Blog / Reputation and business risk
Reputation and business risk
What a Cybersecurity Risk Assessment Actually Checks (and What a Free Scan Does Not)
What a cybersecurity risk assessment checks, what it costs for a company under 50 people, and why three free scans left a law firm unable to answer a client.
Three free scans and no answer
The managing partner of a 40-person law firm has been careful about security, or believed she has. Over four years, three different IT companies have offered a "free security scan," and she has accepted every one. Each produced a report. The first was 84 pages of red and yellow from a vulnerability scanner. The second was a dark-web check that found two partners' old passwords. The third was a two-page scorecard with a letter grade of B and a quote for a managed services contract.
In August a corporate client sends a request. Its outside-counsel guidelines now require every firm handling its matters to confirm, in writing, which security controls it has in place, mapped to a recognized framework, and to name the person responsible for each. The client's list has 22 items: asset inventory, MFA, backup testing, log retention, incident plan, vendor review, and so on.
She opens the three reports. None of them contains an inventory of the firm's systems. None mentions the incident plan, because there is not one. None says whether backups have ever been restored. The vulnerability report lists 340 findings and ranks none of them by what the firm would lose. The scorecard's B is not explained.
She has spent four years collecting documents that cannot answer a single one of the 22 questions. The IT company that produced the scorecard offers to run it again.
What the heck does this mean
A cybersecurity risk assessment is a structured look at what you have, what would hurt if you lost it, which safeguards are in place, which are missing, and in what order to fix them. It ends with a plan, priced and ranked, that a non-technical owner can approve.
A vulnerability scan is one tool inside that process. It lists known software flaws on the systems it can see. It does not know which system holds the client files, whether anyone would notice an intruder, or what a regulator will ask.
A gap assessment measures you against a specific framework or regulation, control by control. A penetration test hires someone to break in. Both are useful. Neither replaces the assessment that decides which one you need.
A "free scan" is a sales tool. The scanner is free because the report is designed to frighten you into a contract, and it ranks findings by what the tool found, not by what your business would lose.
The principle I have carried from bank examinations to a 40-person law firm: accurate insights first, then protection. You cannot prioritize what you have not measured, and a scanner does not measure a business. It measures ports.
The numbers that matter
Assessments for businesses under 50 staff commonly price between USD 5,000 and USD 15,000, with formal compliance audits starting from about USD 15,000 (industry price guides, 2026). Less than the retainer on one mid-sized matter, and it answers the client's 22 questions for every client that asks.
Opportunistic breaches at small businesses trace mainly to compromised credentials, 38%, and unpatched edge devices, 29% (Verizon 2026 DBIR SMB findings). Two things a good assessment checks on the first day, and neither of which a scorecard grade tells you about.
The median time to fully patch a vulnerability is 43 days (Verizon 2026 DBIR). A scan tells you a flaw exists. An assessment tells you whether anyone in your firm owns the job of fixing it inside those 43 days.
What to do this week
- Write the inventory before anyone scans anything: every server, laptop, phone, cloud service and vendor that touches client data, with an owner's name next to each. An assessment without this page is a scan with opinions. (CIS 1 Inventory and Control of Enterprise Assets)
- Take the client's 22 questions, or the framework you answer to, and for each one write "yes, and here is the evidence," "partly," or "no." That truthful column is the first draft of your assessment and it takes an afternoon. (CIS 17 Incident Response Management)
- Pull the last vulnerability report out of the drawer and ask one question of it: which of these findings sit on the firewall, the VPN or the document server? Fix those this month and ignore the rest until you have an owner and a schedule. (CIS 7 Continuous Vulnerability Management)
- Decide who owns patching and how often it happens, and write it down with a day of the week. The 43-day median is what happens when nobody is named. (CIS 7 Continuous Vulnerability Management)
- Draft the one-page incident plan with names and numbers, because it is the item most often missing from a small firm's answer and the cheapest one to add. (CIS 17 Incident Response Management)
- When you do commission an assessment, ask the assessor three things before you sign: will it include an inventory, will each finding be ranked by business impact and mapped to the rules I answer to, and will it end with a plan with costs. If any answer is no, you are buying a scan. (CIS 1 Inventory and Control of Enterprise Assets)
Where AccuSights fits
Our assessment is the one described above: inventory first, then each control tested against your regulators and your clients' requirements, then a plan with an order and a price next to every item, written so a managing partner can approve it without a translator. The Cyber Hygiene Test takes three minutes and gives you a true starting score. A 15-minute call with an engineer tells you if you need the full assessment yet, or just the first five fixes.
We map the assessment to your regulators, and our read-only compliance agent shows which controls are in place and which have drifted, so you prioritize the right things and keep an eye on them. Like a falcon, it sees the whole field and singles out the one thing worth acting on. We have no access and do not remediate; you or your IT partner fix, and we show you where.
Questions people ask
How long does a cybersecurity assessment take? For a business under 50 people, two to four weeks from kickoff to the written report, with perhaps six to ten hours of your team's time spread across interviews, a walk-through and access to a few consoles. The elapsed time is mostly the assessor reading configurations and logs rather than running tools. Anything delivered in an afternoon is a scan, not an assessment.
Is a penetration test the same as a risk assessment? No. A penetration test hires someone to break in and tells you how they did it, which is valuable once the basics are in place. A risk assessment inventories what you have, what would hurt if it were lost, which controls exist and which are missing, and ranks the gaps against the rules you answer to. Doing the pen test first is like hiring a burglar to test a house that has no locks yet: you already know the ending.
What do I get at the end of an assessment? A written report in plain language: an inventory of your systems and data, a list of gaps ranked by how likely and how costly each is, each gap mapped to the control that closes it and to the regulation or customer requirement that asks for it, and a remediation plan with an order and a cost. If the deliverable is a 100-page PDF of scanner output with no plan, you paid for a scan with a cover page.
The audit is not the exam, the attacker is; an assessment is how you find out what grade you would get before someone else sets the paper.
Questions people ask
How long does a cybersecurity assessment take?
For a business under 50 people, two to four weeks from kickoff to the written report, with perhaps six to ten hours of your team's time spread across interviews, a walk-through and access to a few consoles. The elapsed time is mostly the assessor reading configurations and logs rather than running tools. Anything delivered in an afternoon is a scan, not an assessment.
Is a penetration test the same as a risk assessment?
No. A penetration test hires someone to break in and tells you how they did it, which is valuable once the basics are in place. A risk assessment inventories what you have, what would hurt if it were lost, which controls exist and which are missing, and ranks the gaps against the rules you answer to. Doing the pen test first is like hiring a burglar to test a house that has no locks yet: you already know the ending.
What do I get at the end of an assessment?
A written report in plain language: an inventory of your systems and data, a list of gaps ranked by how likely and how costly each is, each gap mapped to the control that closes it and to the regulation or customer requirement that asks for it, and a remediation plan with an order and a cost. If the deliverable is a 100-page PDF of scanner output with no plan, you paid for a scan with a cover page.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
What a Breach Really Costs a 30-Person Business (It Is Not the USD 4.99 Million Headline)
The cost of a data breach, small business edition: not the USD 4.99 million headline but eleven days of lost closings, a bank that drops you, and payroll.
Practical controlsSecurity Awareness Training for a Small Business: Why the Report Button Beats the Delete Key
Security awareness training for small business that works: short, monthly, scored per person and team, tied to real threats, judged by who reports.
Practical controlsThe One-Page Incident Response Plan a 25-Person Company Can Actually Follow
An incident response plan for a small business on one page: who calls whom in the first hour, the regulator clocks, and what to do when your IT provider is hit.
