Skip to content
Assessment · Cybersecurity

Cybersecurity Assessment

One in three companies in the region has no way of knowing whether it has already been attacked. The problem is rarely a lack of tools: it is a lack of visibility. We evaluate your security posture —technical controls, processes, governance and culture— against NIST, ISO 27001 and CIS, and deliver a remediation plan prioritised by exposure reduction.

What it is
You cannot protect what you do not know is exposed.

Investing in security without a diagnosis leads to buying tools that do not address the real risk. The assessment reveals your exposure across eight domains, translates it into business risk —probability and impact— and focuses the investment where it lowers exposure most per unit of effort. It is not a scan: it is a posture evaluation.

01

Know your exposure

Identify vulnerabilities and control gaps before an attacker exploits them.

02

Invest where it lowers risk

Focus the budget on what reduces exposure, not on isolated tools.

03

Comply and prove it

Produce the evidence regulators, clients and insurers ask for.

Assessment or consulting

One surveys and maps the route. The other executes it.

These are two different services and it is worth knowing which one you need before contracting. The assessment does the first information-gathering exercise, builds the roadmap and aligns it with the business areas. The consulting practice executes that roadmap. Many organisations contract the first, execute internally what they can and delegate the rest.

Cybersecurity Assessment — this page

Surveys, maps and aligns. It does the first information-gathering exercise across the eight domains, measures maturity against recognised frameworks, quantifies the risk and builds the roadmap. It aligns that roadmap with the business areas, so the priorities are the business's and not only IT's. It runs two to four weeks. It does not modify configurations, does not deploy tools and does not operate anything.

Cybersecurity practice — implementation

Executes the roadmap. It takes the plan the assessment produced and puts it into practice: architecture design, implementation and configuration of controls, and ongoing support, with permanent operation through SOC and Managed Services. It works just as well if you already have a roadmap of your own.

What it covers

Eight domains, evaluated one by one.

Exposure does not live in a single place. We review each domain with the same depth and rate it by maturity level, so the result can be compared against itself the following year.

01

Governance and policy

Governance structure, policies in force, roles and responsibilities, and how far they are followed in practice.

02

Identity and access

MFA, privilege management, account lifecycle and third-party access to the environment.

03

The workplace

Endpoint protection, encryption, patch management and device control.

04

Network and perimeter

Segmentation, traffic control, remote access and exposure of published services.

05

Cloud

Configuration of your Cloud environments, identities, public exposure and shared responsibility with the provider.

06

Data protection

Classification, encryption, backup and leak prevention for the information that sustains the business.

07

Detection and response

Monitoring, event logging, incident procedures and real recovery capability.

08

Third parties and supply chain

Suppliers with access, critical dependencies and what your contract demands on security.

How we do it

Six phases, without touching your operation.

The assessment rests on interviews, configuration review and documentary evidence. There is no intrusive action on your production systems at any point.

01

Scope and preparation

We define the domains, systems and areas to cover, and agree the read-only access required.

02

Interviews

With IT, security and the business areas that depend on the systems evaluated.

03

Technical review

Configurations, policies and documentary evidence, checked against what the interviews said.

04

Gap analysis

Comparison against NIST CSF, ISO/IEC 27001 and CIS Controls, domain by domain, with the gap made explicit in each control.

05

Risk quantification

Each finding with probability and impact, prioritised by criticality to the business.

06

Business alignment

Presentation of findings and roadmap with leadership and the areas involved, so priorities are agreed rather than imposed by IT.

Method and frameworks

What your posture is measured against.

The evaluation does not rest on the judgement of whichever consultant shows up, nor on a vendor catalogue, but on public and auditable frameworks your team can consult and your auditor will recognise. Some define how maturity is rated; others are the technical guides against which what we find gets checked. And your posture is read against the data-protection regime that applies to you: Habeas Data (Ley 1581) in Colombia, the LFPDPPP in Mexico.

01

NIST Cybersecurity Framework

Evaluation framework. It organises posture into functions —identify, protect, detect, respond and recover— and lets each one be rated for maturity separately.

02

ISO/IEC 27001 and 27002

Evaluation framework. The information security management standard and its control catalogue. It is the structure auditors, clients and insurers expect to see documented.

03

CIS Controls

Evaluation framework. Controls prioritised by real effectiveness against the most frequent attack techniques. It is what orders the roadmap.

04

CIS Benchmarks

Technical guide. Secure configuration baselines per platform. They serve to check how what you already have is configured, not only whether the control exists.

05

MITRE ATT&CK

Technical guide. Catalogue of attack techniques observed in the real world. It allows reviewing whether your detection capability covers what is actually used against organisations like yours.

