NIST SP 800-30 / ISO 27005 / Three weeks, fixed

Cybersecurity Risk Assessment Services

A fixed-scope risk assessment that finds what could actually hurt your business, scores it against your appetite, and hands you a ranked treatment plan and a board summary. Mapped to SOC 2, ISO 27001, HIPAA, NIS 2 or NIST CSF, whichever you report against.

Report in three weeks. $6,900 fixed, pay after you review it.

Risks found in the live environmentAuditor-ready register and treatment planNo retainer, no long engagement
Cybersecurity risk assessment services by Atlant Security, fixed scope in three weeks

Why Companies Commission a Risk Assessment

Someone asked for your risk assessment and you do not have one

Enterprise customers, cyber insurers, SOC 2 and ISO 27001 auditors, HIPAA and NIS 2 all require a documented risk assessment. It is the first artefact requested and the one most companies under 500 staff have never produced, because the person who could write it is the person running everything else.

You have controls but no idea which risks they cover

Security spending without a risk assessment buys tools against the last vendor pitch rather than the most likely loss. The assessment ranks what could actually hurt the business, so the next budget goes to the top of the list and the board can see why.

The consultancy wants a six-month engagement to tell you what you already suspect

A risk assessment for a single legal entity is a three-week piece of work when it is done by someone who has done 200 of them. Fixed scope, fixed price, no retainer, no lengthy commitment, and you pay after you have read the report.

When companies commission a cybersecurity risk assessment: customer, insurer, auditor, framework, change or incident
Risk assessment versus security audit versus penetration test

What the Risk Assessment Covers

Eight areas, each examined in the systems themselves rather than in a questionnaire. The output is one register, because a risk in vendor management and a risk in identity are competing for the same budget and the board needs to see them side by side.

Identity and access
MFA coverage, privileged accounts, joiners and leavers, SSO and service accounts
Endpoints and servers
Patching cadence, endpoint protection, encryption at rest, admin rights
Cloud and SaaS
Configuration, sharing, logging and the shared-responsibility gaps
Email, network and remote access
Filtering, segmentation, VPN and exposure to the internet
Backups and continuity
Coverage, tested restores, recovery time against what the business can tolerate
Vendors and supply chain
Processors, sub-processors, contracts and the concentration risk nobody tracked
People and process
Awareness, phishing exposure, incident readiness and who decides what in a crisis
Data and compliance
Where regulated data lives and moves, and which obligations attach to it
Scope of the cybersecurity risk assessment across identity, endpoints, cloud, network, backups, vendors and people
Frameworks the risk assessment maps to: NIST SP 800-30, ISO 27005, SOC 2 CC3, HIPAA, NIS 2, FAIR
Cybersecurity risk assessment cost: $6,900 fixed for a single legal entity

How Much a Cybersecurity Risk Assessment Costs

The market runs from about $2,000 for a questionnaire-based exercise, which produces a document and not much insight, to $50,000 and beyond for enterprise engagements by large firms, which produce a great deal of both. For a company of 20 to 500 staff the honest price for a full assessment done in the live environment by a senior practitioner is between $5,000 and $15,000.

Ours is $6,900, fixed, for a single legal entity, and you pay after you have read the report. The price does not change if we find more than expected, because the scope was agreed before we started. Multi-entity groups and operational technology sites are quoted in writing, and plants and utilities are assessed under the NIST SP 800-82 OT audit instead.

What you are paying for is judgement: which of the forty things that could go wrong are the five that will, and in what order to fix them. That is what 200+ assessments across 14 countries since 2013 buys you in three weeks.

Who Needs It

SaaS companies asked for a risk assessment in a security questionnaire or a SOC 2 audit
Fintech and payment firms whose supervisor, bank partner or insurer expects one annually
Healthcare and healthtech organisations under the HIPAA Security Rule risk analysis requirement
Manufacturers and utilities in scope of NIS 2, where risk management measures must be documented
Any company that wants to know what to spend on next, backed by evidence rather than vendor pressure

Compared With the Usual Engagement

Atlant SecurityTypical engagement
EvidenceRisks identified in the systems themselvesA workshop and a spreadsheet of opinions
ScoringLikelihood and impact against your stated risk appetite, defended line by lineTraffic-light colours nobody can explain
OutputRegister, treatment plan with owners and dates, board summaryA 90-page PDF with no ranking
TimelineTwo to three weeks, fixed scopeA multi-month engagement that grows
Pricing$6,900 fixed, published, pay after reviewDay rates, quoted after the discovery phase

How the Risk Assessment Works

1

Scoping and asset map

Systems, data, people, vendors and the business processes they support, agreed in writing with the threats that matter for your sector. This takes one call and a short questionnaire, not a workshop programme.

