Consulting
Cyber Risk Assessment for UK SMEs
The standard answer when we ask a new client what would happen if ransomware hit tomorrow is silence, then "our IT company would deal with it." The IT company's plan is usually to restore from backup. The backup has not been tested in eighteen months and covers the file server but not the cloud accounts.
This assessment finds those problems before they cost real money. Six areas, structured findings, a list of what to fix first. No 200-page report.
This Service Is For You If
- ✓ A customer or partner has sent you a security questionnaire you are not sure how to answer
- ✓ You want to know whether your business is actually secure, not just whether you have antivirus
- ✓ You have had an incident or near-miss and want to understand your exposure properly
- ✓ You are preparing for Cyber Essentials or ISO 27001 and need a clear starting point
The Reality for Most Small Businesses
Weak Access Control
Shared logins, no MFA on email, ex-employees with active accounts, admin rights handed out too freely.
Unmanaged Devices
Staff using personal laptops, no endpoint management, out-of-date software nobody is tracking.
No Incident Plan
No written plan for what happens when something goes wrong. Nobody knows who calls who or how to contain it.
Third-Party Blindspots
Suppliers, contractors and partners with access to systems or data, and no process for managing that risk.
What the Assessment Covers
Six areas, structured around how businesses actually run rather than how framework documents are written.
Governance & Risk Management
Who owns security in your business? What policies exist? How is risk tracked and communicated? Most SMEs have no clear answers. We document what is actually in place and what is missing.
Output: clear view of your governance baseline and the gaps.
Assets & Exposure
What systems, data and third-party connections does your business actually have? Most businesses are surprised by how much is out there: cloud services, legacy software, supplier access points they forgot about.
Output: an asset and exposure summary covering your key risk surface.
People, Access & Configuration
We review how accounts are managed, how devices are controlled, how software is kept updated, and whether your configurations follow basic security practice. This is where most attacks are stopped or let through.
Output: access and configuration findings with prioritised fixes.
Detection, Response & Recovery
What happens when something goes wrong? Do you have monitoring? An incident plan? A tested backup? This is where most SMEs are most exposed and where the real business damage happens.
Output: response and recovery gap assessment with practical recommendations.
Supply Chain & Third-Party Risk
Suppliers, contractors and cloud services are a major attack vector. We look at who has access to your systems and data, what controls exist on that access, and where the exposure sits.
Output: third-party risk summary and recommendations.
Risk Register & Prioritised Actions
We pull the findings together into a risk register and an action list ranked by likelihood, impact and effort to fix. Something you can hand to a board, an IT provider, or a customer.
Output: working risk register and actionable remediation plan.
Typical Deliverables
- ✓ Cyber risk assessment report
- ✓ Risk register (likelihood, impact, priority)
- ✓ Prioritised action plan with owners
- ✓ Asset and exposure summary
- ✓ Policy and control gap list
- ✓ Plain-language executive summary
Assessments follow NIST CSF 2.0 and the Cyber Essentials control areas as their backbone, so your findings carry weight with customers and auditors without you having to quote acronyms at them.
If a customer is specifically asking for framework alignment rather than a general risk review, see our NIST CSF consulting page.
Pricing
Snapshot Assessment
£695 + VAT
Standalone Review
A review of your security posture across the key risk areas, with a summary and a list of what to fix first. No ongoing commitment.
- ✓ 60-90 minute discovery session
- ✓ Six-area structured assessment
- ✓ Risk summary with RAG ratings
- ✓ Prioritised action list
- ✓ Follow-up recommendations email
Full Risk Assessment
£1,800 + VAT
Most Practical
In-depth assessment covering people, process and technology. Includes a working risk register, full remediation roadmap and policy gap review.
- ✓ Everything in Snapshot Assessment
- ✓ Full risk register
- ✓ Remediation roadmap
- ✓ Policy and evidence gap review
- ✓ Plain-language executive summary
Assessment & Support
£3,500 + VAT
Hands-On
Full assessment plus ongoing support as you close the gaps: working sessions, policy documentation, and reporting you can share with customers or a board.
- ✓ Everything in Full Risk Assessment
- ✓ Up to 4 working sessions
- ✓ Policy drafting support
- ✓ Stakeholder-ready reporting
- ✓ Priority turnaround 4-6 weeks
Also Preparing for Cyber Essentials?
A cyber risk assessment and Cyber Essentials readiness work well together.
A risk assessment covers the wider picture of your security posture. Cyber Essentials focuses specifically on the five technical control areas assessed during certification. Many clients do both: the risk assessment finds the broader issues, and the Cyber Essentials readiness work gets them ready for the specific question set.
If you have a contract requirement for Cyber Essentials, we can scope both services together. Get in touch to discuss your situation.
Why Work With Us
SydSec is a small specialist consultancy focused on practical security for UK SMEs. We use NIST CSF 2.0 and Cyber Essentials as the backbone of our assessments because they are credible frameworks that produce findings worth acting on, not shelf-ware.
Our background includes enterprise networking, military logistics and transport operations, which means we think about security from an operational angle rather than a purely technical one.
- ✓ CCNA Security
- ✓ CCNA Enterprise Networking & Automation
- ✓ Cisco DevNet Associate
- ✓ BSc Cyber Security (Open University)
- ✓ Credly verified badges
Find Out Where You Stand
Start with a free 20-minute call. No jargon, no hard sell. Just an honest conversation about your business and what makes sense to do first.
Book a Discovery Call General Enquiry