Skip to main content

Assessment service

Cybersecurity & AI Risk Assessment

Get a structured view of your organisation's cybersecurity and AI-related risks, with prioritised findings and practical recommendations for what to address next.

Request an AssessmentFor UK small and medium-sized businesses

Why it is worth doing

Know where you stand, and what to do first

Most small and medium-sized businesses have a reasonable idea that something in their security posture needs attention, but no structured way to say what, how serious it is, or what order to deal with it in. Meanwhile AI tools are being adopted across the business faster than any policy covering them.

This assessment turns that uncertainty into a documented position. You get a risk score you can track over time, findings ranked by severity with the business impact of each explained in plain terms, and a prioritised set of recommendations — so the next decision is about which improvement to fund, not about where to begin.

It is also a document you can put in front of an insurer, a customer running a supplier security review, or a board that wants evidence the question has been taken seriously.

Coverage

What it reviews

Seven areas of cyber security and AI governance, plus an indication of Cyber Essentials readiness.

  • Identity & access
  • Devices & network
  • Email & phishing
  • Backup & recovery
  • Security governance
  • AI governance
  • Incident preparedness
  • Cyber Essentials readiness

Deliverables

What you receive

A report written to be read by a managing director, not only by an IT specialist.

  • Overall risk score and category breakdown
  • Findings ranked Critical, High, Medium and Low
  • Business impact explained for each finding
  • Practical remediation recommendations
  • AI governance assessment
  • Cyber Essentials readiness indicators
  • Prioritised 90-day action plan
  • Professional PDF report

No access required

What it does not require

The assessment is built so that taking part cannot expose you. It never connects to your systems, and there is nothing to install.

  • Passwords
  • System access
  • Software installation
  • Microsoft 365 credentials
  • Network scanning

Every result comes from the answers you give. Scoring is fixed and deterministic — the same answers always produce the same result — and no AI model is involved in producing any score or finding.

The engagement

How it works

A short, structured piece of work with a defined output.

  1. Request an assessment

    Get in touch and we confirm the scope for your organisation, what the assessment will cover, and what it will cost.

  2. Complete the assessment

    You work through the structured questions on our assessment platform, in plain English. If you do not know an answer, say so — that is recorded as unconfirmed, never as a failure.

  3. Receive your report

    A professional PDF containing your risk score, category breakdown, findings ranked by severity, practical recommendations and a prioritised 90-day action plan.

Assessments are scoped and quoted per organisation, because what is proportionate for a team of eight is not what is proportionate for a team of eighty. Get in touch and we will confirm scope and price before any work begins.

Important

What the assessment is not

Being clear about the limits is part of the value. The assessment gives you a well-organised view of your own answers — it does not verify them.

Disclaimer

This is a self-assessment based on the answers supplied. It is not a penetration test, technical audit, Cyber Essentials certification or guarantee of compliance.

The Cyber Essentials section is a preliminary readiness indicator based on questionnaire responses. It is not a Cyber Essentials certification, audit, guarantee of compliance, or guarantee of certification eligibility.

Ready to find out where you stand?

Tell us a little about your organisation and we will confirm scope, timing and cost.