2

Identification in the live environment

Vulnerabilities and control gaps found by looking at the systems themselves: identity consoles, endpoints, cloud configuration, backups, email and network exposure. Interviews confirm process and ownership; screenshots from your IT team do not count as evidence.

3

Analysis and evaluation

Each risk scored for likelihood and impact against the appetite your management sets, ranked, and mapped to the framework you report against, whether that is NIST, ISO 27005, SOC 2, HIPAA or NIS 2.

4

Treatment plan and briefing

A prioritised treatment plan with owners, effort and dates, an executive summary written for the board, and a one-hour briefing where we defend every score. Optional annual reassessment keeps the register current.

The four step cybersecurity risk assessment method: scope, identify, analyse and evaluate, treat
Risk assessment deliverables: risk register, treatment plan, executive summary, control gap list

Pricing

Fixed prices, scoped in writing, and you pay for the assessment after you have reviewed the report.

Most common

Cybersecurity Risk Assessment

One legal entity, all eight areas, two to three weeks.

$6,900fixed
  • Scoping and asset map
  • Risks identified in the live environment
  • Scored, ranked risk register with evidence
  • Treatment plan with owners, effort and dates
  • Control gaps mapped to your framework
  • Executive summary and one-hour board briefing
Book Free Scoping Call

Risk Management Programme

The assessment plus the register kept alive for a year.

$11,900per year
  • Everything in the assessment
  • Register maintained as systems and vendors change
  • Mid-year reassessment of the top risks
  • Quarterly one-hour review with management
  • Auditor and insurer questionnaire support
  • Reassessment after any major change or incident
Book Free Scoping Call

Know What to Fix First

A free scoping call confirms what the assessment would cover for your company and what it would not. Three weeks later you hold a register your board can read and your auditor can accept.

Book the Scoping Call

Schedule Your Free Scoping Call

Cybersecurity Risk Assessment FAQ

How much does a cybersecurity risk assessment cost?
Our full risk assessment for a single legal entity is $6,900 fixed, delivered in two to three weeks, and you pay after you have reviewed the report. The programme option, which adds the risk register maintained for a year, a mid-year reassessment and a quarterly review with management, is $11,900 per year. Market prices range from about $2,000 for a questionnaire-based exercise to $50,000 and more for enterprise engagements by large firms; the difference is usually the size of the company being assessed and how much of the work is done in the live environment rather than in workshops.
What is the difference between a risk assessment, a security audit and a penetration test?
A risk assessment answers what could go wrong, how likely it is, how bad it would be and what to fix first. A security audit answers whether the controls you claim to have are in place and working, with evidence. A penetration test answers whether an attacker can actually get in. Most companies should do the risk assessment first, because it decides where the audit and the test should focus and which spending can wait.
Which frameworks does the assessment follow?
The method follows NIST SP 800-30 and ISO 27005, and the output is mapped to whichever framework you report against: NIST CSF 2.0, ISO 27001 clause 6.1.2, SOC 2 common criteria CC3, the HIPAA Security Rule risk analysis at 164.308(a)(1), NIS 2 Article 21 or GDPR Article 32. Where a board wants numbers rather than colours, we add FAIR-style quantification for the top risks.
How long does it take?
Two to three weeks for a single legal entity with up to a few hundred staff and a normal cloud-first estate. Larger, multi-entity or operational technology environments are scoped and priced in writing before we start, and OT sites are assessed under our NIST SP 800-82 audit instead.
Do we need a risk assessment for SOC 2 or ISO 27001?
Yes. SOC 2 common criteria CC3 require the entity to identify and analyse risks, and auditors ask to see the assessment and how it drove control selection. ISO 27001 clause 6.1.2 requires a defined risk assessment process with results. HIPAA requires a documented risk analysis outright. The report from this service is written so an auditor can accept it as that artefact.
Is this a rapid assessment or a long engagement?
Rapid, by design. The scope is agreed on the first call, the fieldwork takes about two weeks, and the briefing happens in the third. There is no retainer, no discovery phase billed separately and no obligation to buy remediation from us afterwards.
What do we receive?
A risk register with every risk scored, ranked and tied to evidence; a treatment plan with owners, effort estimates and target dates; a control gap list mapped to your framework; an executive summary written for the board; and a one-hour briefing. The register is delivered in a spreadsheet you can keep maintaining, not only in a PDF.
How often should we repeat it?
Annually is the accepted baseline and the frequency most frameworks and insurers expect, plus a reassessment after any major change: a new platform, an acquisition, a move to a new market or an incident. The programme option keeps the register current between full assessments.

Related Services and Guides