, with a ranked plan of what to fix first.

See where you stand. Know what to fix first.

A Best Practice Security Assessment helps you manage the risks to your data. We measure how mature your current information security capabilities are, find the weak areas and rank what to fix first. The review goes beyond technology. We look at your people, processes and technology together, so you understand your overall risk posture. If you need it, we can add an in-depth code review and testing of your whole security architecture.

Best Practice Security Assessment

Risk ranked by what matters to your business.

An assessment identifies, estimates and ranks the risks to your operations and assets. It helps you manage weak spots and limit the threat to your data. It matters even more when your business depends on financial transactions.

We start with how your organisation makes money, how people and assets affect that income, and which risks could cause large losses. Then we look at how to improve your IT infrastructure to reduce the biggest financial risks.

Risk = Asset × Threat × Vulnerability. If an asset is worth nothing to you, the risk of losing money through it is zero.

  • Asset

    How important the assets at risk are to the business.

  • Threat

    How critical the threat is.

  • Vulnerability

    How exposed your systems are to that threat.

When you must meet a standard.

The assessment can be the first step towards a specific standard. These services take it further.

PCI DSS

Gap analysis, assessment and ongoing support for organisations that handle card data.

ISO 27001

Build an information security management system and prepare it for certification.

APRA CPS 234

Information security obligations for APRA-regulated entities, including banks, insurers and superannuation trustees.

How the assessment runs.

Findings come from three sources of evidence: people, systems and documents.

  1. Step 1: Plan

    Agree the scope, the people to speak with and any standard you must meet.

  2. Step 2: Interview

    Talk with management, data owners and other staff about how security works day to day.

  3. Step 3: Analyse systems

    Review your systems and infrastructure to see how controls are set up in practice.

  4. Step 4: Review documents

    Examine your policies, procedures, records and plans, and compare them with what we observe and hear.

  5. Step 5: Rate and rank

    Rate the maturity of each capability and rank each weak area by the risk it creates for the business.

  6. Step 6: Report

    Present the findings and a ranked remediation plan to your team and leadership.

What the assessment covers.

Maturity review

The maturity of your information security capabilities today, measured consistently across each area.

People

Roles, responsibilities, awareness and how decisions about security are made.

Processes

Policies and procedures, and whether what happens in practice matches what is written down.

Technology

Your systems and infrastructure, and how well the controls on them are set up.

Code review

On request, an in-depth review of application code to find security flaws.

Architecture testing

On request, testing across your whole security architecture to confirm how controls hold up.

What you have at the end.

  • A clear view of how mature your security is today.

  • A list of weak areas across people, processes and technology.

  • A remediation plan ranked by risk to the business.

  • An understanding of your overall risk posture that leadership can act on.

Security assessment questions.

How is this different from a penetration test?

A penetration test attacks specific systems to find weaknesses an attacker could use. This assessment looks wider, at people, processes and technology, and measures how mature your security is overall. We can add testing when you need it.

Is this a compliance audit?

No. It measures your security against good practice and gives you a plan. It does not certify you. If you need to meet a particular standard, tell us and we will take it into account.

What do you need from us?

Time with management, data owners and other staff, access to review your systems and infrastructure, and your security documentation.

What happens after the assessment?

You get a ranked plan of what to fix first. You can act on it with your own team or ask Vectra to help, and repeat the assessment later to measure progress.

Start with a conversation.

Speak to us about your cyber governance and compliance requirements.