Cybersecurity Assessment
One in three companies in the region has no way of knowing whether it has already been attacked. The problem is rarely a lack of tools: it is a lack of visibility. We evaluate your security posture —technical controls, processes, governance and culture— against NIST, ISO 27001 and CIS, and deliver a remediation plan prioritised by exposure reduction.
Investing in security without a diagnosis leads to buying tools that do not address the real risk. The assessment reveals your exposure across eight domains, translates it into business risk —probability and impact— and focuses the investment where it lowers exposure most per unit of effort. It is not a scan: it is a posture evaluation.
Know your exposure
Identify vulnerabilities and control gaps before an attacker exploits them.
Invest where it lowers risk
Focus the budget on what reduces exposure, not on isolated tools.
Comply and prove it
Produce the evidence regulators, clients and insurers ask for.
One surveys and maps the route. The other executes it.
These are two different services and it is worth knowing which one you need before contracting. The assessment does the first information-gathering exercise, builds the roadmap and aligns it with the business areas. The consulting practice executes that roadmap. Many organisations contract the first, execute internally what they can and delegate the rest.
Cybersecurity Assessment — this page
Surveys, maps and aligns. It does the first information-gathering exercise across the eight domains, measures maturity against recognised frameworks, quantifies the risk and builds the roadmap. It aligns that roadmap with the business areas, so the priorities are the business's and not only IT's. It runs two to four weeks. It does not modify configurations, does not deploy tools and does not operate anything.
Cybersecurity practice — implementation
Executes the roadmap. It takes the plan the assessment produced and puts it into practice: architecture design, implementation and configuration of controls, and ongoing support, with permanent operation through SOC and Managed Services. It works just as well if you already have a roadmap of your own.
Eight domains, evaluated one by one.
Exposure does not live in a single place. We review each domain with the same depth and rate it by maturity level, so the result can be compared against itself the following year.
Governance and policy
Governance structure, policies in force, roles and responsibilities, and how far they are followed in practice.
Identity and access
MFA, privilege management, account lifecycle and third-party access to the environment.
The workplace
Endpoint protection, encryption, patch management and device control.
Network and perimeter
Segmentation, traffic control, remote access and exposure of published services.
Cloud
Configuration of your Cloud environments, identities, public exposure and shared responsibility with the provider.
Data protection
Classification, encryption, backup and leak prevention for the information that sustains the business.
Detection and response
Monitoring, event logging, incident procedures and real recovery capability.
Third parties and supply chain
Suppliers with access, critical dependencies and what your contract demands on security.
Six phases, without touching your operation.
The assessment rests on interviews, configuration review and documentary evidence. There is no intrusive action on your production systems at any point.
Scope and preparation
We define the domains, systems and areas to cover, and agree the read-only access required.
Interviews
With IT, security and the business areas that depend on the systems evaluated.
Technical review
Configurations, policies and documentary evidence, checked against what the interviews said.
Gap analysis
Comparison against NIST CSF, ISO/IEC 27001 and CIS Controls, domain by domain, with the gap made explicit in each control.
Risk quantification
Each finding with probability and impact, prioritised by criticality to the business.
Business alignment
Presentation of findings and roadmap with leadership and the areas involved, so priorities are agreed rather than imposed by IT.
What your posture is measured against.
The evaluation does not rest on the judgement of whichever consultant shows up, nor on a vendor catalogue, but on public and auditable frameworks your team can consult and your auditor will recognise. Some define how maturity is rated; others are the technical guides against which what we find gets checked. And your posture is read against the data-protection regime that applies to you: Habeas Data (Ley 1581) in Colombia, the LFPDPPP in Mexico.
NIST Cybersecurity Framework
Evaluation framework. It organises posture into functions —identify, protect, detect, respond and recover— and lets each one be rated for maturity separately.
ISO/IEC 27001 and 27002
Evaluation framework. The information security management standard and its control catalogue. It is the structure auditors, clients and insurers expect to see documented.
CIS Controls
Evaluation framework. Controls prioritised by real effectiveness against the most frequent attack techniques. It is what orders the roadmap.
