
Services
Risk Assessments
Structured evaluation of your security posture against recognised frameworks including NIST, ISO 27001, and COBIT.
Overview
Cyberxperts performs risk and maturity assessments structured against international frameworks, including NIST, ISO 27001, and COBIT. This work has included assessments for the National Nuclear Regulator, Transnet, GEMS Service Provider Network, and multiple South African municipalities.
Problems this addresses
- Uncertainty about current security maturity relative to recognised standards
- No structured basis for prioritising security investment
- Compliance obligations without a clear gap analysis
- Previous assessments that lacked a defined framework
Benefits
A clear, framework-based view of your current security maturity
Defined gaps and prioritised recommendations
Assessment methodology grounded in NIST, ISO 27001, and COBIT
Experience assessing regulator, financial services, and municipal environments
Our process
01
Scoping
We define the assessment scope, framework, and systems in scope.
02
Assessment
Evidence gathering against the chosen framework, including documentation review and technical evaluation.
03
Gap analysis
Findings are mapped against the framework to identify maturity gaps.
04
Reporting
A structured report with prioritised, actionable recommendations.
Frequently asked questions
Which frameworks do you assess against?
Primarily NIST, ISO 27001, and COBIT, selected based on your regulatory context and objectives.
How long does an assessment take?
This depends on scope. Past engagements have ranged from a few weeks to several months for larger, multi-entity assessments.
