Cybersecurity

Risk analysis and recommendations

Not every company needs the same level of protection. We work out what can realistically go wrong in your business, where the weakest points are, and what is worth securing first.

Starting with the risk, not the shopping list

The usual way security spending happens is that something alarming appears in the news or in a vendor pitch, and a product gets bought. The product is often fine. The problem is that nobody checked whether the risk it addresses is anywhere near the top of your list.

Meanwhile the actual exposure sits somewhere less interesting. An accounting system on a machine that has not been updated in two years. Ten people sharing one administrator password. A supplier with permanent access to your environment that nobody has reviewed since the integration was built.

A risk analysis puts those things in one place and in order. It is not a comfortable document to read, and it is considerably cheaper than finding out empirically.

Your risks are specific to you

There is no standard threat profile, because businesses do not have standard consequences.

An online shop loses money by the hour when it is down, so availability dominates. A law firm might survive a day of downtime without much harm but would be seriously damaged by a leak of client documents, so confidentiality dominates. A manufacturer with production systems on the network has a physical safety dimension the other two do not. A company that processes personal data at scale carries a legal exposure that changes the calculation again.

So we start with the business, not with the network. What you sell, what stops if something breaks, which data would hurt most if it appeared publicly, and which obligations you carry towards your customers. The technical inventory comes after, because it is only interpretable once you know what matters.

Along the way this typically surfaces things nobody had written down. Which systems the invoicing process actually depends on. That one spreadsheet that half of operations is built around, sitting on a laptop.

Realistic scenarios, not mythical hackers

We do not find it useful to talk about sophisticated adversaries targeting your company specifically. For most businesses that is not the threat, and the framing makes people either frightened or dismissive, neither of which produces good decisions.

The scenarios that actually deserve modelling are ordinary. An employee opens an attachment and ransomware encrypts the file server. A mailbox is compromised and used to send a payment-detail change to your customers. A laptop is stolen from a car with the disk unencrypted. A supplier is breached and their access to your systems is used. A database is deleted by mistake during a routine change and the backup turns out to be incomplete.

For each one, the useful exercise is walking through the hours after it happens. Who notices, and how long does that take. What stops working. What it costs per day. Which existing safeguard would hold and which would turn out to be theoretical. That walkthrough is usually where the priority list writes itself, because the gaps become obvious in a way that no severity score conveys.

Prioritising honestly

Two things determine the order: how much risk an action removes, and what it costs in money and disruption.

That ratio produces some unglamorous winners. Testing that your backups restore. Removing accounts belonging to people who left. Turning on multi-factor authentication for email and admin consoles. Patching the internet-facing systems. None of it is interesting, all of it is cheap, and together it eliminates most of the realistic scenarios.

The expensive items go further down, and some of them should stay undone. A company of thirty people does not need a round-the-clock security operations centre. Saying so is part of the job. We would rather you spend the budget on the three things that move your risk than on a programme that looks thorough and leaves the file server unpatched.

You will also see recommendations we expect you to decline. That is fine, as long as the decision is deliberate. An accepted risk that someone chose knowingly is a normal part of running a business. An accepted risk nobody knew about is the problem.

What you can do with the result

The output is meant to be usable by more than one audience. A prioritised list your technical team can start executing next week. A summary the person holding the budget can read and understand without a translator. And an honest statement of what you are exposed to at the current level of protection.

That last part matters more than it sounds. Most companies cannot describe their own exposure in a sentence, which makes every security conversation a negotiation between vague anxiety and vague reassurance. Replacing that with a specific list is the point of the exercise.

What you get

Map of sensitive data and processes

A written inventory of what data you hold, where it lives, who can reach it, and which processes stop working if a given system is unavailable.

Realistic threat scenarios

Concrete situations for your business rather than generic warnings: an encrypted file server, a compromised mailbox used for invoice fraud, a departing employee with active access.

Weak point assessment

Where the current setup would give way first, based on what we find rather than on a standard checklist that ignores how you actually work.

Prioritised action list

Recommendations ordered by risk reduced per unit of effort, so the first three items are the ones worth doing this month.

Cost and effort estimates

Each recommendation with an indication of what it takes to implement, so you can weigh it against everything else competing for the same budget.

Recommendations in plain language

Written to be read by whoever signs off the budget, not only by an administrator. If a recommendation cannot be explained in a sentence, it is not ready.

How we work

  1. 01

    Understand the business first

    What you sell, what stops if a system goes down, which data would be most damaging to lose or leak, and what obligations you have towards customers and regulators.

  2. 02

    Inventory the environment

    Systems, data, accounts, suppliers and integrations. You cannot assess risk against an environment nobody has fully described, and that description rarely exists at the start.

  3. 03

    Build the scenarios

    For each realistic failure or attack, what happens hour by hour, what it costs, and which existing safeguards would actually hold.

  4. 04

    Rank and recommend

    Scenarios ranked by likelihood and impact, then matched to actions ranked by cost and effect. The output is an ordered list, not a catalogue of everything possible.

  5. 05

    Review the plan together

    We walk through the findings with you, argue about the priorities where it is useful, and agree what happens in the next quarter and what waits.

Tools and technology

Where a solid open-source tool exists, we choose it over a closed one. No lock-in to a single vendor, and costs you can actually predict.

  • Nmap
  • OpenVAS
  • Nuclei
  • Semgrep
  • Trivy
  • Lynis
  • Wazuh
  • MITRE ATT&CK
  • CIS Benchmarks
  • OWASP Top 10
  • Nessus
  • Microsoft Entra ID

Frequently asked questions

More services in this category

Read testimonials from companies that trusted us

They're always a few steps ahead.

Mikołaj

CEO & Founder, GBS®

View on Clutch
GBS® logo

Delivered well ahead of the deadline.

Yasniel

CEO, IMEGA Sp z o.o.

View on Clutch

ZanReal's individual approach is impressive.

Adam

Executive, w-studio.pl

View on Clutch

Knowledge and business intuition make them a valuable partner.

Magda

Designer, DIGITALUNI

View on Clutch

Quick solutions that reduced costs by 99%.

Andrei Kapytau

Team Lead, busel.uk

View on Clutch

+20% deliverability for our email campaigns.

Joan Calabria

Sales Director, 36NORTH

View on Clutch
36NORTH logo

Not sure what is worth securing first?

Message us

Tell us how your business runs and which systems it depends on. We will map the realistic risks and give you an ordered list of what to fix first.

Zanek

Can't keep up with changes in AI world?

Let us do the heavy lifting. Every week we distill the most important AI developments into a focused 5-minute briefing — so you stay ahead without the noise.

Find out more
Weekly AIonline