Skip to content

Security Assessment

We offer our clients a range of cybersecurity services, including security testing, security assessment, and security development. With our services, you can ensure the cybersecurity of your organization and continue growing in the digital world.

Technical assessments

Microsoft 365 Security Assessment

A review of your Microsoft 365 environment's settings against the CIS Benchmark Level 1 and Level 2 checkpoints.

Starting from €3,000 (excl. VAT)Duration: about 2 weeks
Show details

What's included:

  • Kick-off meeting (1 hour): scoping and agreeing on the required read access
  • Review of settings against CIS checkpoints at both Level 1 and Level 2
  • A report where every finding is classified by severity and includes a remediation recommendation
  • A result matrix showing the status of each checkpoint and the rationale for any deviations
  • Final meeting (1 hour): review of findings and prioritization of fixes

Duration:

  • The engagement takes about 2 weeks from the kick-off meeting to the final meeting.

What we need from you:

  • Read access to the environment being assessed (Global Reader and Security Reader roles are sufficient)
  • A point of contact familiar with the environment who can answer follow-up questions

Benefits:

  • You'll know where your environment's settings deviate from the CIS guidance and what those deviations mean
  • A clear report and result matrix for follow-up actions

AWS security assessment

A review of your AWS environment's settings against the CIS AWS Foundations Benchmark and AWS best practices.

Starting from €3,000 (excl. VAT)Duration: about 2 weeks
Show details

What's included:

  • Kick-off meeting (1 hour): scoping and agreeing on the required read access
  • Review of settings against the CIS AWS Foundations Benchmark at both Level 1 and Level 2
  • A report where findings are classified by severity and include a remediation recommendation
  • A result matrix showing the status of each checkpoint and the rationale for any deviations
  • Final meeting (1 hour): review of findings and prioritization of fixes

Duration:

  • The engagement takes about 2 weeks from the kick-off meeting to the final meeting.

What we need from you:

  • Read access to the AWS environment being assessed (e.g. the SecurityAudit policy is sufficient)
  • A point of contact familiar with the environment who can answer follow-up questions

Benefits:

  • Access management, configuration management, and authentication are comprehensively assessed
  • IAM Access Analyzer, AWS Config, CloudTrail, S3, EC2, RDS, and other services are reviewed
  • A clear report and result matrix for follow-up actions

OWASP ASVS assessment

Assessing your application's security against the OWASP ASVS standard across three selectable levels of assurance.

Starting from €5,000 (excl. VAT)Duration: about 2 weeks
Show details

What's included:

  • Kick-off meeting (definition of objectives and targets)
  • Documentation-based and testing-based assessment
  • Reporting of findings and remediation recommendations
  • Final meeting and planning of next steps

Duration:

  • The engagement takes about 2 weeks from the kick-off meeting to the final meeting.

What we need from you:

  • Access rights to the application being assessed, as well as its documentation
  • A point of contact familiar with the application's architecture who can answer follow-up questions

Benefits:

  • Your application's security level is systematically assessed according to industry standards
  • You strengthen customer and stakeholder trust in your security posture

Organizational assessments

Cybermeter (Kybermittari)

A tool developed by the Finnish National Cyber Security Centre for assessing an organization's cybersecurity maturity and target level.

€4,000 – 7,000 (excl. VAT)Duration: 2–3 weeks
Show details

What's included:

  • Kick-off meeting (1 hour)
  • Cybermeter assessment and workshops
  • Reporting
  • Final meeting (1 hour)

Duration:

  • The whole engagement takes about 2–3 weeks from the kick-off meeting to the final meeting.

What we need from you:

  • Participants for the workshops from management and those responsible for security
  • A point of contact who coordinates workshop scheduling

Benefits:

  • Improved visibility into the organization's cybersecurity posture
  • Maturity level assessment and planning of development actions
  • Shared understanding between management and cybersecurity professionals
  • Systematic improvement of monitoring and reporting

Current state security assessment

An overview of your organization's cybersecurity: administrative practices, technical safeguards, and documentation.

Starting from €4,500 (excl. VAT)Duration: 1–2 weeks
Show details

What's included:

  • Kick-off meeting and scoping of the assessment
  • Current state analysis (review of documentation and environments, interviews)
  • Reporting and actionable recommendations
  • Final meeting and planning of next steps

Duration:

  • The whole engagement takes about 1–2 weeks from the kick-off meeting to the final meeting.

What we need from you:

  • Access to relevant documents and environments, plus interviewees
  • A point of contact who coordinates interview scheduling

Benefits:

  • A clear overview of your organization's cybersecurity posture
  • Identification of risks and areas for improvement before serious incidents occur
  • A concrete and prioritized action plan for enhancing security
  • Improved readiness to meet legal and contractual requirements (e.g., GDPR, ISO 27001, NIS2)
Frameworks

Standards and requirements we apply

We select the applicable standards based on the scope of the engagement and your industry.

Legislation and requirements

  • NIS2
  • CRA
  • DORA

Standards and frameworks

  • ISO 27001
  • IEC 62443
  • IEC 81001-5-1
  • NIST Cybersecurity Framework 2.0

Technical guidelines

  • CIS Benchmarks
  • OWASP ASVS, MASVS, Top 10
  • CSA Cloud Controls Matrix

Didn't find the right service?

Do you need a customized security assessment? We perform comprehensive, technology-agnostic security evaluations for various systems, applications, and organizations. Each assessment is tailored to your specific needs, risk profile, and business context—whether it's a single application, the entire IT environment, or critical business processes.

Who Is This Service For?

Companies and organizations with special requirements or complex environments

Industries where traditional assessment models are not sufficient

Projects that require combining multiple assessment targets (e.g., cloud services, applications, internal networks)

Get in touch and let's design a security assessment that fits your organization perfectly!