06

NIST SP 800-30

Risk guide. Risk assessment methodology. It is the basis of the probability-and-impact quantification that orders the findings.

Risks of going without

What it costs to keep operating blind.

None of these risks shows up on day one. They all come due together on the day of the incident, when the cost of having known earlier can no longer be recovered.

01

Misdirected investment

Tools get bought that do not address the real risk, and the budget runs out without exposure coming down.

02

A surface nobody measures

Every new system, integration and supplier widens the exposure without anyone recalculating it.

03

More expensive incidents

With no procedures and no tested response capability, recovery time and cost multiply.

04

Compliance at risk

Auditors, clients and insurers ask for evidence that does not exist, and the answer gets improvised.

05

A budget without an argument

Security investment is defended with intuition instead of with quantified risk.

06

Third parties without control

Suppliers with access to the environment that were never evaluated and that nobody reviews periodically.

The figures

The gap is not in the tools: it is in not knowing.

Indicators for small and medium-sized companies in Latin America. Most come from the ESET Security Report 2025, a survey of more than 3,000 security professionals across more than 15 countries in the region. Each card cites its source. Updated August 2026.

32%

have no way of knowing whether they were already attacked

They lack the tools to confirm whether they suffered an attack. The gap is not in defence: it is in visibility. Source: ESET Security Report 2025.

20%

leave their security in untrained hands

Of Latin American SMEs delegate the protection of their digital assets to staff without the specialised training required. Source: Kaspersky, 2025.

38%

do not use centralised anti-malware

Each device protects itself, with no console that allows seeing the whole or responding in a coordinated way. Source: ESET Security Report 2025.

25%

protect corporate mobile devices

Only one in four. The rest have company email and files on devices outside any control. Source: ESET Security Report 2025.

22%

suffered ransomware within two years

While 95% name it as their main concern, one in five has already lived through it. Source: ESET Security Report 2025.

27%

hold cyber risk insurance

The rest absorb the full cost of an incident with no cover to cushion it. Source: ESET Security Report 2025.

What it asks of your team

What it costs you in time, said upfront.

An assessment that does not state the commitment it requires ends up delayed. This is what we need from your side to deliver on time.

01

Two to four weeks

Two weeks in organisations of up to 50 employees; four between 51 and 300. The timeline is agreed before starting.

02

Scheduled interviews

Sessions with IT, security and the business areas that depend on the systems evaluated, booked at the outset.

03

Read-only access

Queries against consoles and existing documentation. At no point is a configuration modified.

04

A single point of contact

One person coordinating schedules and access. It is the factor that most affects hitting the deadline.

05

Whatever documentation exists

Policies, inventories and diagrams, in whatever state they are in. Nothing needs preparing to start.

06

A closing session

The presentation of findings with leadership, where the plan's priorities are decided.

Who it is for

When it makes sense and when it does not.

It makes sense if…

Your organisation has between 10 and 300 employees with hybrid infrastructure; you have to answer audits, clients or insurers with evidence; you are about to set a security budget and need to back it; or you suspect you are investing in tools without knowing whether they address the real risk.

Probably not if…

You already have a mature programme and what you are looking for is execution: in that case go straight to the Cybersecurity practice. Or if you need to demonstrate the exploitability of a specific vulnerability: that is a pentest, and it is a different service.

Benefits

What you gain from the assessment.

A real view of the risk

Your exposure evaluated across technical controls, processes, governance and culture, not just tools.

Risks prioritised by business

Vulnerabilities classified by probability and impact, not by isolated technical severity.

A focused remediation plan

Actions ordered by how much exposure they remove against the effort they demand.

Compliance and evidence

A documentary basis against recognised frameworks for audits, clients and insurers.

A justified investment

An argument with figures to defend the security budget before leadership.

A point of comparison

A baseline that allows measuring progress the following year on the same criteria.

The SUMāTO approach

Why this assessment and not a scan.

The difference is not in the tools: it is in translating technical findings into decisions leadership can take and fund.

01

Evaluation, not scan

Exposure is measured across controls, processes, governance and culture. A tool on its own sees none of the last three.

02

Recognised frameworks

The comparison is against industry standards, not against the opinion of whichever consultant shows up.

03

Risk in business language

Each finding with probability, impact and the consequence of not acting, in terms leadership understands.

04

Vendor independence

The remediation plan is not shaped by what would suit us to sell afterwards.

05

No interruption to operations

Interviews and document review. No intrusive action on production systems.

