One-off security assessment

AI Security Baseline: know what to fix first

A practical cybersecurity baseline covering people, email, website, access, backups, and incident readiness.

Request a Security Baseline

In short

The AI Security Baseline gives management a verified starting point and a 30, 60, and 90-day action plan. It combines an interview, passive external checks, policy review, and specialist validation without pretending to be a full penetration test.

When this helps

Useful when security is important but fragmented

  • Nobody can explain the current risks in one overview.
  • MFA, access, backups, and policies differ between teams.
  • Customers ask security questions that take days to answer.
  • Technical warnings exist, but priorities and owners are unclear.

Deliverables

What you receive

  • Management summary and transparent score by category
  • Evidence register with critical, high, medium, and low findings
  • 30, 60, and 90-day improvement roadmap
  • Technical action list for internal IT or your MSP
  • Review call with management and the responsible technical owner

Approach

From intake to a defensible action plan

01

Understand

We map systems, responsibilities, access, employee practices, backups, and incident readiness.

02

Verify

We perform passive domain, email, website, and configuration checks and review available evidence.

03

Prioritize

Findings are ranked by exposure, business impact, effort, and dependencies.

04

Transfer

Management and IT receive separate, usable views of the same roadmap.

Clear boundary

What this assessment is not

The Baseline is not an automated penetration test, a legal compliance certificate, or 24/7 monitoring. Active attack simulation requires a separate scope, explicit authorization, and specialist supervision.

Frequently asked questions

Does the assessment disrupt our systems?

The standard Baseline uses interviews, evidence, and passive checks. We do not launch intrusive tests against production systems as part of this service.

Is this enough for NIS2 compliance?

No single scan proves compliance. The Baseline helps identify gaps and organize evidence, responsibilities, and improvements that may support a broader compliance programme.

Can our IT provider execute the roadmap?

Yes. The technical action list is written so your internal IT team or existing MSP can implement it. We can also support selected improvements.

Turn the first security question into an owned next step

We will scope the assessment, required access, evidence, review, and expected output before any checks start.

Request a Security Baseline