Fixed-scope security review

Know exactly where your security stands, and what to fix first.

A structured review of your current exposure, identity controls, endpoint coverage and response readiness, turned into a clear, prioritised action plan you can actually act on.

Fixed scope Senior-led Plain-English findings Delivered in weeks
What this review is

A clear picture of your security, before you commit to changes.

Most organisations do not lack security tools. They lack a clear, current view of where the real risks sit and which ones matter most.

Not a sales audit dressed up as advice. This review is designed to give leadership a practical security picture before budget, tools or remediation work are decided.

The Security Posture and Risk Review gives you that picture. We examine your existing environment across identity and access, devices and endpoints, email and data, cloud configuration and response readiness.

The aim is to identify where exposure is highest, what is already well managed, and what deserves attention first.

It is an independent, senior-led assessment that turns technical findings into business decisions, not a generic checklist or unreadable report.

Cloud is examined here as one part of the organisation’s wider security posture. A fixed-scope look at the cloud estate itself, covering spend, licensing, recovery readiness and day-to-day control, is a separate engagement: the Cloud Health Check.

ID

Identity and access

MFA, admin accounts, permissions, leavers, guests and access lifecycle.

DV

Devices and endpoints

Coverage, patching, encryption, endpoint protection and device visibility.

EM

Email and data exposure

Phishing controls, account protection, shared data and external exposure.

IR

Response readiness

Escalation, evidence, recovery steps and practical incident ownership.

Who it is for

Built for organisations that have outgrown informal security.

This is for teams that need clarity before a renewal, insurance review, client questionnaire, Cyber Essentials preparation or wider security investment.

01

You have grown quickly

More users, devices and tools have accumulated, and no one has a clear, current view of the whole picture.

02

A renewal or audit is coming

Insurance, a client security questionnaire, or Cyber Essentials readiness means you need to know where you stand before someone else checks.

03

You suspect gaps but cannot see them

Things mostly work, but you are not confident security decisions are being owned, reviewed or evidenced properly.

What usually prompts it

Most reviews start because someone outside the business asked a question.

You do not need an incident to justify a review. The trigger is usually a renewal, a questionnaire or a decision that needs evidence behind it. What you get back is prioritised understanding you can draw on when you respond — a SoftExponent review, not an insurer’s, a client’s or a certification body’s attestation.

IN

A cyber insurance renewal

Your insurer wants to know how identity, endpoint and recovery controls are actually handled before they quote.

CQ

A client security questionnaire

A customer has sent a security questionnaire and the answers need to be accurate, consistent and defensible.

SV

Supplier or vendor scrutiny

You are being assessed as a supplier, or an assessment has come back with questions you cannot yet answer.

BD

Leadership has asked for a clearer picture

The board or senior team wants a view of security risk that does not require a technical background to follow.

SP

A spend or remediation decision

Budget is available and you want to know what genuinely deserves it before committing to tools or a project.

Review process

How the review works.

The review is designed to be structured, low-disruption and useful. The goal is not to create noise, but to show what needs attention and why.

01

Map the environment

We review your identity, devices, email, cloud and access setup. You get a clear picture of the controls already in place, without disrupting day-to-day work.

02

Assess and prioritise

We identify exposure, weak controls and gaps. You get a prioritised view based on real business risk, not a generic checklist.

03

Deliver the posture snapshot

You receive a clear action plan showing what to fix first, who owns each risk and the practical next steps.

What you receive

A Security Posture Snapshot, not a 40-page report no one reads.

The review produces a clear deliverable that turns technical findings into decisions: exposure ranked by priority, controls reviewed in plain language, and a practical action plan with owners and next steps.

Sample review output

Security Posture Snapshot

Review type Fixed scope Status Executive ready Focus Exposure and action
Posture indicators Risk view
Identity posture 78%
Endpoint coverage 91%
Response readiness 72%
Open priorities 5 items
Priority risks Action
High
Inactive accounts still enabled Review leavers, shared mailboxes and unused access.
Identity review
First priority
Medium
Phishing controls need tightening Strengthen user guidance and email protection rules.
Email controls
Next cycle
High
Response steps not documented Create escalation, evidence and recovery guidance.
Incident plan
First priority
Senior review note Decision view
Security review

Focus next on access hygiene, phishing resilience and response documentation before adding more security tooling.

