At some point somebody asks the question. A major customer sends a security questionnaire, the insurer wants details before renewing the policy, or a new board member asks in the meeting: how secure are we, actually? And then the room goes quiet. IT knows its systems, the management team knows the budget, and in between sits a gap that nobody noticed until this question came up: no single place in the company holds the full picture.
A security assessment is the structured way to answer that question: a review of where you stand that management and IT can work with together, instead of gut feeling or an 80-page report.
A security assessment is a structured review of where you stand: what exists, what works, what is missing and what of it matters for your business. The result is a basis for decisions: the biggest risks, prioritised by business relevance, with a realistic effort estimate. In our experience the most surprising finding is often what is already there and not being used.
What is a security assessment, and what is it not?
A security assessment is a systematic comparison of your security position against a recognised benchmark, usually ISO 27001 or the NIST Cybersecurity Framework. It looks at more than technology: who is responsible, which processes exist, which tools are in use and which of them work. The result is a prioritised overview of the biggest risks.
Two mix-ups persist. An assessment is not a penetration test: a pentest checks whether an attacker gets through at one specific point, and says nothing about whether your backups can be restored or who decides in an emergency. And it is not a certification audit: there is no certificate, and no formalism either. An audit checks against a standard. An assessment asks what matters for your business.
The benchmark still matters. Without a frame of reference, a review of your position becomes a matter of the assessor's taste. Frameworks such as the NIST Cybersecurity Framework exist for exactly this reason: so the evaluation stays traceable and comparable the second time round.
What does a security assessment deliver in practice?
In short: a basis for decisions. A good security assessment delivers three things. A risk overview prioritised by business relevance rather than technical severity. A roadmap with realistic effort and a sequence. And a shared language in which IT and management can talk about security without talking past each other.
The third point is underrated. In many SMEs, security budgets do not come from an assessment of the situation but from occasions: an incident at a competitor, a persuasive sales meeting, an article that worries the board. Over the years, individual decisions pile up. Each one was defensible on its own. Together they rarely form a picture.
An assessment reverses the order: first the situation, then the money. After that, every security expense can be argued over like any other investment: which risk does it reduce, what does it cost, what would the alternative be. That sounds banal. In practice it is the difference between a budget the management team understands and stands behind, and one that has to be fought for again every year.
There is also an effect no report captures: trust. A board that has once seen an honest review of the situation, including the uncomfortable findings, believes the rest too. A management team that knows where the biggest risks sit no longer has to react to every headline. That saves nerves, and it saves the expensive panic purchases that tend to follow those headlines.
The most common outcome of an assessment is, by the way, not a shopping list. In our experience the review usually reveals a sizing problem: too many tools, too little overview, too much cost for too little real protection. More protection. Fewer tools. Lower cost. That is not a savings exercise; it is what happens when someone lays out the whole landscape side by side for the first time.
What this looks like in a real SME
An example, anonymised. A supplier with around 150 employees receives a security questionnaire from its biggest customer: a good 60 questions, four weeks to respond. IT is solidly set up, three people, day-to-day operations run fine. Even so, nobody can answer the questionnaire without guessing on half the questions.
The review then shows the usual pattern. Two endpoint products run in parallel, one left over from an old service-provider contract that nobody cancelled. Backups run daily, but nobody has ever rehearsed a restore. Admin rights have grown historically. And nobody is formally responsible for security as a task; it happens on the side.
What sits at the top of the roadmap is telling: almost nothing to buy. Clarify responsibility, test the restore, clean up access rights, cancel one of the two endpoint products. The questionnaire went back with honest answers and a plan instead of embellished ticks. In our experience, buyers do not want to see a flawless questionnaire. They want proof that someone knows the situation and leads.
The company bought not a single new security product afterwards. The cancelled licence funded part of the clean-up; the rest was working time and clarity about who owns what. This is what it looks like when the order is right: understand first, then decide, then invest.
When is a security assessment worth it?
Whenever a decision is coming up that needs a factual basis: before the budget round, before a customer audit or questionnaire, before an ISMS project, after strong growth or an acquisition. Or when a new head of IT or a new managing director wants to know what they have taken over.
The calendar is currently adding reasons. Since 1 April 2025, Switzerland's reporting obligation for cyberattacks on critical infrastructure has been in force, with reports due to the BACS (the Swiss federal cybersecurity office) within 24 hours. And by the end of 2026 the ISG, the Swiss Information Security Act, requires organisations within its scope to run a working ISMS, a deadline that reaches suppliers through customer contracts as well. We covered what that means in our article on the ISG ISMS obligation by the end of 2026. Anyone affected needs an honest starting position first. The standard comes after.
It is just as clear when an assessment is not worth it: when you have long known your gaps and what is missing is the execution. A second expert opinion on known problems is occupational therapy. And an assessment repeated every year without anything changing in between is an expensive ritual. The review is a starting point, not a permanent state.
From report to decision
The real product of an assessment is the meeting after delivery, in which the management team or the board decides something based on the findings. For that to work, it takes less than many expect: the three to five biggest risks, phrased in business language, with a proposal for what could be done about each, what it costs and what happens if you leave it.
Three things come out of that meeting: a decision per risk (accept it, reduce it or transfer it), an owner per measure and a date on which progress is reported. Nothing more. A 90-day horizon has proven itself, because it is short enough that nobody files the roadmap away, and long enough that something moves alongside the day-to-day business.
And this is also the most common way to waste an assessment: the report gets accepted, praised and filed. No owner, no date, no decision. Six months later the situation is the same, only the document is older. The review was then accurate, but for nothing.
How do you recognise a good assessment?
By the first question. A good assessment starts with the business: how do you earn money, which processes must not stand still, which data would be a problem in the wrong hands. Whoever starts with the firewall configuration instead is evaluating technology without context, and prioritisation becomes a matter of luck. Beyond that, four traits help:
- It prioritises instead of covering itself. A report in which everything is red protects the assessor, not you.
- It also names what can go. Whoever only finds gaps and never excess has not looked at the cost side. Our article on consolidating security tools shows how much often sits there.
- It has a fixed scope, a fixed price and a defined end. A review billed by effort has a built-in incentive never to finish.
- The result works without the provider. Your team can work with the roadmap even if nobody ever comes back.
And a warning from practice: free assessments from tool vendors end with astonishing reliability in the finding that precisely the vendor's product is missing. That is not an assessment, that is a sales meeting with a questionnaire. A review of your position should come from someone who earns nothing from whatever gets bought afterwards.
If you want to know how we set this up: our Cyber Assessment is a two-week sprint at a fixed price of CHF 1'900, with a gap analysis against ISO 27001 and NIST CSF, a risk register with the top 10 topics, a 90-day roadmap and an executive readout for the management team or the board. The amount is credited in full against a follow-up mandate. The details are in the package overview with prices.
Frequently asked questions
What is the difference between a security assessment and a penetration test?
A penetration test checks technically whether an attacker gets through at a defined point. A security assessment evaluates the whole position: organisation, responsibilities, processes and technology. The sensible order is usually assessment first, pentest afterwards, targeted at the places where it answers an open question.
How long does a security assessment take in an SME?
In a company with 50 to 500 employees, a usable review takes weeks rather than months. Our format is a two-week sprint. If it takes much longer, the work is usually digging too deep into technology and prioritising too little.
Do we need to prepare for a security assessment?
No. A review works with what is there. Missing documentation is a finding, not an entry requirement. What helps: making the right people available for a few well-prepared conversations, meaning IT, the management team and, depending on the topic, HR or production.
