Risk analysis and recommendations
Not every company needs the same level of protection. We work out what can realistically go wrong in your business, where the weakest points are, and what is worth securing first.
Starting with the risk, not the shopping list
The usual way security spending happens is that something alarming appears in the news or in a vendor pitch, and a product gets bought. The product is often fine. The problem is that nobody checked whether the risk it addresses is anywhere near the top of your list.
Meanwhile the actual exposure sits somewhere less interesting. An accounting system on a machine that has not been updated in two years. Ten people sharing one administrator password. A supplier with permanent access to your environment that nobody has reviewed since the integration was built.
A risk analysis puts those things in one place and in order. It is not a comfortable document to read, and it is considerably cheaper than finding out empirically.
Your risks are specific to you
There is no standard threat profile, because businesses do not have standard consequences.
An online shop loses money by the hour when it is down, so availability dominates. A law firm might survive a day of downtime without much harm but would be seriously damaged by a leak of client documents, so confidentiality dominates. A manufacturer with production systems on the network has a physical safety dimension the other two do not. A company that processes personal data at scale carries a legal exposure that changes the calculation again.
So we start with the business, not with the network. What you sell, what stops if something breaks, which data would hurt most if it appeared publicly, and which obligations you carry towards your customers. The technical inventory comes after, because it is only interpretable once you know what matters.
Along the way this typically surfaces things nobody had written down. Which systems the invoicing process actually depends on. That one spreadsheet that half of operations is built around, sitting on a laptop.
Realistic scenarios, not mythical hackers
We do not find it useful to talk about sophisticated adversaries targeting your company specifically. For most businesses that is not the threat, and the framing makes people either frightened or dismissive, neither of which produces good decisions.
The scenarios that actually deserve modelling are ordinary. An employee opens an attachment and ransomware encrypts the file server. A mailbox is compromised and used to send a payment-detail change to your customers. A laptop is stolen from a car with the disk unencrypted. A supplier is breached and their access to your systems is used. A database is deleted by mistake during a routine change and the backup turns out to be incomplete.
For each one, the useful exercise is walking through the hours after it happens. Who notices, and how long does that take. What stops working. What it costs per day. Which existing safeguard would hold and which would turn out to be theoretical. That walkthrough is usually where the priority list writes itself, because the gaps become obvious in a way that no severity score conveys.
Prioritising honestly
Two things determine the order: how much risk an action removes, and what it costs in money and disruption.
That ratio produces some unglamorous winners. Testing that your backups restore. Removing accounts belonging to people who left. Turning on multi-factor authentication for email and admin consoles. Patching the internet-facing systems. None of it is interesting, all of it is cheap, and together it eliminates most of the realistic scenarios.
The expensive items go further down, and some of them should stay undone. A company of thirty people does not need a round-the-clock security operations centre. Saying so is part of the job. We would rather you spend the budget on the three things that move your risk than on a programme that looks thorough and leaves the file server unpatched.
You will also see recommendations we expect you to decline. That is fine, as long as the decision is deliberate. An accepted risk that someone chose knowingly is a normal part of running a business. An accepted risk nobody knew about is the problem.
What you can do with the result
The output is meant to be usable by more than one audience. A prioritised list your technical team can start executing next week. A summary the person holding the budget can read and understand without a translator. And an honest statement of what you are exposed to at the current level of protection.
That last part matters more than it sounds. Most companies cannot describe their own exposure in a sentence, which makes every security conversation a negotiation between vague anxiety and vague reassurance. Replacing that with a specific list is the point of the exercise.
What you get
Map of sensitive data and processes
A written inventory of what data you hold, where it lives, who can reach it, and which processes stop working if a given system is unavailable.
Realistic threat scenarios
Concrete situations for your business rather than generic warnings: an encrypted file server, a compromised mailbox used for invoice fraud, a departing employee with active access.
Weak point assessment
Where the current setup would give way first, based on what we find rather than on a standard checklist that ignores how you actually work.
Prioritised action list
Recommendations ordered by risk reduced per unit of effort, so the first three items are the ones worth doing this month.
Cost and effort estimates
Each recommendation with an indication of what it takes to implement, so you can weigh it against everything else competing for the same budget.
Recommendations in plain language
Written to be read by whoever signs off the budget, not only by an administrator. If a recommendation cannot be explained in a sentence, it is not ready.
How we work
- 01
Understand the business first
What you sell, what stops if a system goes down, which data would be most damaging to lose or leak, and what obligations you have towards customers and regulators.
- 02
Inventory the environment
Systems, data, accounts, suppliers and integrations. You cannot assess risk against an environment nobody has fully described, and that description rarely exists at the start.
- 03
Build the scenarios
For each realistic failure or attack, what happens hour by hour, what it costs, and which existing safeguards would actually hold.
- 04
Rank and recommend
Scenarios ranked by likelihood and impact, then matched to actions ranked by cost and effect. The output is an ordered list, not a catalogue of everything possible.
- 05
Review the plan together
We walk through the findings with you, argue about the priorities where it is useful, and agree what happens in the next quarter and what waits.
Tools and technology
Where a solid open-source tool exists, we choose it over a closed one. No lock-in to a single vendor, and costs you can actually predict.
- Nmap
- OpenVAS
- Nuclei
- Semgrep
- Trivy
- Lynis
- Wazuh
- MITRE ATT&CK
- CIS Benchmarks
- OWASP Top 10
- Nessus
- Microsoft Entra ID
Frequently asked questions
More services in this category
Application and system security
Business applications are a standing target. We find where the vulnerabilities are, tell you which ones matter, and fix them before someone else finds them first.
Network and infrastructure security
Most infrastructure is secured in theory. We make access match what people actually need, and split the environment so a problem in one place does not become a problem everywhere.
Backups and data recovery
A backup only counts if you can restore from it. We build backup systems that run automatically, survive an attack on the main environment, and get tested by actually restoring the data.
Read testimonials from companies that trusted us
Delivered well ahead of the deadline.
ZanReal's individual approach is impressive.
Knowledge and business intuition make them a valuable partner.
Quick solutions that reduced costs by 99%.
Not sure what is worth securing first?
Message usTell us how your business runs and which systems it depends on. We will map the realistic risks and give you an ordered list of what to fix first.
Can't keep up with changes in AI world?
Let us do the heavy lifting. Every week we distill the most important AI developments into a focused 5-minute briefing — so you stay ahead without the noise.
Find out more