CIS Benchmarks
Technical guide. Secure configuration baselines per platform. They serve to check how what you already have is configured, not only whether the control exists.
MITRE ATT&CK
Technical guide. Catalogue of attack techniques observed in the real world. It allows reviewing whether your detection capability covers what is actually used against organisations like yours.
NIST SP 800-30
Risk guide. Risk assessment methodology. It is the basis of the probability-and-impact quantification that orders the findings.
The frameworks are public and verifiable: anyone on your team can consult them and check the rating we deliver. That is the difference between an auditable evaluation and an opinion.
What it costs to keep operating blind.
None of these risks shows up on day one. They all come due together on the day of the incident, when the cost of having known earlier can no longer be recovered.
Misdirected investment
Tools get bought that do not address the real risk, and the budget runs out without exposure coming down.
A surface nobody measures
Every new system, integration and supplier widens the exposure without anyone recalculating it.
More expensive incidents
With no procedures and no tested response capability, recovery time and cost multiply.
Compliance at risk
Auditors, clients and insurers ask for evidence that does not exist, and the answer gets improvised.
A budget without an argument
Security investment is defended with intuition instead of with quantified risk.
Third parties without control
Suppliers with access to the environment that were never evaluated and that nobody reviews periodically.
The gap is not in the tools: it is in not knowing.
Indicators for small and medium-sized companies in Latin America. Most come from the ESET Security Report 2025, a survey of more than 3,000 security professionals across more than 15 countries in the region. Each card cites its source. Updated August 2026.
have no way of knowing whether they were already attacked
They lack the tools to confirm whether they suffered an attack. The gap is not in defence: it is in visibility. Source: ESET Security Report 2025.
leave their security in untrained hands
Of Latin American SMEs delegate the protection of their digital assets to staff without the specialised training required. Source: Kaspersky, 2025.
do not use centralised anti-malware
Each device protects itself, with no console that allows seeing the whole or responding in a coordinated way. Source: ESET Security Report 2025.
protect corporate mobile devices
Only one in four. The rest have company email and files on devices outside any control. Source: ESET Security Report 2025.
suffered ransomware within two years
While 95% name it as their main concern, one in five has already lived through it. Source: ESET Security Report 2025.
hold cyber risk insurance
The rest absorb the full cost of an incident with no cover to cushion it. Source: ESET Security Report 2025.
The figures come from the reports cited and are reviewed once a year. If one stops being current, it is withdrawn: out-of-date data subtracts credibility rather than adding it.
What it costs you in time, said upfront.
An assessment that does not state the commitment it requires ends up delayed. This is what we need from your side to deliver on time.
Two to four weeks
Two weeks in organisations of up to 50 employees; four between 51 and 300. The timeline is agreed before starting.
Scheduled interviews
Sessions with IT, security and the business areas that depend on the systems evaluated, booked at the outset.
Read-only access
Queries against consoles and existing documentation. At no point is a configuration modified.
A single point of contact
One person coordinating schedules and access. It is the factor that most affects hitting the deadline.
Whatever documentation exists
Policies, inventories and diagrams, in whatever state they are in. Nothing needs preparing to start.
A closing session
The presentation of findings with leadership, where the plan's priorities are decided.
When it makes sense and when it does not.
It makes sense if…
Your organisation has between 10 and 300 employees with hybrid infrastructure; you have to answer audits, clients or insurers with evidence; you are about to set a security budget and need to back it; or you suspect you are investing in tools without knowing whether they address the real risk.
Probably not if…
You already have a mature programme and what you are looking for is execution: in that case go straight to the Cybersecurity practice. Or if you need to demonstrate the exploitability of a specific vulnerability: that is a pentest, and it is a different service.
What you gain from the assessment.
A real view of the risk
Your exposure evaluated across technical controls, processes, governance and culture, not just tools.
Risks prioritised by business
Vulnerabilities classified by probability and impact, not by isolated technical severity.
A focused remediation plan
Actions ordered by how much exposure they remove against the effort they demand.
Compliance and evidence
A documentary basis against recognised frameworks for audits, clients and insurers.