Exposure view Prioritised

Security risks grouped by business impact, not just technical severity.

Identity focus Actionable

User access, MFA, permissions and account lifecycle reviewed clearly.

Action plan Next steps
01 Confirm MFA and inactive account review Priority
02 Improve phishing readiness and user reporting Next
03 Document incident escalation and evidence steps Next
04 Review backup recovery evidence Planned
Scope boundaries

What this review is not.

Being precise about the boundaries makes the review more useful, not less. If what you actually need is one of the things below, we will say so and point you to the right route.

PT

Not a penetration test

We do not attempt to exploit systems. The review examines how controls are configured, owned and managed, not whether they can be broken into.

VA

Not a vulnerability assessment

There is no automated scanning of hosts or applications for known vulnerabilities, and no CVE inventory at the end of it.

AA

Not an accredited or certification audit

SoftExponent is not a certification body, and this review is not an audit carried out under an accreditation scheme.

CE

Not a Cyber Essentials assessment

Cyber Essentials is assessed by a licensed Certification Body. We help you prepare; we do not assess or certify.

GC

Not a guarantee of certification or compliance

Acting on the findings should leave you in a stronger position, but no review can guarantee a certification result or a compliance outcome.

RW

Not the remediation work itself

The review tells you what to fix and in what order. Carrying it out is separate, and you are free to do it internally or with another provider.

Scope and pricing

Fixed scope. Clear price. No open-ended engagement.

The Security Posture and Risk Review is designed to give you a clear starting point without committing to a large project before you know what matters.

Fixed-scope engagement
£1,250 starting from

Suitable for most organisations up to around 50 users. Larger or more complex environments are scoped after a short conversation.

We examine identity, access, endpoint, email, cloud and response readiness across the current environment.

You receive a Security Posture Snapshot with priority risks, senior review notes and practical next steps.

The walkthrough translates findings into plain English so leadership can see what to fix first and why.

i

Third-party licences, deeper assurance and remediation work are quoted separately where needed.

Buyer questions

Questions buyers ask before a review.

The review is intended to be clear before it starts: what happens, what access is needed, and what you receive at the end.

Most reviews are completed within two to three weeks of starting, depending on the size of the environment and how quickly access and information can be provided.

It is usually suitable for organisations up to around 50 users, especially teams that have grown quickly or need a clearer view before Cyber Essentials readiness, insurance, renewal or security investment. Larger environments can still be reviewed after a short scoping conversation.

We will advise exactly what access is needed and the safest way to provide it. Nothing is changed or touched without your agreement.

No. The review runs alongside normal operations. Your team should not experience disruption during the assessment.

You decide. The action plan is yours to act on however you choose: internally, with SoftExponent, or with another provider. There is no obligation to continue.

No. The review looks at how your security is configured, owned and managed rather than attempting to exploit it. If a penetration test is genuinely what you need, we will say so, and one can be arranged separately through appropriate specialist capability.

No. Cyber Essentials is assessed by a licensed Certification Body, and SoftExponent does not assess or certify. The review will show you clearly where you stand against the kind of controls Cyber Essentials expects, which is why many organisations run one before starting. Our Cyber Essentials readiness support is the route for certification itself.

Yes, as your own evidence. The snapshot gives you an accurate, current picture of how your controls are managed, which makes those answers easier to give and easier to stand behind. It is a SoftExponent review, not an insurer’s, a client’s or a certification body’s attestation, and it should not be presented as one.

That is a common reason to run one. The review looks at the environment as it is today, not at who configured it, and the findings are written so they can be handed straight to your existing provider as a work list. There is no requirement to change supplier, and no obligation to use SoftExponent for the remediation.

Next step

Start with a clear view, not a guess.

Before you invest in tools or change suppliers, get an independent, senior-led picture of where your security actually stands and what to fix first.