06

Continuity into operation

If you decide to delegate execution, the plan connects with SOC and Managed Services without starting the survey again.

The conclusion

As-Is, To-Be and the plan to get from one to the other.

Every assessment closes with the same structure, whatever the practice: where you stand today, where you need to be, what separates the two states and in what order that distance gets closed.

01

Current state — As-Is

The starting point surveyed with evidence, not declared in an interview: which controls exist, how they operate and how far they sit from what the business needs.

02

Target state — To-Be

The level of protection the organisation needs to reach, defined with the business areas rather than imposed by the consultant. It is the benchmark everything else is measured against.

03

Gap analysis

Every difference between the As-Is and the To-Be, with everything required to close it: technology, processes, people, governance and budget. No gap is stated without what it demands.

04

Risk matrix

Each gap rated by probability and business impact, so priority does not depend on who pushes hardest but on what it costs to leave it open.

05

Work plan

The concrete sequence to reach the To-Be: what gets remediated first, what it depends on, how much effort it takes and who should answer for each front.

06

Business alignment

The plan is presented and agreed with the areas involved. A roadmap signed only by IT does not survive the first quarter.

The report

How what you receive is structured.

The central deliverable is a report with a fixed structure, designed so leadership reads the first pages and the technical team works with the rest.

01

Executive summary

Two pages: overall posture, the three risks that weigh most and what decision each one calls for.

02

Maturity by domain

Rating of the eight domains, with the gap made explicit against NIST, ISO 27001 and CIS.

03

Findings with evidence

Each finding with what was observed, where it was observed and why it matters. No claims without backing.

04

Risk map

Probability and impact per finding, ordered by business risk rather than technical severity.

05

Remediation plan

Actions prioritised by exposure removed against effort, with a suggested owner and horizon.

06

Immediate actions

What can be corrected without a project or additional budget, separated from the rest so you can start now.

Deliverables

What you receive at the end.

  • Current state (As-Is): security posture with a maturity level for each of the eight domains, evaluated against recognised industry frameworks.
  • Inventory of vulnerabilities and control gaps, with supporting evidence.
  • Target state (To-Be): the level of protection the business requires per domain, agreed with the areas.
  • Gap analysis between the As-Is and the To-Be, with each gap, its evidence and everything required to close it: technology, processes, people, governance and budget.
  • Risk matrix: each gap rated by probability and business impact, to support investment decisions.
  • Work plan to reach the To-Be: remediation prioritised by exposure reduction against effort, with a suggested owner and horizon.
  • Immediate-impact actions, executable without a project or additional budget.
  • Architecture and control recommendations for the medium term.
  • Executive presentation for committee and leadership.
  • Alignment session with the business areas involved.
Frequently asked questions

About the Cybersecurity Assessment.

What exactly do you evaluate?+
Eight domains: governance and policy, identity and access, the workplace, network and perimeter, cloud, data protection, detection and response, and third parties. Each is rated by maturity level against recognised frameworks. It is an exposure evaluation, not just a technical scan.
How does it differ from cybersecurity consulting?+
The assessment does the first information-gathering exercise, builds the roadmap and aligns it with the business areas. It does not modify configurations and does not implement tools. The Cybersecurity practice is the one that executes that roadmap: it designs, implements, configures and sustains the controls, with continuous operation via SOC and Managed Services.
Is it the same as a pentest?+
No. A pentest tests the exploitability of specific vulnerabilities; the assessment evaluates the maturity and exposure of your whole posture and delivers a prioritised remediation plan. They complement each other: the assessment usually indicates where a pentest is worth doing afterwards.
Does it interrupt our operation?+
No. It rests on interviews, configuration review and documentation, with no intrusive action on your production systems.
Who should take part on our side?+
IT and security leads, and the business areas that depend on the systems evaluated. It is the business's participation that allows a technical finding to be translated into real impact.
Do you quantify the risk?+
Yes. We classify each finding by probability and impact so the investment focuses where it most reduces exposure, and so the budget can be defended with figures.
Is it useful for compliance and insurers?+
Yes. It produces evidence useful for audits, regulatory requirements, client questionnaires and cyber insurance policies.
How often should we repeat it?+
Annually at minimum. The attack surface changes with every new system, integration and supplier, and several frameworks require periodic reviews. Repeating it on the same criteria allows measuring progress.
Going deeper

Security, in depth.

The first step

Know your exposure before an attacker does.

Book your Cybersecurity Assessment and get a prioritised risk map, quantified in business terms, with a remediation plan actionable from the first week. If you would rather start with a short conversation to see whether it applies to your case, that works too.

Book my assessment See the Cybersecurity practice