Skip to content
Practice · 12 August 2026 · 4 min read

What a first security assessment actually covers

Not a scanner report. A prioritised picture of how you would be breached, and what to do about it this quarter.

Clients often expect a first assessment to be a long list of findings ranked by a scanner's severity. That list has a place, but it is not the deliverable. The deliverable is an answer to one question: if someone wanted in, how would they do it, and what would stop them?

Scope in days, not weeks

We agree the estate up front: external attack surface, cloud accounts, identity provider, the applications that matter, and any AI systems in use. A focused week beats an unbounded month.

Three lenses

  • Exposure: what is reachable and what it reveals.
  • Identity: who can get to what, and how hard it is to become them.
  • Blast radius: what one compromised account or key would allow.

Findings with a fix path

Every finding comes with the change that closes it, who should own it, and roughly how long it takes. Ranked by exploitability and business impact, so the first week of fixes removes the most risk.

A report two audiences can read

One page for the board with the picture and the plan; the technical detail behind it for the engineers. If the board page needs a glossary, we have failed.

Then, if it makes sense, we stay: hardening alongside your team and monitoring what we hardened.