What should I expect from an IT security assessment?

Short answer

An IT security assessment should start with an agreed written scope, combine interviews and document review with technical testing such as vulnerability scanning and configuration review, and end with a report that ranks findings by business risk. Expect an executive summary, detailed findings with evidence and a remediation roadmap. Prioritization should weigh known exploited vulnerabilities and the systems that matter most.

Scope comes first

The scope decides what you learn. Agree in writing which locations, users, systems and cloud services are covered, whether testing is external, internal or both, and what is excluded. Tie scope to a framework when you can, such as NIST CSF 2.0 for a general program review or NIST SP 800-171 for defense CUI, so findings map to something recognized.

Also agree on rules of engagement: testing windows, who to call if something breaks, and written authorization for any active testing. NIST SP 800-115 is the long-standing federal guide to planning and conducting technical security testing, analyzing findings and developing mitigation strategies.

What the work usually includes

  • Interviews with leadership, IT and key staff about how work actually gets done
  • Review of policies, the asset inventory, network diagrams and past incidents
  • Vulnerability scanning of internet-facing and internal systems
  • Configuration review of Microsoft 365, identity, firewalls, endpoints and backups
  • Checks of MFA coverage, admin accounts and remote access
  • Penetration testing, only if it is in the agreed scope

The deliverables to ask for

  • An executive summary a non-technical leader can read in ten minutes
  • Detailed findings with evidence, affected systems and a clear fix for each
  • A risk rating method that is explained, not just colors
  • A prioritized remediation roadmap with rough effort for each item
  • Raw scan output, so your team or next provider can verify it

How findings should be prioritized

Severity scores alone produce long lists. Good assessments combine technical severity with business context: what the system does, what data it holds and whether it faces the internet. CISA recommends using its Known Exploited Vulnerabilities catalog, the authoritative list of vulnerabilities exploited in the wild, as an input to vulnerability management prioritization.

In practice, items near the top are often missing MFA, exposed remote access, known exploited vulnerabilities on internet-facing systems, untested backups and excessive admin rights. Policy gaps matter too, but they rarely outrank an open door.

After the report

Assign an owner and date to each finding, fix the top items first, and rescan to confirm. If your current IT provider performed the assessment, consider an independent review periodically. CISA also offers no-cost Cyber Hygiene vulnerability scanning of internet-facing systems; contact CISA to confirm whether your organization is eligible.

Common follow-up questions

Is a security assessment the same as a penetration test?

No. An assessment reviews your overall security program, configurations and vulnerabilities. A penetration test is a narrower exercise in which testers try to exploit weaknesses to show real impact. Many assessments include limited testing; full penetration testing should be scoped and authorized separately.

How often should a small business be assessed?

There is no universal rule. Many companies assess annually and after major changes such as a merger, cloud migration or new compliance obligation. Contracts, insurers or regulators may set their own frequency, so check those requirements first.

Should our IT provider assess its own work?

It can run routine scanning and reviews, but an occasional independent assessment gives leadership an outside view. If the provider does the assessment, ask it to disclose that it manages the systems in scope and to share raw evidence.

Need help with this?

LAN Service Group performs IT security assessments for small and mid-size businesses and turns the findings into a prioritized remediation roadmap it can carry out as a managed or co-managed IT provider.

Talk to LAN Service Group (888) 281-7243

Sources