Assess

Security capability assessment

See where your security program stands, capability by capability, and what to fix first. The first step of Assess, Build, Operate.

Ali Aleali

Ali Aleali, CISSP, CCSP

Co-Founder & Principal Consultant

Former security architect for Bank of Canada and Payments Canada. CISSP, CCSP, more than twenty years in enterprise security. Leads every engagement.

Connect on LinkedIn

What the assessment covers

Carried out inside your environment, against the framework you are being measured on.

icon-7

Current state review

Systems, documentation and data flows reviewed inside your environment, with the people who operate them.

icon-5

Capability scoring

Each of the security capabilities an effective program is built from, scored on the maturity scale, so the gaps are visible as a shape rather than a list.

icon-6

Gap analysis against your framework

SOC 2, ISO 27001, NIST CSF or CPCSC. Where no framework has been named, a baseline with findings mapped so a later decision does not mean starting again.

icon-3

Findings rated by consequence

Rated by what an attacker or an auditor would do with them, rather than by control count.

icon-9

Remediation plan sequenced by dependency

Owners and effort against each item. Written so it can be handed to an internal team, to Truvo, or to a third party.

icon-8

Findings presented to the people who act

A working session with your team, and with your board or your customer where that was the trigger.

Assess, Build, Operate, applied to the whole security program

Timeline follows the size of the estate and how much documentation exists, and is set before the engagement starts. A documented methodology, led by a senior architect with more than ten years of enterprise security experience and a CISSP.

01

Assess

Which systems, which framework, who we interview. Access happens inside your environment. Truvo takes no custody of production data.

02

Build

Systems, documentation and data flows reviewed. Capabilities scored. Findings rated by consequence.

03

Operate

Written report with current state, rated findings and a sequenced remediation plan, then a working session with the people who will act on it.

What you hold at the end

A written report and a plan that can be handed to anyone, plus the session where the findings are walked through with the people who will act on them.

  • Current-state report

  • Capability scores on the maturity scale

  • Findings rated by attacker and auditor consequence

  • Gap analysis against your framework

  • Remediation plan with owners and effort

  • Board or customer presentation, where that was the trigger

What the assessment settles

Three questions a security lead has, answered in writing.

When an assessment is the right call, and when it is not

Most companies asking for a penetration test need the assessment first. We say which one the situation calls for on the scoping call.

Frequently asked questions

A penetration test answers whether a specific system can be broken into on the day it is tested. An assessment answers whether the program around that system produces a defensible security posture over time: how decisions get made, what evidence exists, where the gaps sit, and what order to fix them in. Most companies asking for one need the assessment first, because a test report with no program behind it produces a list no one owns. Truvo runs both and will say which one the situation calls for.

Often yes, and the reason is scope. A certification covers the boundary the company drew and the controls inside it, on the evidence the auditor sampled. An assessment looks at the systems outside that boundary, the controls that pass on paper while failing in operation, and the questions a customer is asking that the report does not answer. The finding that comes up most often is a control that works in one environment and was never extended to the other three.

Whichever one you are being measured on. In practice that is SOC 2 or ISO 27001 for commercial customers, NIST CSF where a customer or insurer has asked for a maturity rating, and CPCSC or CMMC where defence contracts are involved. Where no framework has been named, the assessment runs against a baseline and maps the findings so that a framework decision later does not mean starting again.

Timeline follows the size of the estate and how much documentation already exists, and it is set before the engagement starts rather than discovered during it. The deliverable is a written report covering current state, rated findings, and a sequenced remediation plan, plus a working session where the findings are walked through with the people who will act on them. The plan is written so that it can be handed to an internal team, to Truvo, or to a third party.

No. Access happens inside your environment, in your platforms and the third party systems you grant access to. Truvo does not take custody of, store, or host your production data or personal information in order to run an assessment. For teams whose own customers ask that question in a security review, that answer is part of what the engagement produces.

Talk to the architect who would do the work

A 30-minute call. We look at your environment and say plainly whether we can help and what it would take.

From the blog: assessing a security program

vCISO Services for Mid-Market SaaS: How to Evaluate Fractional Security Leadership in 2026

vCISO services give a mid-market SaaS company senior security leadership on a fractional basis: someone who owns the security program, drives SOC 2 ...

Top 8 vCISO Services for Mid-Market SaaS in 2026

The right vCISO service for a mid-market SaaS company is the one that owns and runs the security program end to end, on a fractional basis, the way a ...

What a Security Architect Actually Does: Three Roles and Where Requirements Come From

A security architect does three jobs: sets security requirements for systems other people design, assesses and reviews those designs, and solutions ...