A justified investment
An argument with figures to defend the security budget before leadership.
A point of comparison
A baseline that allows measuring progress the following year on the same criteria.
Why this assessment and not a scan.
The difference is not in the tools: it is in translating technical findings into decisions leadership can take and fund.
Evaluation, not scan
Exposure is measured across controls, processes, governance and culture. A tool on its own sees none of the last three.
Recognised frameworks
The comparison is against industry standards, not against the opinion of whichever consultant shows up.
Risk in business language
Each finding with probability, impact and the consequence of not acting, in terms leadership understands.
Vendor independence
The remediation plan is not shaped by what would suit us to sell afterwards.
No interruption to operations
Interviews and document review. No intrusive action on production systems.
Continuity into operation
If you decide to delegate execution, the plan connects with SOC and Managed Services without starting the survey again.
As-Is, To-Be and the plan to get from one to the other.
Every assessment closes with the same structure, whatever the practice: where you stand today, where you need to be, what separates the two states and in what order that distance gets closed.
Current state — As-Is
The starting point surveyed with evidence, not declared in an interview: which controls exist, how they operate and how far they sit from what the business needs.
Target state — To-Be
The level of protection the organisation needs to reach, defined with the business areas rather than imposed by the consultant. It is the benchmark everything else is measured against.
Gap analysis
Every difference between the As-Is and the To-Be, with everything required to close it: technology, processes, people, governance and budget. No gap is stated without what it demands.
Risk matrix
Each gap rated by probability and business impact, so priority does not depend on who pushes hardest but on what it costs to leave it open.
Work plan
The concrete sequence to reach the To-Be: what gets remediated first, what it depends on, how much effort it takes and who should answer for each front.
Business alignment
The plan is presented and agreed with the areas involved. A roadmap signed only by IT does not survive the first quarter.
How what you receive is structured.
The central deliverable is a report with a fixed structure, designed so leadership reads the first pages and the technical team works with the rest.
Executive summary
Two pages: overall posture, the three risks that weigh most and what decision each one calls for.
Maturity by domain
Rating of the eight domains, with the gap made explicit against NIST, ISO 27001 and CIS.
Findings with evidence
Each finding with what was observed, where it was observed and why it matters. No claims without backing.
Risk map
Probability and impact per finding, ordered by business risk rather than technical severity.
Remediation plan
Actions prioritised by exposure removed against effort, with a suggested owner and horizon.
Immediate actions
What can be corrected without a project or additional budget, separated from the rest so you can start now.
What you receive at the end.
- Current state (As-Is): security posture with a maturity level for each of the eight domains, evaluated against recognised industry frameworks.
- Inventory of vulnerabilities and control gaps, with supporting evidence.
- Target state (To-Be): the level of protection the business requires per domain, agreed with the areas.
- Gap analysis between the As-Is and the To-Be, with each gap, its evidence and everything required to close it: technology, processes, people, governance and budget.
- Risk matrix: each gap rated by probability and business impact, to support investment decisions.
- Work plan to reach the To-Be: remediation prioritised by exposure reduction against effort, with a suggested owner and horizon.
- Immediate-impact actions, executable without a project or additional budget.
- Architecture and control recommendations for the medium term.
- Executive presentation for committee and leadership.
- Alignment session with the business areas involved.
About the Cybersecurity Assessment.
What exactly do you evaluate?+
How does it differ from cybersecurity consulting?+
Is it the same as a pentest?+
Does it interrupt our operation?+
Who should take part on our side?+
Do you quantify the risk?+
Is it useful for compliance and insurers?+
How often should we repeat it?+
Security, in depth.
- Zero Trust: the perimeter is now identity — the principle that orders a secure architecture today.
- AI risk and security — the gaps that AI adoption opens up.
- It forms part of our Cybersecurity practice.
Know your exposure before an attacker does.
Book your Cybersecurity Assessment and get a prioritised risk map, quantified in business terms, with a remediation plan actionable from the first week. If you would rather start with a short conversation to see whether it applies to your case, that works too.
Book my assessment → See the Cybersecurity practice →